HIPAA compliant cloud storage
Where documents containing patient information end up. Sharing settings and connected third-party apps are the recurring gap.
Storage is where documents drift. A scanned referral goes into a folder, a link is shared to move it along, and the link keeps working long after the person who needed it has gone. Public or anyone-with-the-link sharing is the failure mode that recurs, because it is a two-click action available to every staff member and it leaves behind nothing that looks like a mistake.
Connected applications are the other half. A storage account is usually the hub every other tool plugs into, and vendors here are consistent in placing those third-party connections outside the agreement, which means coverage effectively ends the moment a file syncs somewhere else. A workable product gives an administrator real control: restrict external sharing, expire links, allowlist connected apps, prevent permanent deletion, and show an audit trail of who opened what.
Can be used with patient information
Each of these requires a signed agreement and, usually, specific settings. Open an entry for the exact conditions.
Box
ConditionalYes, if you are on a Box Enterprise-tier account and you request and sign the agreement before any patient files are stored.
Dropbox
ConditionalYes, if you are on a Dropbox team plan and your administrator signs the agreement in the admin console before any patient files are uploaded.
OneDrive
ConditionalYes for OneDrive for Business on a Microsoft 365 business subscription, where the agreement applies automatically — but the consumer OneDrive on a personal Microsoft account is a different product and is not covered.
What to check before you adopt one
- Check whether an administrator can disable public or anyone-with-the-link sharing outright, rather than relying on each staff member to pick the right option every time.
- Ask how permanent deletion works and whether you can stop staff destroying records you are obliged to keep for years.
- Get the vendor's position on connected third-party apps in writing, since storage sits at the centre of everything and these connections are routinely outside scope.
- Confirm the agreement is signed before you migrate, because several vendors state it must be in place before any patient files are transferred in.
- Verify that the audit log records file access and sharing events, and that it is retained at least as long as your own record-keeping obligations.
The expensive mistake
Migrating years of scanned records into a new account first and sorting the paperwork out afterwards. Several vendors state plainly that the agreement must exist before patient files arrive, and a bulk upload is not something you can undo. The same mistake happens on downgrade: moving to a cheaper plan can end coverage while every file stays exactly where it is.
Tracking which of these your organization uses?
The vendor and BAA register keeps every tool that touches patient information, its agreement status and its renewal date in one place — seeded from this research. See pricing.
Information, not certification and not legal advice. Each entry reflects that vendor’s published documentation as read on the date shown on its page. Vendors change terms without notice — confirm anything you rely on directly with them.