CompyMax

Is Box HIPAA compliant?

Only under specific conditions

Yes, if you are on a Box Enterprise-tier account and you request and sign the agreement before any patient files are stored.

Applies to Box (Enterprise, Enterprise Plus, Enterprise Advanced). Last reviewed against Box's own documentation. Next review December 2, 2026.

Reviewed by Lisa Tran, CISSP — Healthcare Information Security Executive.

What you must do

  • Be on an Enterprise-tier account. Box requires Enterprise, Enterprise Plus or Enterprise Advanced.
  • Have the agreement in place first. Box states it should be signed prior to storing any patient information.
  • An admin or co-admin requests it: Admin Console → Account & Billing → HIPAA Compliance section → 'Request a HIPAA BAA' → complete the form → Continue. Box sends the addendum by email in three to five business days.
  • Configure Box yourself. Box states customers are responsible for configuring Box compliantly and enforcing their own policies.
  • If you use a Box partner product that touches patient information, sign a separate agreement with that partner in addition to your agreement with Box.

Does Box sign a business associate agreement?

Yes. Box offers one. Box Enterprise, Enterprise Plus or Enterprise Advanced Admin Console → Account & Billing → HIPAA Compliance → 'Request a HIPAA BAA' → complete the form → Continue.

See their documentation.

What this means in practice

Box gates this at the Enterprise tier, and the trap is entirely in the plan names. Box sells a plan called Business, and a practice manager who has been told to buy a business account will reasonably buy it. Business is not eligible; Enterprise, Enterprise Plus and Enterprise Advanced are. Personal and Starter are out too.

The request is not instant either. An admin or co-admin fills in the form in the Admin Console under Account and Billing, and Box emails the addendum back in three to five business days. That is fine if you plan for it and painful if you discover it the week files are due to move, since the agreement is meant to be in place before anything is stored.

After signing, the work is yours. Box is clear that configuring the account and enforcing your own policies sits with the customer, not with Box. And if you use a Box partner product that touches patient information, you need a separate agreement with that partner as well as the one with Box.

How organizations get this wrong

The specific mistakes we see with Box, not generic advice.

  • Buying Box's Business plan because the name sounds right for a business, when only Enterprise, Enterprise Plus and Enterprise Advanced qualify.
  • Starting the request the week of go-live and losing three to five business days waiting for Box to email the addendum back.
  • Connecting a Box partner product to folders holding patient files without signing a separate agreement with that partner too.
  • Treating Box's security reputation as though it does your configuration work, when Box states policy enforcement and setup remain the customer's job.

What the agreement does not cover

  • Box Personal, Starter and Business accounts.
  • Box partner and third-party integrations, which require their own separate agreement.

Alternatives

Listed on merit. We take no payment for placement and use no affiliate links.

  • Dropbox

    Self-serve electronic signing in the admin console, available below the enterprise tier

  • Google Drive

    Amendment accepted instantly in the Admin console with no sales cycle

Signing the agreement is step one. Proving it is step two.

Once you have the agreement with Box, someone has to know it exists, where the copy is, when it needs revisiting and who owns it. That register is what a client's security questionnaire is actually asking about, and it is the section of an evidence pack most organizations cannot produce on request.

$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.

Sources

Every statement above comes from Box’s own published documentation, read on the date shown.

  1. Box HIPAA and HITECH Overview and FAQBox. No publication date given. Read July 29, 2026.
  2. HIPAA-Compliant File Sharing & Cloud StorageBox. No publication date given. Read July 29, 2026.

Change history

  • First published.

This page is information, not certification and not legal advice. It reflects Box’s published documentation as read on July 29, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.

Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.