CompyMax

Is Dropbox HIPAA compliant?

Only under specific conditions

Yes, if you are on a Dropbox team plan and your administrator signs the agreement in the admin console before any patient files are uploaded.

Applies to Dropbox team accounts. Last reviewed against Dropbox's own documentation. Next review December 1, 2026.

Reviewed by Lisa Tran, CISSP — Healthcare Information Security Executive.

What you must do

  • Be on an eligible team plan. Dropbox lists Standard, Advanced, Business, Business Plus, Enterprise, Education and Dropbox Sign.
  • Sign before you migrate. Dropbox states an agreement must be in place before you transfer patient information into your account.
  • US-based administrators sign electronically: dropbox.com → Admin console → Settings → Account → Team profile → Advanced → 'Set up BAA'.
  • Outside the US you cannot self-serve — electronic signing is US-only. Contact sales@dropbox.com.
  • Configure sharing permissions to limit external sharing.
  • Disable permanent deletions so records cannot be irrecoverably destroyed.
  • Review every third-party app connected to the team. Dropbox states these are not covered by your terms, including the agreement.
  • Download and retain a copy of the executed agreement from the admin console.

Does Dropbox sign a business associate agreement?

Yes. Dropbox offers one. Team plans: Standard, Advanced, Business, Business Plus, Enterprise, Education and Dropbox Sign. US customers: Admin console → Settings → Account → Team profile → Advanced → 'Set up BAA'. Outside the US: email sales@dropbox.com.

See their documentation.

What this means in practice

Dropbox makes this easy for a US team on an eligible plan: a suitable administrator signs electronically from the admin console under Team profile and Advanced, and it is done. Outside the US there is no self-serve route at all and you have to email Dropbox sales, which is worth knowing before you promise a start date.

Sequence is the thing people get wrong. Dropbox is explicit that the agreement must be in place before patient information is transferred in, and the natural instinct is the reverse: migrate the shared drive over a weekend, get everyone working, then tidy up the paperwork. That order cannot be undone afterwards.

Two settings decisions follow immediately. Turn off permanent deletion so records cannot be destroyed beyond recovery, and tighten external sharing before staff start creating links. Then audit what is connected: third-party apps are not covered by your terms, Dropbox Dash is stated not to support compliance with HIPAA, and reseller support cannot be switched back on once the team has signed.

How organizations get this wrong

The specific mistakes we see with Dropbox, not generic advice.

  • Dragging years of scanned charts into Dropbox over a weekend and setting up the agreement the following week, which reverses the required order.
  • Buying Dropbox through a reseller who also provides your IT support, then finding reseller support cannot be enabled once the team signs.
  • Leaving permanent deletion enabled, so a departing staff member can destroy patient records in a way no administrator can recover.
  • Enabling Dropbox Dash to search across team files, when Dropbox states Dash does not support compliance with HIPAA.

What the agreement does not cover

  • Dropbox Dash. Dropbox states Dash does not support compliance with HIPAA, including Dash in Dropbox.
  • Third-party apps and integrations connected to Dropbox.
  • Reseller support, which cannot be enabled once a team signs.
  • Individual and consumer plans.

Alternatives

Listed on merit. We take no payment for placement and use no affiliate links.

  • Box

    Comparable storage with the request built into the admin console and enterprise governance controls

  • Google Drive

    Covered by the Workspace amendment and bundled with email and calendar

  • OneDrive for Business

    In scope under Microsoft's default agreement

Signing the agreement is step one. Proving it is step two.

Once you have the agreement with Dropbox, someone has to know it exists, where the copy is, when it needs revisiting and who owns it. That register is what a client's security questionnaire is actually asking about, and it is the section of an evidence pack most organizations cannot produce on request.

$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.

Sources

Every statement above comes from Dropbox’s own published documentation, read on the date shown.

  1. Dropbox and HIPAA/HITECHDropbox. No publication date given. Read July 29, 2026.
  2. Sign a Business Associate Agreement for your Dropbox team accountDropbox. No publication date given. Read July 29, 2026.

Change history

  • First published.

This page is information, not certification and not legal advice. It reflects Dropbox’s published documentation as read on July 29, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.

Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.