Is Dropbox Sign HIPAA compliant?
Only on an annual Standard or Premium plan that meets Dropbox's minimum contract value and has a signed agreement — there is no self-serve path and monthly billing does not qualify.
Applies to Dropbox Sign, formerly HelloSign. Last reviewed against Dropbox's own documentation. Next review January 16, 2027.
Reviewed by David Kim — Billing and RCM Operations Director.
What you must do
- Be on an annual Standard or Premium Dropbox Sign plan. Dropbox names annual billing specifically.
- Meet Dropbox's minimum contract value, which it does not publish — get the figure in writing from sales.
- Have the agreement signed before you transfer patient information into the account.
- Existing customers contact their account manager; everyone else uses the Dropbox Sign sales contact form.
- Expect the product to change: you can no longer CC people on signature requests, receive PDF copies of signed documents by email, or edit a document's title and message.
- If an administrator re-enables per-user editing of titles and messages, treat both fields as visible in outbound email and train staff accordingly.
Does Dropbox Sign sign a business associate agreement?
Yes. Dropbox offers one. Annual Standard or Premium, plus a minimum contract value Dropbox does not publish. Existing customers contact their account manager. Everyone else completes the Dropbox Sign sales contact form — there is no admin-console self-service route.
What this means in practice
Dropbox Sign is governed separately from Dropbox itself, in its own help article with its own eligibility rules, and those rules are tighter than most people expect. Support requires an annual Standard or Premium plan, a signed agreement, and a minimum contract value Dropbox does not publish. Monthly billing does not qualify, and there is no self-service path — you go through an account manager or the sales contact form.
Switching it on visibly changes the product. Copying other people onto signature requests stops working, signed documents are no longer emailed out as PDF attachments, and editing a document's title and message is disabled. Each of those was a route by which a patient's name, or the nature of the form they were signing, could travel through ordinary email to somebody outside the practice.
One of the three can be undone. An administrator can restore per-user editing of titles and messages, which quietly reopens the path Dropbox closed. If you turn it back on, treat those fields as public. Third-party apps connected to your account stay outside the agreement either way.
How organizations get this wrong
The specific mistakes we see with Dropbox Sign, not generic advice.
- Buying a monthly Standard plan and assuming it qualifies, when Dropbox names annual Standard or Premium plus a minimum contract value.
- Re-enabling per-user editing of document titles and messages, which puts the reason for a form back into outbound email.
- Confusing a Dropbox team agreement with Dropbox Sign's — separate articles, different eligibility, different sign-up routes.
- Sending consent forms before the agreement is executed, when Dropbox requires it in place beforehand.
What the agreement does not cover
- Any plan or billing term other than annual Standard or Premium, including free and monthly subscriptions.
- Accounts below the unpublished minimum contract value.
- Third-party apps and integrations.
- Dropbox Dash, which Dropbox states does not support compliance with HIPAA.
Alternatives
Listed on merit. We take no payment for placement and use no affiliate links.
Enhanced plans quoted through sales include an addendum for eSignature
Signing the agreement is step one. Proving it is step two.
Once you have the agreement with Dropbox Sign, someone has to know it exists, where the copy is, when it needs revisiting and who owns it. That register is what a client's security questionnaire is actually asking about, and it is the section of an evidence pack most organizations cannot produce on request.
$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.
Sources
Every statement above comes from Dropbox’s own published documentation, read on the date shown.
- Is Dropbox Sign HIPAA compliant? — Dropbox. Published December 4, 2025. Read July 29, 2026.
Change history
- — First published.
This page is information, not certification and not legal advice. It reflects Dropbox’s published documentation as read on July 29, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.
Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.