CompyMax

Is Tresorit HIPAA compliant?

Only under specific conditions

Yes — Tresorit states plainly that it signs business associate agreements, which is more than most encrypted-storage vendors will say, but you still have to ask for one and plan for what zero-knowledge encryption costs you.

Applies to Tresorit encrypted cloud storage. Last reviewed against Tresorit's own documentation. Next review February 20, 2027.

Reviewed by Lisa Tran, CISSP — Healthcare Information Security Executive.

What you must do

  • Ask Tresorit for the business associate agreement and have it executed before patient files are uploaded. Tresorit states it 'signs HIPAA Business Associate Agreements (BAA) with customers seeking HIPAA compliance'.
  • Understand what zero-knowledge means for recovery. End-to-end encryption is the reason the product suits this data, and it is also why a lost account key can mean permanently lost records — set up admin recovery deliberately.
  • Control external sharing. Share links are the ordinary way files leave an encrypted store; set expiry, passwords and open limits as policy rather than per file.
  • Keep a record of which tresors hold patient information, so the vendor register and any later access request have something to work from.
  • Check device access. Encryption at rest does nothing about a synced laptop that is not itself encrypted and locked.

Does Tresorit sign a business associate agreement?

Yes. Tresorit offers one. Not stated. Tresorit's security page says it signs agreements with customers seeking HIPAA compliance without naming a plan. Not described on the security page beyond the statement that Tresorit signs them. Request it through Tresorit sales or support before uploading patient data.

See their documentation.

What this means in practice

Tresorit is one of the few encrypted-storage vendors that says the quiet part publicly: it signs business associate agreements. That single sentence is worth more than a page of security marketing, because in this category most vendors describe their encryption at length and never say whether they will contract.

What zero-knowledge buys you is that Tresorit cannot read the files. What it costs you is that Tresorit cannot recover them either. For a practice, that trade is usually right and occasionally catastrophic — it is the reason to set up administrative recovery on day one rather than after the first departing employee takes their key with them.

The sharing surface is where encrypted stores leak. Not through the encryption, through a share link somebody set to never expire.

How organizations get this wrong

The specific mistakes we see with Tresorit, not generic advice.

  • Uploading first and asking for the agreement afterwards, on the assumption that a vendor which advertises HIPAA has already covered you.
  • Skipping admin recovery setup, then discovering the design guarantees the data is gone.
  • Creating share links without expiry, password or open limits, which is the ordinary way files leave an encrypted vault.
  • Assuming a personal or free tier carries the same terms as a business subscription. Tresorit does not say it does.

What the agreement does not cover

  • Anything you copy out of Tresorit. The protection is a property of the store, not of the file.
  • Recovery of data whose keys are lost, which is the direct consequence of the zero-knowledge design.
  • Plan scope, which Tresorit's security page does not state — confirm the agreement covers the subscription you actually hold.

Alternatives

Listed on merit. We take no payment for placement and use no affiliate links.

  • Box

    Where you need a mainstream content platform other systems integrate with rather than an encrypted vault

  • SpiderOak

    The other zero-knowledge option, though it qualifies who it will sign for

Signing the agreement is step one. Proving it is step two.

Once you have the agreement with Tresorit, someone has to know it exists, where the copy is, when it needs revisiting and who owns it. That register is what a client's security questionnaire is actually asking about, and it is the section of an evidence pack most organizations cannot produce on request.

$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.

Sources

Every statement above comes from Tresorit’s own published documentation, read on the date shown.

  1. Security and compliance at TresoritTresorit. No publication date given. Read August 24, 2026.

Change history

  • First published.

This page is information, not certification and not legal advice. It reflects Tresorit’s published documentation as read on August 24, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.

Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.