Medcurity Get Started
Last updated: March 2026

Is Dropbox HIPAA Compliant?

Quick Answer

Yes, Dropbox can be HIPAA compliant with a Business or Advanced plan, signed Business Associate Agreement, and proper configuration. Dropbox requires a BAA, encryption, sharing restrictions, audit logging, and careful management of third-party integrations. Standard and Plus plans do not support HIPAA compliance.

Dropbox Plan Requirements & BAA

Eligible Plans

Only Dropbox Business and Advanced plans support HIPAA Business Associate Agreements. Dropbox Basic, Plus, and Family plans cannot be used for Protected Health Information. Verify your organization is on a Business or Advanced plan before storing any PHI in Dropbox.

Obtaining a BAA

Contact Dropbox sales or your account manager to request a Business Associate Agreement. Provide your organization information, confirm your plan tier, and execute Dropbox's standard BAA. The BAA covers all file storage, sharing, and access activities. Processing typically takes 1-3 weeks.

Encryption & Data Protection

Security Feature HIPAA Configuration
Encryption In Transit TLS 1.2+ enforced for all uploads and downloads
Encryption at Rest AES-256 encryption; Dropbox-managed encryption by default
Customer-Managed Keys Available for Advanced plans; enables additional control
Two-Factor Authentication Enforce for all users; required for team admin accounts
Password Requirements Minimum 12 characters with complexity requirements

Encryption Best Practices

File Sharing & Access Controls

Folder Structure & Permissions

Organize PHI into separate team folders with restricted access. Set folder permissions to allow only necessary staff to view and edit patient files. Use role-based access: viewer, editor, manager. Regularly audit folder permissions and remove users who no longer need access.

Sharing Configuration

Audit Logging & Compliance

Team Activity Logs

Enable and monitor Dropbox team event logs. Track all file uploads, downloads, sharing changes, and permission modifications. Export logs monthly for compliance review. Retain logs for at least 6 years to meet healthcare retention requirements.

Activity Type Monitoring Strategy
File Downloads Monitor for unusual download patterns; alert on bulk downloads
Sharing Changes Audit all share link creations and permission modifications
User Access Track login locations and times; alert on unusual access patterns
Admin Actions Review all team admin actions weekly
Deletions Monitor file deletions and retention of deleted files

File Recovery & Data Retention

File Recovery Features

Dropbox retains deleted files for 30 days, allowing recovery. For HIPAA, configure your retention policy to match healthcare requirements. Never rely solely on Dropbox for data recovery; maintain separate backups. Ensure all recovered files are encrypted and access is controlled.

Permanent Deletion

When PHI needs permanent deletion for compliance reasons, use Dropbox's permanent delete feature. This removes files immediately rather than moving to trash. Document all permanent deletions for audit purposes. Verify deletion in Dropbox activity logs.

Third-Party Apps & Integrations

Third-Party App Security

Never authorize third-party apps to access PHI in Dropbox without reviewing their privacy policies and ensuring they have HIPAA BAAs. Each app that processes PHI must have its own Business Associate Agreement. Regularly audit connected apps and remove those no longer in use.

Safe Integration Practices

Mobile & Desktop Client Security

Desktop Client Configuration

Mobile Client Configuration

HIPAA Compliance Checklist

Pre-Implementation Requirements

✓ Dropbox Business or Advanced plan active
✓ HIPAA BAA signed and verified
✓ Two-factor authentication enabled for all users
✓ Public sharing disabled at team level
✓ File sharing restricted to members only
✓ Share links require passwords and expiration dates
✓ Folder permissions configured with role-based access
✓ Team event logs enabled and monitored
✓ Third-party apps reviewed and approved
✓ User training completed on PHI handling
✓ Regular audit schedule established

Frequently Asked Questions

Can we use Dropbox Plus for patient records? +
No. Dropbox Plus (and Basic, Family plans) do not support HIPAA BAAs. You must upgrade to Dropbox Business or Advanced plans. Plus plans cannot legally store Protected Health Information under HIPAA.
How long can we recover deleted Dropbox files? +
Dropbox retains deleted files for 30 days. After 30 days, files cannot be recovered. For HIPAA compliance, implement a retention policy aligned with healthcare requirements (typically 3-7 years). Maintain separate encrypted backups outside Dropbox for long-term retention.
What about Dropbox shared folders with external partners? +
External partners must be Business Associates with executed BAAs to access PHI shared folders. Never share PHI folders with external organizations unless they have signed HIPAA BAAs. Audit all shared folder access and remove partnerships when no longer needed.
Can we use Dropbox Vault for sensitive patient files? +
Yes. Dropbox Vault provides additional security with a separate password/2FA requirement. It's recommended for highly sensitive PHI. However, Vault alone doesn't make Dropbox HIPAA-compliant. A BAA and other controls are still required.

Ensure Your Dropbox is HIPAA Compliant

Medcurity audits Dropbox Business deployments to verify BAA coverage, encryption settings, sharing controls, and audit logging for healthcare data compliance.

Schedule Your Dropbox Audit