Yes, Dropbox can be HIPAA compliant with a Business or Advanced plan, signed Business Associate Agreement, and proper configuration. Dropbox requires a BAA, encryption, sharing restrictions, audit logging, and careful management of third-party integrations. Standard and Plus plans do not support HIPAA compliance.
Only Dropbox Business and Advanced plans support HIPAA Business Associate Agreements. Dropbox Basic, Plus, and Family plans cannot be used for Protected Health Information. Verify your organization is on a Business or Advanced plan before storing any PHI in Dropbox.
Contact Dropbox sales or your account manager to request a Business Associate Agreement. Provide your organization information, confirm your plan tier, and execute Dropbox's standard BAA. The BAA covers all file storage, sharing, and access activities. Processing typically takes 1-3 weeks.
| Security Feature | HIPAA Configuration |
|---|---|
| Encryption In Transit | TLS 1.2+ enforced for all uploads and downloads |
| Encryption at Rest | AES-256 encryption; Dropbox-managed encryption by default |
| Customer-Managed Keys | Available for Advanced plans; enables additional control |
| Two-Factor Authentication | Enforce for all users; required for team admin accounts |
| Password Requirements | Minimum 12 characters with complexity requirements |
Organize PHI into separate team folders with restricted access. Set folder permissions to allow only necessary staff to view and edit patient files. Use role-based access: viewer, editor, manager. Regularly audit folder permissions and remove users who no longer need access.
Enable and monitor Dropbox team event logs. Track all file uploads, downloads, sharing changes, and permission modifications. Export logs monthly for compliance review. Retain logs for at least 6 years to meet healthcare retention requirements.
| Activity Type | Monitoring Strategy |
|---|---|
| File Downloads | Monitor for unusual download patterns; alert on bulk downloads |
| Sharing Changes | Audit all share link creations and permission modifications |
| User Access | Track login locations and times; alert on unusual access patterns |
| Admin Actions | Review all team admin actions weekly |
| Deletions | Monitor file deletions and retention of deleted files |
Dropbox retains deleted files for 30 days, allowing recovery. For HIPAA, configure your retention policy to match healthcare requirements. Never rely solely on Dropbox for data recovery; maintain separate backups. Ensure all recovered files are encrypted and access is controlled.
When PHI needs permanent deletion for compliance reasons, use Dropbox's permanent delete feature. This removes files immediately rather than moving to trash. Document all permanent deletions for audit purposes. Verify deletion in Dropbox activity logs.
Never authorize third-party apps to access PHI in Dropbox without reviewing their privacy policies and ensuring they have HIPAA BAAs. Each app that processes PHI must have its own Business Associate Agreement. Regularly audit connected apps and remove those no longer in use.
✓ Dropbox Business or Advanced plan active
✓ HIPAA BAA signed and verified
✓ Two-factor authentication enabled for all users
✓ Public sharing disabled at team level
✓ File sharing restricted to members only
✓ Share links require passwords and expiration dates
✓ Folder permissions configured with role-based access
✓ Team event logs enabled and monitored
✓ Third-party apps reviewed and approved
✓ User training completed on PHI handling
✓ Regular audit schedule established
Medcurity audits Dropbox Business deployments to verify BAA coverage, encryption settings, sharing controls, and audit logging for healthcare data compliance.
Schedule Your Dropbox Audit