Back to resources

Cloud storage has made small practice operations significantly easier. Patient forms, referral letters, lab results, and administrative files all live somewhere accessible from any device. The problem is that "accessible" and "HIPAA-compliant" are not the same thing, and most practices are using cloud storage in ways that create compliance risk they're not aware of.

The default problem

Google Drive, Dropbox, and Microsoft OneDrive are all HIPAA-eligible. That means a compliant version of each product exists. It does not mean the version your practice is currently using is that version.

The standard consumer tier of any of these tools is not HIPAA-compliant. It lacks the Business Associate Agreement that HIPAA requires, and it doesn't include the contractual commitments around data handling, breach notification, and security controls that a BAA mandates.

"HIPAA-eligible" vs. "HIPAA-compliant": A product is HIPAA-eligible if it has the technical capability to support compliance. It becomes HIPAA-compliant for your practice when you're on the right plan AND you have a signed BAA AND your configuration settings meet the requirements. Eligibility is necessary but not sufficient.

What each major platform requires

Google Drive (Google Workspace)

Standard Gmail and Google Drive consumer accounts do not support BAAs and are not suitable for PHI. Google Workspace for Business (the paid business version, previously G Suite) does support BAAs, which you can sign through the Admin Console. Once the BAA is in place, Google Drive, Gmail, Meet, and other covered services can be used for PHI, subject to your configuration settings.

Important: individual user Gmail accounts, even if they end in your domain, may not be covered if they're not under the BAA-covered Workspace plan. Verify with your Google admin.

Microsoft OneDrive / SharePoint

Consumer OneDrive is not HIPAA-compliant. Microsoft 365 Business plans (Business Basic, Standard, Premium) include the Microsoft Online Services BAA, which covers OneDrive, SharePoint, Teams, and Exchange. Sign the BAA through the Microsoft 365 admin center.

Dropbox

Consumer Dropbox and Dropbox Plus are not HIPAA-compliant. Dropbox Business plans offer BAA support. Once you're on a Business plan and have signed the BAA, Dropbox can be used for PHI.

Box

Box Business and higher plans support BAAs and are commonly used in healthcare. Box has strong enterprise-grade security features and is a solid choice for practices that need compliant cloud storage.

Configuration still matters

Having a BAA is necessary. It's not sufficient. Your cloud storage configuration also needs to:

The sharing link problem: The biggest HIPAA risk in cloud storage for small practices isn't the platform itself. It's staff sharing files using "anyone with a link" settings because it's convenient. Those links can be forwarded, bookmarked, and accessed indefinitely. Audit your sharing settings and switch to "specific people only" defaults.

What to do this week


Cloud storage compliance isn't complicated, but it does require intentional setup. The underlying tools are often already HIPAA-capable. Getting them configured and covered by a BAA is the work most practices haven't done yet.

Not sure if your cloud storage setup is HIPAA-compliant?

The free Cyber Health Score flags common cloud storage gaps in 5 minutes.

Get your free Cyber Health Score