Cloud storage has made small practice operations significantly easier. Patient forms, referral letters, lab results, and administrative files all live somewhere accessible from any device. The problem is that "accessible" and "HIPAA-compliant" are not the same thing, and most practices are using cloud storage in ways that create compliance risk they're not aware of.
The default problem
Google Drive, Dropbox, and Microsoft OneDrive are all HIPAA-eligible. That means a compliant version of each product exists. It does not mean the version your practice is currently using is that version.
The standard consumer tier of any of these tools is not HIPAA-compliant. It lacks the Business Associate Agreement that HIPAA requires, and it doesn't include the contractual commitments around data handling, breach notification, and security controls that a BAA mandates.
"HIPAA-eligible" vs. "HIPAA-compliant": A product is HIPAA-eligible if it has the technical capability to support compliance. It becomes HIPAA-compliant for your practice when you're on the right plan AND you have a signed BAA AND your configuration settings meet the requirements. Eligibility is necessary but not sufficient.
What each major platform requires
Google Drive (Google Workspace)
Standard Gmail and Google Drive consumer accounts do not support BAAs and are not suitable for PHI. Google Workspace for Business (the paid business version, previously G Suite) does support BAAs, which you can sign through the Admin Console. Once the BAA is in place, Google Drive, Gmail, Meet, and other covered services can be used for PHI, subject to your configuration settings.
Important: individual user Gmail accounts, even if they end in your domain, may not be covered if they're not under the BAA-covered Workspace plan. Verify with your Google admin.
Microsoft OneDrive / SharePoint
Consumer OneDrive is not HIPAA-compliant. Microsoft 365 Business plans (Business Basic, Standard, Premium) include the Microsoft Online Services BAA, which covers OneDrive, SharePoint, Teams, and Exchange. Sign the BAA through the Microsoft 365 admin center.
Dropbox
Consumer Dropbox and Dropbox Plus are not HIPAA-compliant. Dropbox Business plans offer BAA support. Once you're on a Business plan and have signed the BAA, Dropbox can be used for PHI.
Box
Box Business and higher plans support BAAs and are commonly used in healthcare. Box has strong enterprise-grade security features and is a solid choice for practices that need compliant cloud storage.
Configuration still matters
Having a BAA is necessary. It's not sufficient. Your cloud storage configuration also needs to:
- Restrict sharing settings so PHI isn't shared with "anyone with a link" by default
- Require login to access shared files
- Have audit logging enabled so you can track who accessed what
- Use MFA on accounts that can access PHI
- Limit folder access by role (not everyone in the practice needs access to everything)
The sharing link problem: The biggest HIPAA risk in cloud storage for small practices isn't the platform itself. It's staff sharing files using "anyone with a link" settings because it's convenient. Those links can be forwarded, bookmarked, and accessed indefinitely. Audit your sharing settings and switch to "specific people only" defaults.
What to do this week
- Identify which cloud storage tools your practice uses for any patient-related documents
- Confirm whether your plan tier supports a BAA for each tool
- Locate or request the BAA from each vendor
- Review sharing settings and disable "anyone with a link" access for existing files containing PHI
- Brief staff on appropriate sharing practices
Cloud storage compliance isn't complicated, but it does require intentional setup. The underlying tools are often already HIPAA-capable. Getting them configured and covered by a BAA is the work most practices haven't done yet.
Not sure if your cloud storage setup is HIPAA-compliant?
The free Cyber Health Score flags common cloud storage gaps in 5 minutes.
Get your free Cyber Health Score