Vendor compliance profile

Is Dropbox HIPAA compliant?

Dropbox may support some HIPAA-regulated file workflows only for eligible team accounts after a Business Associate Agreement is in place and the customer configures access, sharing, devices, retention, and integrations appropriately. Consumer accounts and third-party apps should not be assumed to be covered for PHI.

Reviewed by Evidence: Public first-party sourcesConfidence: High
Visit vendor site

Direct compliance answer

Dropbox HIPAA, BAA, PHI, and SOC 2 snapshot

Last checked: 2026-10-01 | Confidence: High

Direct answerDropbox may support some HIPAA-regulated file workflows only for eligible team accounts after a Business Associate Agreement is in place and the customer configures access, sharing, devices, retention, and integrations appropriately. Consumer accounts and third-party apps should not be assumed to be covered for PHI.
BAA availabilityDropbox says eligible US-based team administrators can sign a BAA from the admin console. Confirm the current eligible plan, legal entity, covered services, reseller restrictions, and account-specific agreement before PHI use.
Can it handle PHI?File names, folder names, shared links, previews, comments, signatures, local sync folders, mobile devices, deleted files, support cases, APIs, and third-party apps can expose PHI.
SOC 2 caveatDropbox provides trust and assurance resources, including SOC materials. Review the current report, product scope, period, exceptions, and whether the exact services used by the buyer are covered.
What to verifyWhether the account and plan are currently eligible and the correct legal entity has executed Dropbox's BAA before PHI is introduced. Which Dropbox products, support services, AI features, APIs, transfer tools, signatures, previews, and account regions are covered or excluded.

Scope of this profile

Use this profile for Dropbox team-plan eligibility, BAA execution, covered file services, sharing, device, retention, and third-party integration review. It does not cover every Dropbox product or connected app.

HIPAA status signal

Conditional

BAA public signal

Available for eligible team accounts

SOC 2 evidence signal

Public evidence

PHI warning: File names, folder names, shared links, previews, comments, signatures, local sync folders, mobile devices, deleted files, support cases, APIs, and third-party apps can expose PHI.

Search query answers

Is Dropbox HIPAA compliant?

Dropbox should be treated as conditionally suitable, not automatically HIPAA compliant. Dropbox publishes a BAA path for eligible team accounts, but the customer must execute the agreement, use covered services, configure the account, and govern every PHI file, share, device, support, and integration path.

Does Dropbox offer a BAA?

Dropbox says eligible US-based team account administrators can sign a BAA electronically in the admin console. Buyers should confirm current plan eligibility, account location, covered services, excluded features, reseller limitations, and the executed agreement before uploading PHI.

Can Dropbox store PHI?

Only after the correct Dropbox team account and BAA are verified and the complete storage workflow is governed. File names, shared links, previews, sync clients, local devices, deleted files, support cases, APIs, and third-party integrations can all expose PHI outside the intended boundary.

Are Dropbox integrations covered by its BAA?

Dropbox states that third-party apps and integrations are not part of its included services and are not covered by Dropbox terms, including its BAA. Each connected app must be evaluated independently before it receives PHI.

HIPAA, BAA, and SOC 2 summary

HIPAADropbox publishes a HIPAA/HITECH program for specified team offerings, but there is no official HIPAA certification and an eligible account does not make the customer's file workflow compliant by itself.
BAADropbox says eligible US-based team administrators can sign a BAA from the admin console. Confirm the current eligible plan, legal entity, covered services, reseller restrictions, and account-specific agreement before PHI use.
SOC 2Dropbox provides trust and assurance resources, including SOC materials. Review the current report, product scope, period, exceptions, and whether the exact services used by the buyer are covered.
PHI riskFile names, folder names, shared links, previews, comments, signatures, local sync folders, mobile devices, deleted files, support cases, APIs, and third-party apps can expose PHI.
CategoryHIPAA-Compliant Databases and Cloud Services: BAA Comparison
Last checked2026-10-01
ConfidenceHigh

Public evidence and open questions

What public sources say

  • Dropbox's HIPAA/HITECH help page lists specified team offerings and describes an electronic BAA flow for eligible US-based administrators.
  • Dropbox's Business Agreement requires a separate HIPAA BAA before PHI is stored, transmitted, or otherwise processed and warns that not every Dropbox service is designed for PHI.
  • Dropbox states that third-party apps and integrations are outside its included services and are not covered by the Dropbox BAA.

What remains unconfirmed

  • Whether the buyer's exact plan, legal entity, region, account history, support path, signature workflow, and enabled services are eligible under current Dropbox BAA terms.
  • Whether Sign, Replay, Dash, AI features, APIs, previews, transfer tools, local sync clients, backups, and connected apps are covered or must remain outside the PHI workflow.
  • Whether sharing, device management, retention, deletion, audit, support, and incident controls satisfy the buyer's own obligations.

What it may be used for

  • File storage and collaboration in an eligible Dropbox team account after the BAA, covered services, account configuration, permissions, retention, and devices are verified.
  • Healthcare operations that can centralize administration, restrict external sharing, control endpoints, monitor activity, and review every integration.
  • Vendor evaluation where Dropbox's agreement, security evidence, and customer responsibilities are reviewed separately.

What not to use it for

  • Uploading PHI to consumer, personal, or otherwise ineligible Dropbox accounts.
  • Sharing PHI through public links, unmanaged devices, personal sync folders, or third-party apps that lack separate review and coverage.
  • Assuming a Dropbox BAA covers every Dropbox product, integration, reseller arrangement, or customer configuration.

What to verify with the vendor

  • Whether the account and plan are currently eligible and the correct legal entity has executed Dropbox's BAA before PHI is introduced.
  • Which Dropbox products, support services, AI features, APIs, transfer tools, signatures, previews, and account regions are covered or excluded.
  • How administrators enforce MFA, SSO, least privilege, external sharing, link expiration, device approval, audit logs, retention, deletion, and recovery.
  • Whether every third-party app, backup, e-signature, endpoint, support workflow, and downstream destination has appropriate separate review and coverage.

Safer alternatives and related profiles

Safer alternatives to consider

  • Microsoft 365 file services only where the Microsoft BAA and in-scope services cover the intended workflow and tenant configuration.
  • Google Workspace Drive only after Google's HIPAA BAA is accepted and included functionality, sharing, add-ons, and retention are governed.
  • A healthcare-specific document exchange or patient portal when identity, consent, messaging, signatures, and clinical records require one governed workflow.

FAQ

Is Dropbox HIPAA compliant?

Dropbox should be treated as conditionally suitable, not automatically HIPAA compliant. Dropbox publishes a BAA path for eligible team accounts, but the customer must execute the agreement, use covered services, configure the account, and govern every PHI file, share, device, support, and integration path.

Does Dropbox offer a BAA?

Dropbox says eligible US-based team account administrators can sign a BAA electronically in the admin console. Buyers should confirm current plan eligibility, account location, covered services, excluded features, reseller limitations, and the executed agreement before uploading PHI.

Can Dropbox store PHI?

Only after the correct Dropbox team account and BAA are verified and the complete storage workflow is governed. File names, shared links, previews, sync clients, local devices, deleted files, support cases, APIs, and third-party integrations can all expose PHI outside the intended boundary.

Are Dropbox integrations covered by its BAA?

Dropbox states that third-party apps and integrations are not part of its included services and are not covered by Dropbox terms, including its BAA. Each connected app must be evaluated independently before it receives PHI.

Will Dropbox sign a BAA?

Dropbox says eligible US-based team administrators can sign a BAA from the admin console. Confirm the current eligible plan, legal entity, covered services, reseller restrictions, and account-specific agreement before PHI use.

Can Dropbox be used with PHI?

Do not use this vendor with PHI until your organization verifies BAA scope, covered services, configuration, access controls, data retention, and connected integrations.

Does SOC 2 mean Dropbox is HIPAA compliant?

No. SOC 2 evidence can support security diligence, but it does not prove HIPAA compliance, confirm BAA coverage, or approve PHI use. Review HIPAA terms, BAA scope, covered services, configuration, and intended workflow separately.

What should buyers verify before using Dropbox with PHI?

Whether the account and plan are currently eligible and the correct legal entity has executed Dropbox's BAA before PHI is introduced. Which Dropbox products, support services, AI features, APIs, transfer tools, signatures, previews, and account regions are covered or excluded. How administrators enforce MFA, SSO, least privilege, external sharing, link expiration, device approval, audit logs, retention, deletion, and recovery. Whether every third-party app, backup, e-signature, endpoint, support workflow, and downstream destination has appropriate separate review and coverage.

Last checked and source notes

Last checked
2026-10-01
Confidence
High
Dataset rows
274 vendors
  • Reviewed Dropbox's HIPAA/HITECH help page, Business Agreement, and trust materials on 2026-10-01.
  • Dropbox suitability remains conditional on the eligible team account, executed BAA, covered services, customer controls, devices, sharing, and integrations.
  • ComplySaaS did not verify a private Dropbox contract, signed BAA, admin-console state, or customer-specific configuration.
  • Dropbox and HIPAA/HITECH
  • Dropbox Business Agreement
  • Dropbox Trust Center