Vendor compliance profile
Is Dropbox HIPAA compliant?
Dropbox may support some HIPAA-regulated file workflows only for eligible team accounts after a Business Associate Agreement is in place and the customer configures access, sharing, devices, retention, and integrations appropriately. Consumer accounts and third-party apps should not be assumed to be covered for PHI.
Direct compliance answer
Dropbox HIPAA, BAA, PHI, and SOC 2 snapshot
Last checked: 2026-10-01 | Confidence: High
| Direct answer | Dropbox may support some HIPAA-regulated file workflows only for eligible team accounts after a Business Associate Agreement is in place and the customer configures access, sharing, devices, retention, and integrations appropriately. Consumer accounts and third-party apps should not be assumed to be covered for PHI. |
|---|---|
| BAA availability | Dropbox says eligible US-based team administrators can sign a BAA from the admin console. Confirm the current eligible plan, legal entity, covered services, reseller restrictions, and account-specific agreement before PHI use. |
| Can it handle PHI? | File names, folder names, shared links, previews, comments, signatures, local sync folders, mobile devices, deleted files, support cases, APIs, and third-party apps can expose PHI. |
| SOC 2 caveat | Dropbox provides trust and assurance resources, including SOC materials. Review the current report, product scope, period, exceptions, and whether the exact services used by the buyer are covered. |
| What to verify | Whether the account and plan are currently eligible and the correct legal entity has executed Dropbox's BAA before PHI is introduced. Which Dropbox products, support services, AI features, APIs, transfer tools, signatures, previews, and account regions are covered or excluded. |
Scope of this profile
Use this profile for Dropbox team-plan eligibility, BAA execution, covered file services, sharing, device, retention, and third-party integration review. It does not cover every Dropbox product or connected app.
HIPAA status signal
Conditional
BAA public signal
Available for eligible team accounts
SOC 2 evidence signal
Public evidence
PHI warning: File names, folder names, shared links, previews, comments, signatures, local sync folders, mobile devices, deleted files, support cases, APIs, and third-party apps can expose PHI.
Search query answers
Is Dropbox HIPAA compliant?
Dropbox should be treated as conditionally suitable, not automatically HIPAA compliant. Dropbox publishes a BAA path for eligible team accounts, but the customer must execute the agreement, use covered services, configure the account, and govern every PHI file, share, device, support, and integration path.
Does Dropbox offer a BAA?
Dropbox says eligible US-based team account administrators can sign a BAA electronically in the admin console. Buyers should confirm current plan eligibility, account location, covered services, excluded features, reseller limitations, and the executed agreement before uploading PHI.
Can Dropbox store PHI?
Only after the correct Dropbox team account and BAA are verified and the complete storage workflow is governed. File names, shared links, previews, sync clients, local devices, deleted files, support cases, APIs, and third-party integrations can all expose PHI outside the intended boundary.
Are Dropbox integrations covered by its BAA?
Dropbox states that third-party apps and integrations are not part of its included services and are not covered by Dropbox terms, including its BAA. Each connected app must be evaluated independently before it receives PHI.
HIPAA, BAA, and SOC 2 summary
| HIPAA | Dropbox publishes a HIPAA/HITECH program for specified team offerings, but there is no official HIPAA certification and an eligible account does not make the customer's file workflow compliant by itself. |
|---|---|
| BAA | Dropbox says eligible US-based team administrators can sign a BAA from the admin console. Confirm the current eligible plan, legal entity, covered services, reseller restrictions, and account-specific agreement before PHI use. |
| SOC 2 | Dropbox provides trust and assurance resources, including SOC materials. Review the current report, product scope, period, exceptions, and whether the exact services used by the buyer are covered. |
| PHI risk | File names, folder names, shared links, previews, comments, signatures, local sync folders, mobile devices, deleted files, support cases, APIs, and third-party apps can expose PHI. |
| Category | HIPAA-Compliant Databases and Cloud Services: BAA Comparison |
| Last checked | 2026-10-01 |
| Confidence | High |
Public evidence and open questions
What public sources say
- Dropbox's HIPAA/HITECH help page lists specified team offerings and describes an electronic BAA flow for eligible US-based administrators.
- Dropbox's Business Agreement requires a separate HIPAA BAA before PHI is stored, transmitted, or otherwise processed and warns that not every Dropbox service is designed for PHI.
- Dropbox states that third-party apps and integrations are outside its included services and are not covered by the Dropbox BAA.
What remains unconfirmed
- Whether the buyer's exact plan, legal entity, region, account history, support path, signature workflow, and enabled services are eligible under current Dropbox BAA terms.
- Whether Sign, Replay, Dash, AI features, APIs, previews, transfer tools, local sync clients, backups, and connected apps are covered or must remain outside the PHI workflow.
- Whether sharing, device management, retention, deletion, audit, support, and incident controls satisfy the buyer's own obligations.
What it may be used for
- File storage and collaboration in an eligible Dropbox team account after the BAA, covered services, account configuration, permissions, retention, and devices are verified.
- Healthcare operations that can centralize administration, restrict external sharing, control endpoints, monitor activity, and review every integration.
- Vendor evaluation where Dropbox's agreement, security evidence, and customer responsibilities are reviewed separately.
What not to use it for
- Uploading PHI to consumer, personal, or otherwise ineligible Dropbox accounts.
- Sharing PHI through public links, unmanaged devices, personal sync folders, or third-party apps that lack separate review and coverage.
- Assuming a Dropbox BAA covers every Dropbox product, integration, reseller arrangement, or customer configuration.
What to verify with the vendor
- Whether the account and plan are currently eligible and the correct legal entity has executed Dropbox's BAA before PHI is introduced.
- Which Dropbox products, support services, AI features, APIs, transfer tools, signatures, previews, and account regions are covered or excluded.
- How administrators enforce MFA, SSO, least privilege, external sharing, link expiration, device approval, audit logs, retention, deletion, and recovery.
- Whether every third-party app, backup, e-signature, endpoint, support workflow, and downstream destination has appropriate separate review and coverage.
Safer alternatives and related profiles
Safer alternatives to consider
- Microsoft 365 file services only where the Microsoft BAA and in-scope services cover the intended workflow and tenant configuration.
- Google Workspace Drive only after Google's HIPAA BAA is accepted and included functionality, sharing, add-ons, and retention are governed.
- A healthcare-specific document exchange or patient portal when identity, consent, messaging, signatures, and clinical records require one governed workflow.
AWS HIPAA eligible services and BAA scope
HIPAA: Conditional | SOC 2: Public evidence
Amazon RDS HIPAA eligibility and supported engines
HIPAA: Conditional | SOC 2: AWS public evidence
Amazon Aurora HIPAA eligibility and configuration
HIPAA: Conditional | SOC 2: AWS public evidence
Amazon Connect HIPAA contact-center eligibility
HIPAA: Conditional | SOC 2: AWS public evidence
AWS Bedrock HIPAA model and BAA checklist
HIPAA: Conditional | SOC 2: AWS public evidence
FAQ
Is Dropbox HIPAA compliant?
Dropbox should be treated as conditionally suitable, not automatically HIPAA compliant. Dropbox publishes a BAA path for eligible team accounts, but the customer must execute the agreement, use covered services, configure the account, and govern every PHI file, share, device, support, and integration path.
Does Dropbox offer a BAA?
Dropbox says eligible US-based team account administrators can sign a BAA electronically in the admin console. Buyers should confirm current plan eligibility, account location, covered services, excluded features, reseller limitations, and the executed agreement before uploading PHI.
Can Dropbox store PHI?
Only after the correct Dropbox team account and BAA are verified and the complete storage workflow is governed. File names, shared links, previews, sync clients, local devices, deleted files, support cases, APIs, and third-party integrations can all expose PHI outside the intended boundary.
Are Dropbox integrations covered by its BAA?
Dropbox states that third-party apps and integrations are not part of its included services and are not covered by Dropbox terms, including its BAA. Each connected app must be evaluated independently before it receives PHI.
Will Dropbox sign a BAA?
Dropbox says eligible US-based team administrators can sign a BAA from the admin console. Confirm the current eligible plan, legal entity, covered services, reseller restrictions, and account-specific agreement before PHI use.
Can Dropbox be used with PHI?
Do not use this vendor with PHI until your organization verifies BAA scope, covered services, configuration, access controls, data retention, and connected integrations.
Does SOC 2 mean Dropbox is HIPAA compliant?
No. SOC 2 evidence can support security diligence, but it does not prove HIPAA compliance, confirm BAA coverage, or approve PHI use. Review HIPAA terms, BAA scope, covered services, configuration, and intended workflow separately.
What should buyers verify before using Dropbox with PHI?
Whether the account and plan are currently eligible and the correct legal entity has executed Dropbox's BAA before PHI is introduced. Which Dropbox products, support services, AI features, APIs, transfer tools, signatures, previews, and account regions are covered or excluded. How administrators enforce MFA, SSO, least privilege, external sharing, link expiration, device approval, audit logs, retention, deletion, and recovery. Whether every third-party app, backup, e-signature, endpoint, support workflow, and downstream destination has appropriate separate review and coverage.
Last checked and source notes
- Last checked
- 2026-10-01
- Confidence
- High
- Dataset rows
- 274 vendors
- Reviewed Dropbox's HIPAA/HITECH help page, Business Agreement, and trust materials on 2026-10-01.
- Dropbox suitability remains conditional on the eligible team account, executed BAA, covered services, customer controls, devices, sharing, and integrations.
- ComplySaaS did not verify a private Dropbox contract, signed BAA, admin-console state, or customer-specific configuration.
- Dropbox and HIPAA/HITECH
- Dropbox Business Agreement
- Dropbox Trust Center