Does Dropbox Offer a Business Associate Agreement (BAA) for Medical Records?
Dropbox BAA Eligibility
Yes. Dropbox offers a Business Associate Agreement to eligible team customers so you can handle Protected Health Information (PHI) in a HIPAA-compliant manner once the BAA is in place. Dropbox indicates it will sign BAAs with qualifying team plans, and HIPAA requires a BAA before any PHI is stored or transmitted in a cloud service. ([dropbox.com](https://www.dropbox.com/business/trust/compliance/certifications-compliance?utm_source=openai))
Practically, this means covered entities and business associates in US healthcare privacy programs can use Dropbox for medical records after executing the agreement and configuring the required security controls. ([dropbox.com](https://www.dropbox.com/business/trust/compliance/certifications-compliance?utm_source=openai))
Signing the BAA
Electronic BAA steps
- Log in to dropbox.com with your team admin credentials.
- Select Admin console in the left sidebar.
- Open Settings > Account > Team profile.
- Under Advanced, choose Set up BAA and follow the prompts to review and sign.
After signing, a copy of the executed Electronic BAA is automatically saved to your Dropbox account for recordkeeping. ([help.dropbox.com](https://help.dropbox.com/account-settings/business-associate-agreement?fallback=true))
Admin Console Navigation
Where to enable HIPAA-related controls
- Strengthen authentication: require two‑step verification and (optionally) configure SSO.
- Restrict external sharing: adjust team‑wide sharing to limit links/folders to internal recipients only when PHI is involved.
- Retention hygiene: disable permanent deletions for non‑admins to support record retention needs.
- Monitoring: review and export activity reports for sharing, authentication, and admin actions to detect anomalies.
These recommendations align with Dropbox’s HIPAA best‑practice guidance for team plans and should be implemented alongside your internal policies and data security regulations. ([assets.dropbox.com](https://assets.dropbox.com/documents/en/trust/getting_started_with_hipaa.pdf))
Plan Requirements
Dropbox states it will sign BAAs with team plans such as Standard, Advanced, Enterprise, and Education. Dropbox’s BAA help article also notes that the workflow applies to admins on Standard, Business, Advanced, Business Plus, and Enterprise—reflecting current plan labels across business tiers. If you’re evaluating eligibility, confirm your team is on one of these supported plans. ([dropbox.com](https://www.dropbox.com/business/trust/compliance/certifications-compliance?utm_source=openai))
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Geographic Restrictions
The ability to execute an Electronic BAA directly in the Dropbox Admin Console is available only to US‑based customers. Teams outside the United States should coordinate with Dropbox to complete agreement formalities through supported channels. ([help.dropbox.com](https://help.dropbox.com/account-settings/business-associate-agreement?fallback=true))
HIPAA itself does not prohibit storing or processing ePHI outside the US; however, it requires a BAA and a risk‑based approach to cross‑border storage and access. Your risk analysis should address data location, access paths, and vendor safeguards before enabling any international workflows. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/faq/2083/do-the-hipaa-rules-allow-a-covered-entity-or-business-associate-to-use-a-csp-that-stores-ephi-on-servers-outside-of-the-united-states/index.html?utm_source=openai))
Compliance Standards
Dropbox maintains third‑party attestations and certifications relevant to US healthcare privacy and data security regulations, including SOC examinations and ISO certifications (e.g., ISO 27001, 27017, 27018, 22301, and 27701). Dropbox also provides mappings of its controls to HIPAA/HITECH requirements to support your compliance program and due diligence. ([assets.dropbox.com](https://assets.dropbox.com/documents/en/trust/getting_started_with_hipaa.pdf))
BAA Implementation Process
Practical rollout checklist
- Scope PHI: document which files, folders, and processes will contain Protected Health Information.
- Choose an eligible plan: ensure your organization is on a supported Dropbox team tier for the Business Associate Agreement. ([dropbox.com](https://www.dropbox.com/business/trust/compliance/certifications-compliance?utm_source=openai))
- Execute the Electronic BAA: complete the Admin Console workflow and archive the agreement copy in a controlled folder. ([help.dropbox.com](https://help.dropbox.com/account-settings/business-associate-agreement?fallback=true))
- Configure security baselines: enforce two‑step verification/SSO, restrict external sharing, disable permanent deletions for non‑admins, and set up monitoring and reports. ([assets.dropbox.com](https://assets.dropbox.com/documents/en/trust/getting_started_with_hipaa.pdf))
- Train your workforce: align usage with HIPAA Compliance policies (e.g., file naming, sharing etiquette, device hygiene).
- Validate before go‑live: confirm the BAA is executed and controls are active before uploading any PHI or ePHI. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/faq/2083/do-the-hipaa-rules-allow-a-covered-entity-or-business-associate-to-use-a-csp-that-stores-ephi-on-servers-outside-of-the-united-states/index.html?utm_source=openai))
- Monitor and iterate: review logs regularly, re‑assess risks (especially for cross‑border access), and adjust Admin Console policies as needed. ([assets.dropbox.com](https://assets.dropbox.com/documents/en/trust/getting_started_with_hipaa.pdf))
Conclusion
Dropbox does offer a Business Associate Agreement for handling medical records, provided you use an eligible team plan and configure appropriate safeguards. Execute the Electronic BAA, enable the HIPAA‑aligned controls in the Admin Console, and maintain ongoing monitoring to keep PHI protected.
FAQs
Which Dropbox plans include a BAA?
Dropbox signs BAAs with qualifying team plans, including Standard, Advanced, Enterprise, and Education. The BAA signing workflow also applies to admins on Standard, Business, Advanced, Business Plus, and Enterprise plans. Check your current tier to confirm eligibility. ([dropbox.com](https://www.dropbox.com/business/trust/compliance/certifications-compliance?utm_source=openai))
How do I sign the BAA in Dropbox?
In the Admin Console, go to Settings > Account > Team profile > Advanced, then select Set up BAA to review and sign. A copy of the executed Electronic BAA is saved to your Dropbox account. ([help.dropbox.com](https://help.dropbox.com/account-settings/business-associate-agreement?fallback=true))
Is the Dropbox BAA available outside the US?
You can’t complete the Electronic BAA in the Admin Console unless your organization is US‑based. Non‑US teams should work directly with Dropbox to finalize agreement options. Regardless of location, HIPAA permits the use of cloud providers if a BAA is in place and you manage cross‑border risks appropriately. ([help.dropbox.com](https://help.dropbox.com/account-settings/business-associate-agreement?fallback=true))
What medical data does the Dropbox BAA cover?
The BAA covers Protected Health Information (including ePHI) as defined by HIPAA—individually identifiable health information in any form, held or transmitted by a covered entity or business associate. De‑identified data that meets HIPAA’s de‑identification standard is not PHI. ([hhs.gov](https://www.hhs.gov/hipaa/for-professionals/special-topics/hipaa-ftc-act/index.html?utm_source=openai))
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.