Limited-time offer: LAUNCH50 gives 50% off forever. Auto-applied at checkout.See pricing

Cloud storage and file sharing

Best HIPAA-Compliant Cloud Storage for Medical Clinics

A practical evaluation guide for medical clinics choosing cloud storage that can operate under a BAA and support safe PHI handling.

Decision summary

The best HIPAA-compliant cloud storage option for a medical clinic is not the one with the most storage. It is the one that offers a signed BAA, appropriate access controls, and audit logging — and that your staff will actually use correctly.

The BAA requirement comes first

Before comparing features, storage limits, or pricing, one question determines whether a product is even eligible for PHI storage: does the vendor offer a signed BAA for your plan?

HHS published guidance in 2016 confirming that cloud service providers storing ePHI — even if they cannot access the data — are business associates and require a BAA. Any cloud storage option that does not offer a BAA is not a legal option for PHI storage, regardless of how secure it may appear technically.

What the HIPAA Security Rule actually requires

Under 45 CFR 164.312, technical safeguards for ePHI include:

  • Access controls: Unique user identification, emergency access procedures, automatic logoff, and encryption or decryption mechanisms.
  • Audit controls: Hardware, software, and procedural mechanisms to record and examine access and activity.
  • Integrity controls: Mechanisms to authenticate that ePHI has not been altered or destroyed.
  • Transmission security: Encryption for ePHI transmitted over open networks.

A product that offers a BAA but does not support these controls in its configuration does not meet the technical safeguard requirements. Audit logging, unique user access, and transmission encryption are practical minimums.

Evaluating your options

Google Workspace (Business or Enterprise)

Google offers a BAA for Business Standard, Business Plus, and Enterprise tiers. Personal accounts and free Workspace tiers are not covered. Clinics using Google Workspace must configure Drive sharing settings to prevent external sharing by default and disable consumer integrations that are not covered by the BAA. Google publishes a HIPAA implementation guide with specific configuration steps.

Microsoft 365 (Business Premium or higher)

Microsoft provides a BAA covering OneDrive for Business and SharePoint Online under qualifying Microsoft 365 plans. Audit logging, access controls, and data loss prevention policies require configuration. The default state of Microsoft 365 is not HIPAA-ready — it needs to be configured to be compliant.

Dropbox Business and Business Plus

Dropbox offers a BAA for Business-tier accounts. Personal Dropbox accounts are excluded. Dropbox Business includes granular sharing controls and an admin console with audit logs. The personal and shared folder model requires careful policy configuration to prevent accidental PHI exposure.

Box Business

Box has offered HIPAA-eligible plans with BAA coverage for Business and Enterprise tiers. Box includes file-level permissions, version history, and detailed activity logs. It is a reasonable choice for practices that need more granular document-level control than typical cloud storage provides.

What the product does not do

Cloud storage is one component of PHI security. A signed BAA and properly configured access controls do not substitute for:

  • A documented access policy specifying who can access which records
  • Staff training on appropriate use of the storage system
  • An incident response procedure for unauthorized access or data exposure
  • Periodic access reviews to confirm that departed staff no longer have access

These are administrative safeguards under 45 CFR 164.308, and they apply regardless of which storage product the clinic uses.

How PHIGuard connects to storage decisions

PHIGuard handles the administrative safeguard layer: training records, vendor BAA tracking, incident documentation, and access review tasks — all in one system with an immutable audit trail. The technical safeguard (storage product selection and configuration) is separate, but the administrative program that governs it lives in PHIGuard.

For more on PHI handling in cloud environments, read PHI in cloud workflows. For guidance on picking HIPAA software vendors, see best HIPAA-compliant EHR options for small practices.

PHIGuard commercial baseline

PHIGuard uses flat per-clinic pricing rather than per-user fees. A Business Associate Agreement is included on every public plan. The primary trial path is a 30-day free trial with no credit card required. See current PHIGuard pricing for plan names, monthly list prices, annual totals, and current launch details.

Shortlist at a glance

  1. Google Workspace (Business or Enterprise) | Google offers a BAA for Google Workspace Business Standard, Business Plus, and Enterprise tiers covering Google Drive, Gmail, and related services. Workspace for Education and personal accounts are not covered. Clinic administrators must configure sharing settings and disable unapproved consumer integrations before use.
  2. Microsoft 365 (Business Premium or higher) | Microsoft provides a BAA covering OneDrive for Business, SharePoint Online, and related services under qualifying Microsoft 365 and Azure plans. Access controls, retention policies, and audit logging require configuration — they are not on by default.
  3. Dropbox Business | Dropbox offers a BAA for Dropbox Business and Business Plus plans. Personal Dropbox accounts and Dropbox Basic are not covered. Granular sharing controls and audit logging are available on Business plans. Review the current BAA terms before use.
  4. Box Business | Box offers HIPAA-eligible plans with BAA coverage for Business and Enterprise tiers. Box includes granular permission controls, version history, and audit logs. Confirm current plan eligibility with Box before signing.

FAQ

Questions clinics ask when narrowing a shortlist

Do I need a BAA with every cloud storage vendor that touches PHI?

Yes. Under 45 CFR 164.308(b), covered entities must have a signed BAA with every business associate that creates, receives, maintains, or transmits PHI. A cloud storage provider that holds PHI is a business associate.

Is personal Google Drive HIPAA-compliant?

No. Google's BAA covers Google Workspace Business and Enterprise accounts, not personal consumer accounts. A clinic cannot store PHI in a personal Gmail or Google Drive account under HIPAA.

What technical safeguards does HIPAA require for cloud storage?

The Security Rule at 45 CFR 164.312 requires access controls, audit controls, integrity controls, and transmission security. Practically, this means unique user authentication, audit logging, encryption in transit and at rest, and documented access policies.

Is encryption at rest required by HIPAA?

Encryption at rest is an addressable specification under the Security Rule, not an absolute requirement. However, HHS guidance and best practice strongly favor encryption. Most clinics should treat it as required — the risk of operating without it is difficult to justify in a risk analysis.

Operational assurance

Move from comparison pages to a safer operating system.

PHIGuard is built for clinics that need a BAA, auditability, and recurring compliance work in one place instead of stitched across tools.

BAA included Legal baseline available on every plan.
Audit history Compliance actions stay reviewable later.
No card upfront Start evaluation before billing setup.

No credit card required. Add billing details later if you want service to continue after the trial.