Dropbox signs a BAA electronically via the admin console for US-based team accounts on Standard, Advanced, Enterprise, Education, Business, and Business Plus tiers (not free/Plus/Family); Dropbox Sign requires its own separate BAA.
HIPAA compliant cloud storage: Dropbox vs Box vs Google Drive vs OneDrive
Every major cloud-storage service will sign a HIPAA BAA so you can store PHI documents and backups — but the qualifying plan differs sharply, from any paid Workspace seat to Box's Enterprise-only floor. Here is what each one actually requires.
4 tools compared · 4 sign a BAA · last verified 2026-05-31 · how we verify
Box has signed BAAs with healthcare/life-sciences customers since 2013, available only on Enterprise, Enterprise Plus, or Enterprise Advanced plans and requested via the Admin Console.
Google offers a HIPAA BAA to any paid Workspace/Cloud Identity customer via the Admin console (not free consumer Gmail), covering only services on the HIPAA Included Functionality list.
Google Drive is a HIPAA Included service under the Google Workspace BAA — accept it in the Admin console on any paid Workspace plan (not free consumer Gmail/Drive).
Microsoft's HIPAA BAA is included by default through the Data Protection Addendum for commercial/enterprise customers covering in-scope services; Microsoft will not sign a customer's own BAA form, and free accounts are excluded.
OneDrive and SharePoint are in scope under the Microsoft 365 / Office 365 commercial BAA — there is no separate OneDrive BAA, and free accounts are excluded.
Frequently asked questions
Which cloud storage tools sign a HIPAA BAA?
Does Dropbox sign a HIPAA BAA?
Does Box sign a HIPAA BAA?
Does Google Drive sign a HIPAA BAA?
Does OneDrive sign a HIPAA BAA?
Compare another category
See all HIPAA category comparisons →
Browse all 105 vendors by category →