
A BAA can be signed electronically via the Account page of the Admin Console.ĭropbox allows third party apps to be used, although it is important to note that they are not covered by the BAA. To avoid a HIPAA violation, the BAA must be obtained before any file containing PHI is uploaded to a Dropbox account. Dropbox is classed as a business associate so a BAA is required.ĭropbox will sign a business associate agreement with HIPAA-covered entities. The Health Insurance Portability and Accountability Act requires covered entities to enter into a business associate agreement (BAA) with an entity before any protected health information (PHI) is shared. That said, healthcare organizations can use Dropbox to share or store files containing protected health information without violating HIPAA Rules. No software or file sharing platform can be HIPAA compliant as it depends on how the software or platform is used. Healthcare organizations can benefit from using Dropbox, but is Dropbox HIPAA compliant? Can the service be used to store and share protected health information? Is Dropbox HIPAA Compliant?ĭropbox is a popular file hosting service used by many organizations to share files, but what about protected health information? Is Dropbox HIPAA compliant?ĭropbox claims it now supports HIPAA and HITECH Act compliance but that does not mean Dropbox is HIPAA compliant.
