{"id":935,"date":"2021-08-10T09:36:00","date_gmt":"2021-08-10T09:36:00","guid":{"rendered":"https:\/\/www.123formbuilder.com\/wp-blog\/?p=935"},"modified":"2022-12-20T08:51:19","modified_gmt":"2022-12-20T08:51:19","slug":"is-dropbox-hipaa-compliant","status":"publish","type":"post","link":"https:\/\/www.123formbuilder.com\/blog\/is-dropbox-hipaa-compliant","title":{"rendered":"Is Dropbox HIPAA Compliant?"},"content":{"rendered":"\r\n<p>Dropbox is one of the leading file sharing and storing services currently on the market. As of writing this, it has\u00a0<a href=\"https:\/\/expandedramblings.com\/index.php\/dropbox-statistics\/\" target=\"_blank\" rel=\"nofollow noopener\">700 million users<\/a>\u00a0and its revenue for 2020 was $1.914 billion. Many businesses and organizations worldwide use Dropbox, and that includes HIPAA-covered entities.<\/p>\r\n\r\n\r\n\r\n<p>Medical organizations need to be careful when\u00a0<a href=\"\/blog\/hipaa-compliant-file-sharing\">choosing a file sharing<\/a>\u00a0and\u00a0<a href=\"\/blog\/hipaa-compliant-server-requirements\">storing service<\/a>\u00a0as they need to find a provider that will help them stay HIPAA compliant. If you want to keep your business away from legal and financial problems, you need a safe and trustworthy provider.<\/p>\r\n\r\n\r\n\r\n<p>So is Dropbox HIPAA compliant? Let\u2019s take a closer look.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\" id=\"h2-0\">Healthcare Vendors and BAA<\/h2>\r\n\r\n\r\n\r\n<p>Since healthcare providers are covered entities under<a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/privacy\/laws-regulations\/index.html\" target=\"_blank\" rel=\"nofollow noopener\">\u00a0HIPAA regulations<\/a>, they are responsible to comply with all HIPAA rules and ensure the accessibility and protection of all health information. And since HIPAA regulates how PHI is used, accessed, and transferred, it\u2019s relevant for file sharing and storing.<\/p>\r\n\r\n\r\n\r\n<p>If a covered entity works with a third party that encounters PHI in any way, that third party is known as a business associate. All business associates need to sign a business associate agreement (BAA). This agreement ensures that both parties understand and follow all HIPAA rules and regulations.<\/p>\r\n\r\n\r\n\r\n<p>So, the first condition Dropbox needs to meet to be HIPAA-compliant is to offer BAAs to any covered entity that requests one. And while users of the free version of Dropbox aren\u2019t offered a BAA, paid users can ask for a BAA and get one without any issues.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\" id=\"h2-1\">Is Dropbox HIPAA Compliant?<\/h2>\r\n\r\n\r\n\r\n<p>Yes, Dropbox is HIPAA compliant. You\u2019ll be happy to know that if you set up your account correctly and choose the paid version of Dropbox, the service will meet all HIPAA regulations. As we already stated, Dropbox is willing to sign a BAA with any HIPAA-covered entity that purchases the paid version of their service.<\/p>\r\n\r\n\r\n\r\n<p>HIPAA violations shouldn\u2019t be taken lightly. Medical centers can be fined up to millions of dollars for breaking HIPAA regulations, have their entire organization investigated, and even shut down. And not to mention that if you break these regulations, you will also lose your patients\u2019 trust.<\/p>\r\n\r\n\r\n\r\n<p>Companies that need to follow HIPAA standards can easily do that through Dropbox\u2019s settings. You can monitor how PHI is used, limit who can gain access to it, and take advantage of other useful features that will help you avoid any legal problems and expensive fines.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\" id=\"h2-2\">But Still\u2026<\/h2>\r\n\r\n\r\n\r\n<p>When asking the question\u00a0<em>Is Dropbox HIPAA compliant<\/em>, we also need to take into consideration that it\u2019s still a digital tool. And like many other tools, it collects metadata about its users. They gather this metadata based on user interactions with the system and over time, create a general map of their use.<\/p>\r\n\r\n\r\n\r\n<p>Since the contents of this collected metadata get scraped automatically, you can\u2019t be completely sure if Dropbox keeps any PHI information that you didn\u2019t encrypt. And since metadata isn\u2019t protected by a BAA, this is the only thing that might make us question if Dropbox truly is HIPAA-compliant.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\" id=\"h2-3\">How to Use Dropbox to Remain Compliant<\/h2>\r\n\r\n\r\n\r\n<p>The simplest answer to the question\u00a0<em>Is Dropbox HIPAA-compliant<\/em>\u00a0is yes, but only if you follow these steps:<\/p>\r\n\r\n\r\n\r\n<ul class=\"wp-block-list\">\r\n<li><strong>Set up the account first<\/strong>. Before you transfer any PHI, you need to set up your account properly to ensure it\u2019s HIPAA compliant. You can only do this if you\u2019re a paid user.<\/li>\r\n<li><strong>Sign a BAA<\/strong>. You can do that on your Dropbox admin page.<\/li>\r\n<li><strong>Set up security features<\/strong>. Go to settings to enable two-factor authentication and set up who can access, receive, and send files.<\/li>\r\n<li><strong>Disable permanent deletion<\/strong>. Since patients have the right to a copy of their medical records whenever they request them, you need to keep their files.<\/li>\r\n<li><strong>Monitor Dropbox usage<\/strong>. Limiting access isn\u2019t enough. Instruct an admin to check the account regularly and look for any signs of unauthorized parties who are accessing PHI.<\/li>\r\n<li><strong>Avoid third-party apps<\/strong>. There are certain third-party apps that could add better functionality and security to your Dropbox account. However, as they aren\u2019t covered under the BAA, you\u2019ll sign with Dropbox, so you can\u2019t be sure they\u2019ll comply with HIPAA regulations.<\/li>\r\n<\/ul>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\" id=\"h2-4\">Configure Your Dropbox Accounts Carefully<\/h2>\r\n\r\n\r\n\r\n<p>It\u2019s possible to violate HIPAA regulations when using Dropbox, so you need to be very careful when you\u2019re configuring your account. To avoid any issues, you need to do things such as configuring sharing permissions, enabling two-step verification, and all the other steps we mentioned.<\/p>\r\n\r\n\r\n\r\n<p>One of the most important things you need to remember is that you should never allow any unauthorized individuals to access PHI on your Dropbox account. So, make sure admins do regular checks and check reports Dropbox produces for all user activities.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\" id=\"h2-5\">HIPAA Compliance = Dropbox + ?<\/h2>\r\n\r\n\r\n\r\n<p>If you want your HIPAA compliance to be guaranteed, there is a secret ingredient you should use along with Dropbox. This tool and our <a href=\"\/\">form builder<\/a>, 123FormBuilder, are the perfect match you\u2019ve been looking for. We created <a href=\"https:\/\/www.123formbuilder.com\/hipaa-compliant-forms\/\">HIPAA-compliant forms<\/a>\u00a0with\u00a0<a href=\"https:\/\/www.123formbuilder.com\/dropbox-integration\/\">Dropbox integration<\/a>\u00a0that allow you to create safe forms and send them right to your Dropbox account.<\/p>\r\n\r\n\r\n\r\n<p>Best of all, not only are the forms you build with 123FormBuilder secure, but they\u2019re also incredibly easy to make. In just a few clicks, you\u2019ll be able to create your form, ask people who are using that form for files, and easily upload them to your Dropbox account. HIPAA compliance has never been easier.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\" id=\"h2-6\">Conclusion<\/h2>\r\n\r\n\r\n\r\n<p>To sum up, Dropbox is HIPPA compliant and many businesses use it across the globe. However, you should be careful about the way you capture the data. Luckily, you don\u2019t have to look far. Combining Dropbox with our solution is the best choice you can make.<\/p>\r\n","protected":false},"excerpt":{"rendered":"<p>Dropbox is one of the leading file sharing and storing services currently on the market. As of writing this, it has\u00a0700 million users\u00a0and its revenue for 2020 was $1.914 billion. Many businesses and organizations worldwide use Dropbox, and that includes HIPAA-covered entities. Medical organizations need to be careful when\u00a0choosing a file sharing\u00a0and\u00a0storing service\u00a0as they need [&hellip;]<\/p>\n","protected":false},"author":31,"featured_media":936,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[18],"tags":[],"class_list":["post-935","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-level-up-your-forms"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v24.2 (Yoast SEO v27.2) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Is Dropbox HIPAA Compliant? | 123FormBuilder Blog<\/title>\n<meta name=\"description\" content=\"Dropbox is one of the leading file sharing and storing services currently on the market. So, is Dropbox HIPAA compliant? Let\u2019s take a closer look.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.123formbuilder.com\/blog\/is-dropbox-hipaa-compliant\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Is Dropbox HIPAA Compliant?\" \/>\n<meta property=\"og:description\" content=\"Dropbox is one of the leading file sharing and storing services currently on the market. So, is Dropbox HIPAA compliant? Let\u2019s take a closer look.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.123formbuilder.com\/blog\/is-dropbox-hipaa-compliant\" \/>\n<meta property=\"og:site_name\" content=\"123FormBuilder Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-08-10T09:36:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-12-20T08:51:19+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.marketing123.123formbuilder.com\/wp-content\/uploads\/sites\/2\/2022\/01\/is-dropbox-hipaa-compliant-min.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"667\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Oscar Erk\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Oscar Erk\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Is Dropbox HIPAA Compliant? | 123FormBuilder Blog","description":"Dropbox is one of the leading file sharing and storing services currently on the market. So, is Dropbox HIPAA compliant? Let\u2019s take a closer look.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.123formbuilder.com\/blog\/is-dropbox-hipaa-compliant","og_locale":"en_US","og_type":"article","og_title":"Is Dropbox HIPAA Compliant?","og_description":"Dropbox is one of the leading file sharing and storing services currently on the market. So, is Dropbox HIPAA compliant? Let\u2019s take a closer look.","og_url":"https:\/\/www.123formbuilder.com\/blog\/is-dropbox-hipaa-compliant","og_site_name":"123FormBuilder Blog","article_published_time":"2021-08-10T09:36:00+00:00","article_modified_time":"2022-12-20T08:51:19+00:00","og_image":[{"width":1000,"height":667,"url":"https:\/\/cdn.marketing123.123formbuilder.com\/wp-content\/uploads\/sites\/2\/2022\/01\/is-dropbox-hipaa-compliant-min.jpeg","type":"image\/jpeg"}],"author":"Oscar Erk","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Oscar Erk","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.123formbuilder.com\/blog\/is-dropbox-hipaa-compliant#article","isPartOf":{"@id":"https:\/\/www.123formbuilder.com\/blog\/is-dropbox-hipaa-compliant"},"author":{"name":"Oscar Erk","@id":"https:\/\/www.123formbuilder.com\/blog\/#\/schema\/person\/cdebd32c7d95dbb692eb685554790929"},"headline":"Is Dropbox HIPAA Compliant?","datePublished":"2021-08-10T09:36:00+00:00","dateModified":"2022-12-20T08:51:19+00:00","mainEntityOfPage":{"@id":"https:\/\/www.123formbuilder.com\/blog\/is-dropbox-hipaa-compliant"},"wordCount":965,"publisher":{"@id":"https:\/\/www.123formbuilder.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.123formbuilder.com\/blog\/is-dropbox-hipaa-compliant#primaryimage"},"thumbnailUrl":"https:\/\/cdn.marketing123.123formbuilder.com\/wp-content\/uploads\/sites\/2\/2022\/01\/is-dropbox-hipaa-compliant-min.jpeg","articleSection":["Form Tips"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.123formbuilder.com\/blog\/is-dropbox-hipaa-compliant","url":"https:\/\/www.123formbuilder.com\/blog\/is-dropbox-hipaa-compliant","name":"Is Dropbox HIPAA Compliant? | 123FormBuilder Blog","isPartOf":{"@id":"https:\/\/www.123formbuilder.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.123formbuilder.com\/blog\/is-dropbox-hipaa-compliant#primaryimage"},"image":{"@id":"https:\/\/www.123formbuilder.com\/blog\/is-dropbox-hipaa-compliant#primaryimage"},"thumbnailUrl":"https:\/\/cdn.marketing123.123formbuilder.com\/wp-content\/uploads\/sites\/2\/2022\/01\/is-dropbox-hipaa-compliant-min.jpeg","datePublished":"2021-08-10T09:36:00+00:00","dateModified":"2022-12-20T08:51:19+00:00","description":"Dropbox is one of the leading file sharing and storing services currently on the market. So, is Dropbox HIPAA compliant? Let\u2019s take a closer look.","breadcrumb":{"@id":"https:\/\/www.123formbuilder.com\/blog\/is-dropbox-hipaa-compliant#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.123formbuilder.com\/blog\/is-dropbox-hipaa-compliant"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.123formbuilder.com\/blog\/is-dropbox-hipaa-compliant#primaryimage","url":"https:\/\/cdn.marketing123.123formbuilder.com\/wp-content\/uploads\/sites\/2\/2022\/01\/is-dropbox-hipaa-compliant-min.jpeg","contentUrl":"https:\/\/cdn.marketing123.123formbuilder.com\/wp-content\/uploads\/sites\/2\/2022\/01\/is-dropbox-hipaa-compliant-min.jpeg","width":1000,"height":667,"caption":"Is Dropbox HIPAA Compliant"},{"@type":"BreadcrumbList","@id":"https:\/\/www.123formbuilder.com\/blog\/is-dropbox-hipaa-compliant#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https:\/\/www.123formbuilder.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Form Tips","item":"https:\/\/www.123formbuilder.com\/blog\/tag\/level-up-your-forms"},{"@type":"ListItem","position":3,"name":"Is Dropbox HIPAA Compliant?"}]},{"@type":"WebSite","@id":"https:\/\/www.123formbuilder.com\/blog\/#website","url":"https:\/\/www.123formbuilder.com\/blog\/","name":"123FormBuilder Blog","description":"","publisher":{"@id":"https:\/\/www.123formbuilder.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.123formbuilder.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.123formbuilder.com\/blog\/#organization","name":"123FormBuilder Blog","url":"https:\/\/www.123formbuilder.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.123formbuilder.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/cdn.marketing123.123formbuilder.com\/wp-content\/uploads\/sites\/2\/2020\/12\/logo.png","contentUrl":"https:\/\/cdn.marketing123.123formbuilder.com\/wp-content\/uploads\/sites\/2\/2020\/12\/logo.png","width":131,"height":25,"caption":"123FormBuilder Blog"},"image":{"@id":"https:\/\/www.123formbuilder.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.123formbuilder.com\/blog\/#\/schema\/person\/cdebd32c7d95dbb692eb685554790929","name":"Oscar Erk","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/afa59182d087bbb3a497493c89d3791b8d8f86724a08cf49ee5e55c34f1c4305?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/afa59182d087bbb3a497493c89d3791b8d8f86724a08cf49ee5e55c34f1c4305?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/afa59182d087bbb3a497493c89d3791b8d8f86724a08cf49ee5e55c34f1c4305?s=96&d=mm&r=g","caption":"Oscar Erk"},"url":"https:\/\/www.123formbuilder.com\/blog\/author\/oscar-erk123formbuilder-com"}]}},"acf":[],"_links":{"self":[{"href":"https:\/\/www.123formbuilder.com\/blog\/wp-json\/wp\/v2\/posts\/935","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.123formbuilder.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.123formbuilder.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.123formbuilder.com\/blog\/wp-json\/wp\/v2\/users\/31"}],"replies":[{"embeddable":true,"href":"https:\/\/www.123formbuilder.com\/blog\/wp-json\/wp\/v2\/comments?post=935"}],"version-history":[{"count":5,"href":"https:\/\/www.123formbuilder.com\/blog\/wp-json\/wp\/v2\/posts\/935\/revisions"}],"predecessor-version":[{"id":2911,"href":"https:\/\/www.123formbuilder.com\/blog\/wp-json\/wp\/v2\/posts\/935\/revisions\/2911"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.123formbuilder.com\/blog\/wp-json\/wp\/v2\/media\/936"}],"wp:attachment":[{"href":"https:\/\/www.123formbuilder.com\/blog\/wp-json\/wp\/v2\/media?parent=935"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.123formbuilder.com\/blog\/wp-json\/wp\/v2\/categories?post=935"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.123formbuilder.com\/blog\/wp-json\/wp\/v2\/tags?post=935"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}