Practice administrator reviewing HIPAA-compliant cloud software at a medical office workstation

HIPAA-Compliant Cloud Services: A 2026 Guide for SMBs

August 06, 2026

A dental practice in Coral Gables thought they were covered. They'd switched to a popular cloud storage app for sharing patient intake forms, the kind you see advertised everywhere. It was convenient, it worked, and everyone loved it. Then the OCR audit came. The app had no Business Associate Agreement on file, no audit logs, and no encryption at rest. The fine landed at $85,000 and cost the practice administrator six weeks of documentation scrambles she'll never get back.

That story isn't unusual. According to the HHS Office for Civil Rights, over 60% of HIPAA enforcement actions in 2025 involved third-party vendors or cloud services that weren't properly vetted. The question "what cloud services are HIPAA compliant?" sounds simple, but the answer requires you to look past the marketing page and into the fine print of how a platform actually handles protected health information (PHI).

If you're running a medical practice, dental office, behavioral health group, or any other covered entity in South Florida or anywhere else, this guide will help you understand what HIPAA compliance actually requires from a cloud service, which platforms meet the bar, and what steps to take before you move any PHI to the cloud.

Key Takeaways

  • A cloud service is only HIPAA compliant when it signs a Business Associate Agreement (BAA) with your practice and meets the Security Rule's technical safeguards.
  • Microsoft 365 for Business, Google Workspace for Healthcare, Dropbox Business, Box, AWS, and Azure all offer HIPAA BAAs, but the BAA must be signed before you store any PHI.
  • Free consumer tiers (Gmail, personal Dropbox, Google Drive personal) are NOT HIPAA compliant, even if you're the only one using the account.
  • Compliance isn't just about the vendor; it's also about how your staff configures and uses the service, which means your internal policies matter as much as the BAA.
  • If you're unsure whether your current cloud stack is covered, a free IT and security assessment can identify gaps before the OCR finds them first.

What Does HIPAA Actually Require from a Cloud Service?

HIPAA doesn't publish an official list of approved cloud vendors. That's a common misconception. What it does require is a structured framework that any vendor handling PHI on your behalf must meet. There are two core obligations.

The Business Associate Agreement

Any cloud vendor that creates, receives, maintains, or transmits PHI on your behalf is a business associate under HIPAA. Before that vendor touches your data, you need a signed Business Associate Agreement (BAA). This is a legal contract that commits the vendor to protecting PHI, reporting breaches, and following HIPAA's Security Rule requirements. Without a BAA, you're out of compliance regardless of how secure the platform actually is.

Actionable tip: Before migrating any patient records, intake forms, or clinical notes to a cloud service, go to the vendor's legal or compliance portal and locate their BAA. If you can't find one or if the vendor says they don't offer one, that's a disqualifying factor.

The Security Rule's Technical Safeguards

The HIPAA Security Rule also requires covered entities to implement access controls, audit controls, integrity controls, and transmission security. In cloud terms, this means the vendor must support unique user logins (no shared accounts), maintain logs of who accessed what and when, protect PHI from unauthorized alteration, and encrypt data in transit and at rest. Not every cloud service does all of these by default, even when a BAA is available.

For a deep look at how these controls apply to your practice, GDS's compliance management services can help you map your current stack against the full Security Rule checklist.

Which Major Cloud Platforms Are HIPAA Compliant?

The good news is that several widely used platforms do meet the requirements, provided you're on the right tier and you've actually signed the BAA.

Microsoft 365 for Business and Enterprise

Microsoft offers a BAA as part of their managed IT services agreements and directly through Microsoft's compliance portal. Microsoft 365 Business Basic, Standard, and Premium all qualify for a BAA, and Microsoft Azure (which underlies most of their cloud services) has a dedicated healthcare compliance framework. Exchange Online, SharePoint Online, Teams, and OneDrive for Business are all covered when you're on a qualifying plan and the BAA is in place.

Important note: Microsoft 365 Home and Personal are consumer tiers. They are not eligible for a HIPAA BAA and should never be used to handle PHI.

Google Workspace for Healthcare

Google Workspace Business Starter, Standard, and Plus, as well as Enterprise tiers, are eligible for a Google BAA. This covers Gmail (business), Google Drive, Google Docs, Google Meet, and Google Calendar when configured on a qualifying workspace domain. The key is that you must sign Google's BAA through the Google Workspace Admin Console before using these services for PHI.

Personal Gmail accounts are explicitly excluded and carry no HIPAA protections. If your staff is forwarding patient emails to their personal Gmail for convenience, that's a compliance breach in progress.

Dropbox Business and Box

Both Dropbox Business (Business Plus and higher) and Box for Healthcare offer BAAs and are frequently used by smaller practices for document storage and sharing. Box has particularly robust audit logging and access controls, making it a solid choice if your primary need is secure file storage and sharing among clinical staff.

Actionable tip: If you're currently using a personal Dropbox or the free tier of any storage service to share patient files internally, switch immediately to a business tier with a signed BAA. The free and personal tiers cannot be made HIPAA compliant by policy alone.

AWS and Microsoft Azure

If your practice management system or EHR is hosted in the cloud, it's likely running on Amazon Web Services (AWS) or Microsoft Azure. Both providers offer BAAs and have dedicated HIPAA compliance programs. In this case, your EHR vendor is responsible for obtaining the BAA with AWS or Azure, and you obtain a BAA directly with your EHR vendor. The chain of agreements must be intact.

For practices considering custom integrations or automation between cloud tools, our strategic cloud solutions team can design an architecture that keeps every link in that chain documented and compliant.

What About Zoom, DocuSign, and Other Tools?

Zoom for Healthcare (a specific paid plan) offers a BAA. Standard Zoom does not. DocuSign offers a BAA on Business and Enterprise plans. DocuSign Healthcare is purpose-built for PHI workflows. The pattern repeats across most enterprise SaaS tools: there's a healthcare or business tier that includes a BAA, and a consumer or free tier that doesn't.

Red Flags That Mean a Cloud Service Isn't Ready for PHI

Knowing which platforms qualify is helpful, but you also need to know when to walk away. Here are the most common warning signs.

No BAA Available

If a vendor doesn't offer a BAA, that's a hard stop. Some vendors will tell you that their platform is "secure" or "encrypted" as a substitute for a formal agreement. That's not how HIPAA works. Without a signed BAA, you have no contractual basis for using their service with PHI, and you're taking on full liability for any breach that occurs.

Free Consumer Tier

As noted above, the free tiers of virtually every major cloud platform are explicitly excluded from BAA eligibility. This includes Google Drive personal, personal Gmail, free Dropbox, the basic tier of Slack, and free plans from most project management and file sharing tools. If your practice is using any of these tools to handle patient information, that needs to change.

No Audit Logging

The HIPAA Security Rule requires audit controls, meaning you need to be able to answer the question "who accessed patient record X on date Y?" If a platform doesn't provide access logs or requires you to pay extra for audit reports, that's a gap in your compliance posture. This comes up frequently during OCR audits and breach investigations.

Actionable tip: Ask any cloud vendor you're evaluating to show you a sample audit report before you sign a contract. If they can't produce one or if the report doesn't include user-level detail, that tool isn't suitable for PHI storage without significant additional safeguards.

If you'd like a professional review of your current cloud setup against these criteria, request a free IT and security assessment from our team. We'll map every tool in your stack against HIPAA's requirements and tell you exactly where the gaps are.

How to Evaluate a Cloud Vendor for Your Practice

Once you've confirmed that a BAA is available, there are several additional questions worth asking before you commit.

Where Is the Data Stored?

HIPAA doesn't restrict data storage to the US, but most practices prefer to keep PHI on US-based servers for both practical and legal reasons. Confirm the vendor's data residency options and whether you can lock storage to US regions.

How Are Breaches Handled?

Your BAA will specify the vendor's breach notification obligations. Under HIPAA, a business associate must notify you of a breach within 60 days of discovery. Review the BAA's breach notification language and make sure you understand what "discovery" means to the vendor, when the clock starts, and what evidence they'll provide.

What Happens When You Leave?

Data portability and deletion are often overlooked. If you switch vendors, you need to be able to export your PHI and confirm that the old vendor has deleted all copies. The BAA should include language about data return and disposal that aligns with HIPAA's requirements.

I sat with a practice administrator last month who'd been using the same cloud storage tool for six years and had never confirmed what the vendor would do with her data if she canceled. The answer, buried in the terms of service, was that they retained the right to keep anonymized copies. That's a conversation worth having before you're locked in.

For practices that want help structuring their vendor evaluation process, our cybersecurity services include vendor risk management support and documentation you can use for your HIPAA compliance records. We also cover this in more detail in our post on vendor BAA gaps that most practices miss.

Actionable tip: Before signing a contract with any cloud vendor that will touch PHI, send them a written questionnaire asking about data residency, breach notification timelines, subcontractor BAAs, and data deletion procedures. Their written answers become part of your compliance documentation.

What to Do After You Choose a HIPAA-Compliant Cloud Service

Selecting the right platform is only the first step. Compliance requires ongoing attention to how your staff uses these tools.

Train Your Staff on Acceptable Use

A HIPAA-compliant cloud service doesn't protect you if an employee emails PHI to their personal account, shares a login with a colleague, or stores patient records in a personal folder that isn't covered by your business agreement. Staff training on what is and isn't acceptable use is a HIPAA requirement under the Administrative Rule, and it needs to happen at onboarding and annually.

Configure Minimum Necessary Access

The "minimum necessary" standard under HIPAA means employees should only have access to the PHI they need to do their job. In cloud platforms, this translates to role-based access controls: your billing team shouldn't have access to clinical notes, and your front desk shouldn't have access to financial records. Take the time to configure these controls when you set up the platform, and review them when staff roles change.

Document Everything

Your HIPAA compliance documentation should include a list of all cloud vendors with PHI access, copies of signed BAAs, your acceptable use policies, and records of staff training. If the OCR audits you, this documentation is what demonstrates your good-faith effort to comply. Without it, even a technically compliant cloud setup offers limited protection.

For a full overview of what a compliant documentation package looks like, see our earlier post on HIPAA audit readiness for small practices. And if your practice is ready to move to a fully managed IT approach for healthcare, we can take documentation and vendor management off your plate entirely.

Frequently Asked Questions

Is Google Drive HIPAA compliant?

Google Drive is HIPAA compliant when used through a qualifying Google Workspace for Business or Enterprise plan with a signed BAA in place. The personal, consumer version of Google Drive is not eligible for a BAA and should never be used to store PHI.

Does signing a BAA automatically make a cloud service HIPAA compliant?

No. A signed BAA establishes the legal obligation, but you also need to verify that the vendor implements the required technical safeguards (encryption, access controls, audit logs) and that your staff uses the service in a compliant way. The BAA is necessary but not sufficient.

Can I use iCloud for storing patient records?

Apple does not offer a HIPAA BAA for iCloud. This means iCloud cannot be used to store, transmit, or receive PHI under any circumstances. This applies to iCloud Drive, iCloud Photos, and iCloud backup of apps that contain patient information.

What's the penalty for using a non-HIPAA-compliant cloud service?

Penalties range from $100 to $50,000 per violation, capped at $1.9 million per category per year. The range depends on the level of negligence: "unknowing" violations carry lower fines, while "willful neglect" that isn't corrected triggers the maximum. Practices that self-report and cooperate with OCR investigations typically receive more favorable outcomes.

Do I need a separate BAA for every cloud service I use?

Yes. Each vendor that handles PHI needs its own BAA. If you use Microsoft 365, a cloud-based EHR, a telehealth platform, and a cloud-based billing system, each of those vendors requires a signed BAA. You should maintain a vendor list and keep copies of every BAA as part of your compliance documentation.

Ready to Get Your Cloud Setup Audit-Ready?

Understanding which cloud services are HIPAA compliant is the first step. Making sure your practice's specific tools, workflows, and staff policies are actually aligned with those requirements is where most small practices need a hand. If you're not certain your current cloud stack would pass an OCR audit, don't wait for a breach to find out.

Schedule a free IT and compliance assessment with Gradient Data Solutions. We'll review your cloud vendors, check your BAA file, and identify any gaps before they become a problem. Our team works with medical practices, dental offices, behavioral health groups, and other covered entities across South Florida, and we know what the OCR is looking for.

healthcarehipaacloud-servicescompliancecybersecurity
Back to Blog

Get Your Questions Answered

We're happy to help. Call us at (786) 386-1092 or send us a message.