
No cloud platform is "automatically" HIPAA compliant. Not AWS, not Microsoft 365, not Google Workspace. Compliance depends on how you configure the environment, what contracts you sign, and how consistently you monitor everything afterward.
This guide breaks down what "HIPAA compliant cloud storage" actually requires, who's responsible for what under the shared responsibility model, a practical checklist you can act on this week, and how to pick the right provider or IT partner.
Key Takeaways
- No cloud provider is inherently HIPAA compliant; responsibility is shared between you and the cloud service provider (CSP)
- A signed Business Associate Agreement (BAA) is legally required before any ePHI touches a cloud service
- Encryption, access controls, audit logging, and monitoring are mandatory technical safeguards
- Ongoing risk assessments and staff training keep compliance current after initial setup
What Does "HIPAA Compliant Cloud" Actually Mean?
HIPAA doesn't certify or endorse any cloud product. There's no government-issued badge you can point to. HHS has confirmed no standard requires organizations to certify compliance, and the agency doesn't endorse private HIPAA certifications either.
Major providers like AWS, Microsoft Azure, and Google Cloud support compliance. They don't guarantee it out of the box. What actually triggers the rules is the data, not the logo on the login screen.
Any cloud service that creates, receives, maintains, or transmits electronic protected health information (ePHI) falls under HIPAA's Security and Privacy Rules. That's a broad net. It covers your EHR platform, your backup system, even the file-sharing tool your billing coordinator uses to send claims.
The Business Associate Concept
Any cloud service provider (CSP) handling PHI on behalf of a covered entity is legally a Business Associate. That means they must sign a BAA before any PHI touches their systems.
Here's where things get specific by vendor:
- Microsoft 365 — Offers a BAA covering listed services through its Online Services Data Protection Addendum. Using the service alone does not achieve compliance
- Google Workspace — Limits its BAA to listed "Covered Services." Unlisted features and products are excluded
- AWS — Provides a standard BAA through AWS Artifact, but PHI should only touch AWS's HIPAA-eligible services
- Box — Requires a signed BAA before any PHI is stored
- Dropbox Business — Team admins can sign a BAA directly in the Admin Console on qualifying plans
None of these promise that an unconfigured account or a public share link is compliant. That part's on you.

The Shared Responsibility Model: Who's Responsible for What
Think of it as a split lease. The CSP secures the building: physical security, hardware, and network infrastructure. You're responsible for what happens inside your unit: access settings, encryption choices, and who holds the keys.
AWS puts it plainly in its own shared responsibility documentation: the customer manages the guest operating system, security groups, data, and identity access management. AWS protects the infrastructure running underneath.
A concrete example: A healthcare practice using Office 365 for patient scheduling still has to:
- Enable MFA for every user account
- Restrict external sharing settings so files aren't publicly linkable
- Manage user permissions on a minimum necessary basis
If they skip these steps, Microsoft's infrastructure security means nothing. The breach happens at the configuration layer, not the data center.
A BAA Doesn't Equal Compliance
Signing a BAA is a legal prerequisite, not a compliance achievement. Misconfigured settings remain the leading cause of cloud-related breaches.
That same split applies when something goes wrong. Under the Breach Notification Rule, a CSP acting as a business associate must notify the covered entity without unreasonable delay, no later than 60 days after discovery.
The covered entity still handles notification to affected individuals, HHS, and, for breaches affecting 500+ people in one state, local media. The vendor's job stops at telling you. Yours starts there.

8 Practical Steps to Ensure HIPAA Compliance in the Cloud
HIPAA cloud compliance comes from running a clear checklist—and repeating it as your stack changes.
- Sign a BAA with every CSP before storing or transmitting any ePHI. Confirm it names the specific services you're actually using, not just the vendor's general umbrella.
- Set up granular access controls (MFA, role-based permissions, single sign-on) so ePHI is only reachable by authorized staff.
- Enable encryption for data at rest and in transit on every device that touches ePHI, following NIST-recommended standards.
- Turn on audit logging and firewall logging to track access attempts. Review logs regularly, not just when something looks wrong.
- Implement file integrity monitoring to catch unauthorized changes or deletions before they become a bigger problem.
- Classify data by sensitivity and confirm your backup and disaster recovery plans support fast recovery.
- Conduct regular HIPAA risk assessments to catch misconfigurations before an auditor or an attacker does.
- Review your BAA and configurations whenever you add new tools, integrations, or subcontractors. Compliance isn't a "set it and forget it" project. At LME Services, encryption in transit and at rest, access controls, and audit logging are included across our managed plans. For MFA setup, enable it organization-wide in Office 365's Active Users panel or Google Workspace's Admin Console under Security settings. That five-minute task closes one of the most common gaps we see.

Common Mistakes That Put Cloud-Based PHI at Risk
Most breaches don't come from sophisticated attacks. They come from overlooked settings.
- Assuming the vendor label means you're covered — a "HIPAA compliant" vendor still leaves configuration entirely in your hands
- Forgetting to update the BAA when adding new cloud tools, integrations, or subcontractors
- Leaving default sharing permissions on in Google Drive, Dropbox, or Microsoft 365, including public links that anyone can access
- Skipping ongoing staff training, leaving employees unaware of phishing risks or proper file-sharing protocols
These aren't hypothetical. OCR's 2023 enforcement actions bear this out. MedEvolve settled for $350,000 after an FTP server holding PHI for over 230,000 people was left publicly accessible.
iHealth Solutions paid $75,000 after PHI for 267 people sat exposed on an unsecured server. Neither case involved a hacker breaking in. Both involved a setting nobody double-checked.

Why Small and Mid-Size Organizations Should Work with a Managed IT Partner
Small medical practices, billing firms, and law offices rarely have in-house staff who can configure and continuously monitor complex cloud compliance settings. Most organizations under 100 employees simply can't justify hiring a full-time compliance specialist. LME Services is a Chicagoland-based, family-run managed IT and cybersecurity provider that's been doing this work since 1994. We help businesses configure Office 365, Google Workspace, and cloud backup systems to support HIPAA, SOC 2, and ISO compliance readiness. Practically, that looks like:
- 24/7 monitoring with alerting for failed MFA attempts, suspicious forwarding rules, and mass email activity
- MFA and access control setup across Office 365 and Google Workspace environments
- Encrypted backup and disaster recovery, with tested restores rather than backups that just sit there
- BAA collection and management, so you're not chasing down agreements from five different vendors on your own We worked with Hansen & Cleary, a law firm managing sensitive client files, to implement secured remote access, MFA, and encryption for their protected information. The firm moved from reactive break-fix support to comprehensive managed coverage without blowing up their annual IT budget. Our compliance-readiness engagements are quoted based on your specific scope: team size, existing tools, and industry requirements. Quotes typically turn around within 1-2 days after a discovery call. No enterprise complexity, no guessing what's included.
Frequently Asked Questions
Which cloud services are HIPAA compliant?
Microsoft 365, Google Workspace, AWS, and Box will all sign a BAA and offer compliant infrastructure. None of them guarantee compliance automatically. You still have to configure MFA, permissions, and encryption correctly.
What is the new HIPAA rule in 2026?
HHS proposed Security Rule updates in December 2024, including required MFA and encryption at rest and in transit with limited exceptions. As of now it remains a proposed rule, not finalized law, though the current Security Rule stays in effect regardless.
Do I need a BAA for every cloud tool my staff uses?
Yes. Any tool that touches ePHI, even indirectly (a file-sharing app, a scheduling tool, a backup service) requires a signed BAA before use. Skipping this step is a direct HIPAA violation.
Is Google Drive or Dropbox safe for storing patient records?
Both can be compliant if you sign a BAA and configure permissions correctly, restricting public links and enforcing MFA. Neither is safe by default straight out of the box.
What happens if my cloud vendor won't sign a BAA?
That vendor legally cannot be used to store or transmit any PHI. Choose a different provider rather than risk a violation, no matter how convenient the tool seems.
How often should we review our cloud HIPAA compliance?
At minimum, conduct a full risk assessment annually. Add a review any time you change vendors, add new integrations, or roll out a major system update.