The Best HIPAA Compliant Cloud Storage
Healthcare data breaches hit a new annual record in 2025: 772 large breaches reported to the HHS Office for Civil Rights, each affecting 500 or more individuals. Since OCR started tracking in 2009, more than 1 billion patient records have been exposed across roughly 7,400 reported incidents, a number that exceeds the entire U.S. population nearly three times over. If your organization handles protected health information and hasn't scrutinized its cloud storage vendor's HIPAA posture recently, this is the year to do it.
This guide covers what HIPAA-compliant cloud storage actually requires, which major providers meet the bar in 2026, and where the real risk in a cloud storage decision usually hides (hint: it's rarely the storage layer itself).
What HIPAA actually requires from a cloud provider
HIPAA, the Health Insurance Portability and Accountability Act, sets federal rules for protecting patient data. The Privacy Rule and Security Rule together govern how Protected Health Information (PHI), anything that identifies a patient and relates to their care, must be handled, stored, and transmitted.
There is no such thing as an official "HIPAA certified" cloud storage product. HIPAA has no certification body. What actually happens is a Business Associate Agreement (BAA): a legal contract between you (the covered entity) and the vendor (the business associate) that obligates the vendor to protect PHI to HIPAA's standards. Without a signed BAA in place, storing PHI on that platform is a violation regardless of how good the vendor's security actually is.
Recommended reading: Rising cyber attacks on US hospitals
Why this matters more in 2026 than it did a few years ago
The threat environment shifted meaningfully after 2024. The Change Healthcare ransomware attack that year exposed an estimated 192.7 million individuals' data, the largest healthcare breach ever recorded, and it wasn't an isolated event. In 2025, Conduent Business Services disclosed a breach affecting more than 62 million people, and Aflac reported almost 14 million affected. Hacking and IT incidents combined now account for more than 80% of large healthcare breaches, up sharply from 49% back in 2019.
The HIPAA Journal put it plainly in its September 2026 update: "If you have ever received any healthcare services or bought health insurance, your data is likely to have been breached, and quite possibly multiple times." That's not a scare tactic, it's a fair reading of the numbers: more than one billion patient records exposed against a US population of roughly 340 million.
The financial exposure for non-compliance has also gone up. As of the 2026 inflation adjustment, HIPAA Tier 4 violations (uncorrected neglect) carry penalties up to $2,190,294 per year, and even Tier 1 violations, ones made despite reasonable effort, can run up to $73,011 per violation. State attorneys general layer on additional exposure: Massachusetts and Connecticut jointly pursued a $515,000 state-level settlement against one vendor in 2025 on top of a separate $75,000 federal OCR settlement for the same underlying breach.
Cloud storage vendors that support HIPAA compliance in 2026
A quick correction to something that used to trip people up: cloud vendors don't sign your custom BAA. As one 2026 compliance guide from NetSys put it, checked as of September 2026, "Microsoft says it cannot use a customer's BAA, and Google offers its amendment for acceptance in the Admin console." That's normal and doesn't indicate weaker protection, it's just how the major platforms scaled BAA administration.
Google Workspace / Google Cloud
Google will sign its standard HIPAA amendment through the Admin console once you're on an eligible plan. As of 2026, Google's Gemini models are integrated into Workspace under the same BAA coverage for covered services, which matters if your teams are using AI features on top of stored documents. Confirm which specific services are covered before assuming everything in the suite qualifies; not every Google product falls under the BAA.
Amazon Web Services (S3 and related services)
AWS covers HIPAA-eligible services, including S3, under its standard BAA, and now extends that coverage to Amazon Bedrock for organizations running AI workloads against PHI. AWS remains the choice for teams with dedicated engineering resources who want fine-grained control over encryption, access policies, and disaster recovery configuration, but that flexibility comes with more configuration responsibility resting on your team, not AWS's.
Microsoft 365 / OneDrive / Azure
Microsoft's HIPAA BAA applies by default to enterprise agreement customers using eligible services, and now extends to Microsoft 365 Copilot and Azure OpenAI under the Microsoft Online Services DPA. Independent audits under ISO/IEC 27001 and HITRUST CSF certification back this up. For organizations already standardized on Office applications, this is usually the path of least friction.
Box
Box has maintained HIPAA-aligned features since 2012 and continues to publish healthcare-specific guidance. Its access control and activity monitoring features remain solid choices for organizations that need granular permission structures without heavy custom engineering.
Dropbox Business
Dropbox Business supports role-based access controls and HIPAA-aligned identity management, and remains a reasonable choice for smaller healthcare practices that want compliance without a steep technical learning curve.
What actually makes a provider trustworthy, beyond the marketing page
Every vendor above will point to encryption and access controls in their sales material. That's table stakes now, not a differentiator. The attributes that actually separate a well-run HIPAA program from a checkbox exercise:
Independent audit evidence, not just a claim
Ask for the actual SOC 2 Type II report or HITRUST certificate, not a summary page. Anyone can write "HIPAA compliant" on a website; a current third-party audit report is harder to fake.
Clear scope on what's covered under the BAA
This is where I've seen organizations get burned: they sign a BAA covering core storage, then enable a new AI feature or integration that isn't in scope, and PHI flows through an uncovered service without anyone noticing until an audit catches it. Re-review your BAA scope every time you turn on a new feature.
Incident response and breach notification timelines
HIPAA requires notification within 60 days of discovering a breach. Your vendor's contractual commitment to notify you should be faster than that, ideally within 72 hours, so you have runway to meet your own regulatory deadline.
Third-party and subprocessor risk
Your cloud vendor almost certainly uses subprocessors of its own. Ask what visibility you have into that chain. The Conduent and Change Healthcare breaches both involved business associates several steps removed from the actual patient relationship, which is exactly the blind spot that gets exploited.
The tradeoff nobody likes to say out loud
Compliance is not the same as security. A vendor can meet every HIPAA technical requirement and still get breached, because HIPAA sets a floor, not a ceiling. If your organization is handling high volumes of sensitive PHI, or if you're a business associate several steps removed from the patient (a lab, a billing processor, a clearinghouse), treat HIPAA compliance as the minimum bar and invest further in monitoring, employee training, and incident response planning specifically because those are the categories where recent mega-breaches actually originated, not gaps in the underlying cloud infrastructure.
Conclusion
OCR maintains a public breach portal listing every organization that's reported a large breach, and it's a list prospective patients and partners increasingly check. Choosing a cloud provider with a current BAA is necessary but not sufficient. Pair it with a real understanding of what's covered, active monitoring of your own configuration, and a incident response plan you've actually tested, not just written down.
