Cloud Storage HIPAA Compliance: Requirements and Top Providers
If you're storing protected health information anywhere outside your own servers, cloud storage hipaa compliance isn't optional. A vendor claiming to be
1. Core HIPAA requirements every cloud storage vendor must meet
Before you sign any storage contract, understand that HIPAA cloud compliance requirements aren't a single checkbox. They're a set of interlocking obligations spanning legal paperwork, technical controls, and operational discipline. A vendor that nails encryption but skips the paperwork is just as exposed as one with a signed contract and sloppy access controls. Here's what actually matters when you're vetting a provider.
Business associate agreements (BAAs)
Every cloud vendor touching protected health information must sign a business associate agreement before you upload a single record. This document legally binds the vendor to the same HIPAA obligations you carry as a covered entity, and it spells out exactly how they'll handle, store, and protect PHI on your behalf. Skip this step and you've created an unauthorized disclosure the moment data lands on their servers, regardless of how secure their infrastructure looks on paper.
No BAA means no compliant storage, no matter how good the encryption looks.
Encryption at rest and in transit
Data needs protection both while it sits on a disk and while it moves between systems. Providers should offer AES-256 encryption for stored files and TLS 1.2 or higher for anything in transit, with key management you control or can at least audit. Weak or optional encryption settings are a common gap, so confirm encryption is enforced by default rather than something you have to remember to turn on.
Access controls and audit logging
Restricting who can see PHI matters as much as encrypting it. Look for role-based access controls, mandatory multi-factor authentication, and granular permission settings that limit exposure to a need-to-know basis. Equally important is audit logging that records every access, edit, and download, since HIPAA requires you to reconstruct who touched what data and when if an incident occurs.
Breach notification and data retention
Finally, confirm the vendor's contractual commitment to notify you quickly, ideally within 24 to 72 hours, if they discover a breach involving your data. Pair that with clear data retention policies and secure deletion procedures, so PHI doesn't linger indefinitely or get discarded in ways that violate your own retention obligations.
2. Google Cloud
Google Cloud has served as a covered entity partner for years, and its healthcare-focused tooling has matured well beyond basic object storage. If your team already leans on Google Workspace or BigQuery for analytics, adding Cloud Storage into your HIPAA-compliant stack is a logical extension rather than a new vendor relationship to manage.
HIPAA safeguards and BAA coverage
Google signs a business associate agreement covering most of its core services, including Cloud Storage, Compute Engine, and BigQuery, and publishes a full list of which products fall under that BAA. Encryption at rest is enabled by default using AES-256, and Google's Identity and Access Management layer gives you granular, role-based permissions plus detailed audit logs through Cloud Audit Logs. You still own configuration decisions, so misconfigured buckets remain your liability, not Google's.
A signed BAA only protects you if you actually configure the covered services correctly.
Who it's best for
Engineering teams already invested in Google Cloud infrastructure, or those building data-heavy applications that need tight integration with BigQuery and AI/ML tools, get the most value here. It suits organizations with in-house DevOps capacity rather than teams needing a fully managed, hands-off experience.
Pricing
Standard Cloud Storage runs roughly $0.020 per GB per month for frequently accessed data, with cheaper Nearline and Coldline tiers for archival PHI. Egress and API call fees add up quickly, so model your access patterns before committing.
3. Microsoft Azure
Microsoft has spent over a decade courting healthcare IT departments, and Azure's compliance certifications reflect that focus. Hospitals and health systems already running on Windows Server or Office 365 often find Azure the path of least resistance for cloud storage hipaa compliance, since procurement and security teams are usually familiar with Microsoft's contract language already.
HIPAA safeguards and BAA coverage
Azure includes a business associate agreement as part of its Online Services Terms, covering Blob Storage, SQL Database, and most compute services without a separate signature process. Data at rest gets AES-256 encryption by default, and Azure Storage Service Encryption pairs with Azure Key Vault for organizations wanting direct control over key rotation. Role-based access control through Azure Active Directory, combined with Azure Monitor logging, gives you the audit trail HIPAA investigators expect.
Azure's biggest compliance advantage isn't a feature, it's familiarity for teams already inside the Microsoft ecosystem.
Who it's best for
Organizations with existing Microsoft enterprise agreements, or hybrid environments mixing on-premises Active Directory with cloud workloads, benefit most from Azure. It's a strong fit for hospital IT departments modernizing legacy systems rather than greenfield startups building from scratch.
Pricing
Hot-tier Blob Storage starts near $0.0184 per GB per month, with Cool and Archive tiers dropping well below that for infrequently accessed PHI. Transaction and retrieval fees on Archive storage can surprise teams that need frequent access, so map your retrieval frequency first.
4. Amazon Web Services (AWS)
AWS remains the default choice for startups and scale-ups building healthcare products from scratch, largely because its documentation and community support around HIPAA-eligible services is the deepest of any provider. If your engineering team already deploys on EC2 or Lambda, adding S3 for PHI storage keeps your architecture consolidated under one vendor.
HIPAA safeguards and BAA coverage
AWS offers a business associate addendum through AWS Artifact, covering a long list of HIPAA-eligible services including S3, EBS, RDS, and Lambda. Server-side encryption with AES-256 is available on S3 by default, and AWS Key Management Service lets you manage your own keys for tighter control. IAM policies handle role-based access, while CloudTrail logs every API call and object access for the audit trail HIPAA compliance demands.
AWS gives you the most eligible services of any provider, but that breadth means more configuration decisions land on your team.
Who it's best for
Startups and product teams building custom healthcare applications, especially those needing serverless compute alongside storage, get the most out of AWS. It suits teams with strong cloud engineering skills more than organizations wanting a turnkey, low-maintenance setup.
Pricing
Standard S3 storage costs about $0.023 per GB per month, with Glacier tiers dropping to fractions of a cent for long-term archival PHI. Data transfer and request fees can climb fast at scale, so estimate access volume before you commit to a tier.
5. Box
Box takes a different approach than the infrastructure giants above, positioning itself as a content management layer rather than raw storage. Clinical teams and back-office staff who need to share documents, images, and forms without touching a command line tend to gravitate toward Box's familiar folder-and-file interface, which makes cloud storage hipaa compliance approachable for non-technical users.
HIPAA safeguards and BAA coverage
Box signs a business associate agreement for its Business and Enterprise plans, covering document storage, sharing, and collaboration features. Encryption uses AES-256 at rest and TLS in transit, and Box KeySafe lets regulated customers manage their own encryption keys independently of Box's own infrastructure. Granular permission settings let administrators restrict folder access by role, while Box's audit trail logs downloads, edits, and sharing events for compliance reviews.
Box trades infrastructure flexibility for a compliance experience that non-engineers can actually manage themselves.
Who it's best for
Healthcare administrators, billing departments, and clinical staff sharing documents across organizations benefit most from Box's interface. It fits teams that want compliant file sharing without hiring engineers to configure cloud infrastructure.
Pricing
Business plans with HIPAA-eligible features start around $20 per user per month, with Enterprise tiers offering advanced controls at custom pricing. Costs scale with user seats rather than raw storage volume, so it favors document-heavy teams over data-heavy applications.

Next steps for your healthcare data strategy
Picking a HIPAA-compliant cloud storage vendor is only half the battle. A signed BAA and AES-256 encryption protect the data sitting in a bucket, but none of that solves the harder problem: actually getting patient data out of an EHR and into your application in the first place. Google Cloud, Azure, AWS, and Box all give you a secure place to store PHI, yet none of them handle the SMART on FHIR authorization flows, OAuth token management, or Epic and Cerner connectors your app needs to function.
That's where the real integration work happens, and it's usually where timelines stretch from weeks into months. If you're building a healthcare application and want the EHR connectivity piece solved without hiring a specialized integration team, launch your SMART on FHIR app in a couple of steps and skip the months of custom OAuth and compliance plumbing entirely.
The Future of Patient Logistics
Exploring the future of all things related to patient logistics, technology and how AI is going to re-shape the way we deliver care.