Your billing coordinator scanned 2,800 paper superbills last quarter and dropped the PDFs into a shared cloud folder so the remote coder could reach them. Nobody signed a contract with the storage vendor. Nobody checked whether the folder was set to "anyone with the link." That is the moment your practice acquired a HIPAA compliant cloud storage problem — and it happened three months before anyone in compliance heard about it.

This article is written for the person who has to clean that up: the practice owner, privacy officer, or compliance lead. It covers which controls the Security Rule actually requires, where the vendor's responsibility ends and yours begins, what documentation an investigator asks for first, and a sequenced plan you can run in 30 days. No vendor rankings. No clinical guidance. Just obligations, evidence, and order of operations.

What Makes Cloud Storage HIPAA Compliant?

Cloud storage is HIPAA compliant when four things are true at the same time:

  • A signed Business Associate Agreement is in place with the storage provider before any PHI is uploaded, and it covers subcontractors the provider uses.
  • The service is configured with unique user accounts, role-based access, audit logging, and encryption in transit and at rest.
  • Your risk analysis names the service and documents the threats to PHI stored in it, plus the safeguards you chose in response.
  • Your workforce policies govern its use — who may upload, who may share externally, and how access ends the day someone leaves.

No product is "HIPAA certified." HHS does not certify, endorse, or approve software, and any vendor claiming a government seal is selling you a story. A SOC 2 report or HITRUST assessment tells you something useful about the provider's controls, but it is evidence, not absolution. Your practice remains the covered entity on the hook.

The Conduit Exception Does Not Cover Storage

Practices sometimes argue that a cloud vendor is just a pipe — like the postal service — and therefore not a business associate. HHS closed that door explicitly. Its guidance on HIPAA and cloud computing states that a cloud service provider that creates, receives, maintains, or transmits ePHI on your behalf is a business associate, and that the conduit exception is narrow — limited to transmission-only services with transient storage.

The guidance goes further on a point that surprises people: a provider that stores only encrypted PHI and holds no decryption key is still a business associate. Encryption reduces risk. It does not remove the contractual obligation. "They can't read it" is not a defense for having no BAA.

The same logic applies to the consumer tier of services your staff already use. Free personal accounts almost never come with a BAA, and the enterprise tier that does often requires an explicit administrative setting to enable HIPAA-eligible configuration. Buying the right SKU and never flipping that switch is a common, expensive mistake.

Get the BAA Signed Before the First Upload

The sequence matters. A BAA executed after a breach does not retroactively cover the period when PHI sat in an uncontracted service. Investigators ask for the effective date, and they compare it to the date PHI first moved.

A defensible agreement addresses the required elements at 45 CFR 164.504(e): permitted uses and disclosures, the obligation to safeguard, subcontractor flow-down, breach reporting timelines to you, cooperation with individual access requests, and return or destruction of PHI at termination. Watch the breach-notice clause specifically. If the vendor promises to tell you "promptly," push for a defined number of days — you have 60 days from discovery to notify individuals, and a vague vendor clause eats that window.

If you are papering agreements with a remote transcriptionist, a scanning service, or a small storage vendor that has no template of its own, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX. It is a one-time purchase, not a subscription, which matters when you need three agreements this month and none next quarter.

Track the agreements, not just the signatures

Keep a vendor register with five columns: vendor name, service description, PHI categories touched, BAA effective date, and renewal or review date. Retain the executed agreement for at least six years past termination. When someone asks "who has our data," that register is the answer — not a search of an inbox.

Where the Vendor's Job Ends and Yours Begins

Every major cloud provider publishes a shared responsibility model. Read yours. In nearly all of them, the provider secures the physical infrastructure, hypervisor, and platform. You own identity, access permissions, sharing settings, retention, and everything your workforce does inside the tenant.

That split is where most incidents live. The data center did not fail. Someone set a folder to public, or a departed medical assistant's account stayed active for eleven months.

Access control (45 CFR 164.312(a))

Assign a unique user ID to every person — no shared front-desk logins, ever. Apply least privilege: your scheduler does not need the folder of psychotherapy-adjacent records, and your marketing contractor needs no PHI at all. Turn on automatic logoff at the workstation and, where the platform supports it, session timeout in the web client. Enable multi-factor authentication for every account with PHI access. MFA is currently addressable rather than explicitly required, but the Security Rule modernization HHS proposed in January 2025 would make it and encryption mandatory, and OCR settlements have repeatedly treated its absence as an unreasonable gap.

Encryption and the breach safe harbor

Encrypt in transit (TLS) and at rest. If PHI is encrypted consistent with HHS guidance on rendering it unusable, unreadable, or indecipherable, a loss of that data is not a reportable breach. The HHS breach notification guidance points to NIST-approved methods. This is the single highest-leverage control you own: it converts a notification event into a documented non-event, provided the keys were never exposed alongside the data.

Audit controls (45 CFR 164.312(b))

Turn logging on and confirm the retention period. Many platforms default to 90 days on lower tiers, which is useless when a records dispute surfaces at month seven. Log file access, permission changes, external share creation, and administrative actions. Then assign a human to review them — monthly for small practices, weekly if you handle high volumes — and record the date, reviewer, and findings. An unreviewed log is evidence you had the capability and skipped the work.

Disable open link sharing at the tenant level. If a workflow genuinely requires external sharing — a referral packet to a specialist, records to a patient's attorney — require named-recipient sharing with expiration dates. Audit active external shares quarterly and screenshot the result.

The Documents an Investigator Asks for First

When OCR opens an investigation after a complaint or a breach report, the initial data request is predictable. Have these ready:

  1. The current security risk analysis, dated, covering all systems that create, receive, maintain, or transmit ePHI — including the cloud storage tenant.
  2. The risk management plan showing which identified risks you remediated, which you accepted, and why.
  3. Executed BAAs for every vendor touching PHI, with effective dates.
  4. Written policies on access authorization, workforce clearance, termination procedures, sanctions, and device/media controls.
  5. Training records with names, dates, and content covered.
  6. Access logs and review documentation for the period in question.
  7. The incident response record — discovery date, containment steps, risk assessment of the four factors, and notification decisions.

An incomplete or stale risk analysis appears in resolution agreements more often than almost any other finding. NIST SP 800-66r2 is the practical companion for structuring one. If building that document set from scratch is the bottleneck, tools that automate HIPAA risk analysis reports and the supporting policy set shorten the runway considerably — but the accepted risks and remediation decisions have to be yours.

Five Failure Modes That Show Up in Breach Reports

Browse the HHS breach portal for incidents affecting 500 or more individuals and the same patterns repeat.

  • Shadow storage. A clinician syncs a chart folder to a personal account to work from home. Discovered during offboarding, if ever.
  • Orphaned accounts. Termination checklist covers the EHR and badge, misses the cloud tenant. Access persists for months.
  • Misconfigured buckets. A developer or IT contractor stands up storage for a project, leaves it publicly readable, and moves on.
  • Unmanaged subcontractors. Your vendor's vendor stores backups somewhere you never evaluated. Flow-down language exists; enforcement of it does not.
  • Retention drift. PHI that should have been purged in 2019 is still sitting there in 2025, expanding the blast radius of any incident.

A 30-Day Plan With Names Attached

Days 1–5 — Inventory. Privacy officer pulls a list of every cloud service in use, including ones purchased on a staff credit card. Ask each department lead directly: "Where do you put files that don't belong in the EHR?" Expect at least one surprise.

Days 6–10 — Contract triage. For each service touching PHI, confirm a signed BAA exists and is current. Where one is missing, either execute an agreement or stop the data flow. Practice owner signs; privacy officer files.

Days 11–18 — Configuration review. IT or your managed service provider validates MFA enforcement, encryption at rest, log retention length, external sharing defaults, and the full user roster against your active employee list. Capture screenshots with dates. That's your evidence.

Days 19–25 — Update the risk analysis. Add each cloud storage service as an in-scope asset. Document threats, existing safeguards, residual risk, and the remediation owner with a target date.

Days 26–30 — Policy and training. Publish a one-page acceptable-use rule for cloud storage: approved services only, no personal accounts, no open links, report suspected exposure within 24 hours. Train the whole workforce. Log attendance. Add cloud tenant deprovisioning to the termination checklist so this never regresses.

What Good Looks Like Twelve Months Out

A practice with defensible HIPAA compliant cloud storage can produce, in under an hour: the vendor register with BAA dates, the current risk analysis naming each service, twelve months of log review sign-offs, the last quarterly external-share audit, and training records for every person with access. Nothing exotic. Just maintained.

The reason to build this now is that the failure mode is silent. Misconfigured storage produces no error message, no denied claim, no angry phone call — until it produces all three at once, usually through a patient complaint or a security researcher's email.

Start with the gap that carries strict liability and takes the least time to close: the missing contract. If you have a vendor storing PHI without a signed agreement, draft and export a Business Associate Agreement today, get it signed, and file it with an effective date. Then work the configuration list. One vendor at a time is fine; zero is not.