There is no official HIPAA/HITECH certification, and Dropbox says so directly on its own help pages: "There is no official HIPAA/HITECH certification." What Dropbox offers instead is a business associate agreement (BAA), and only on its Standard, Advanced, Enterprise, and Education plans — Basic, Plus, and Family aren't in that list. Even with a BAA signed, Dropbox's own documentation puts the rest of the compliance work — sharing settings, deletion policy, access monitoring, and vetting any third-party app — on the customer.
Dropbox answers the certification question about as plainly as a vendor can. Its own help-center article on HIPAA/HITECH states: "There is no official HIPAA/HITECH certification." The same article points anyone trying to verify Dropbox's posture toward a gated resource rather than a public page: "To help you understand how we're meeting our responsibilities and requirements under HIPAA/HITECH, you can go to our Dropbox Trust Center," which requires registering with a work email before the underlying documentation becomes visible at all.
What Dropbox does offer is a business associate agreement, and only on specific business plans. Dropbox's compliance page states: "Dropbox will sign business associate agreements (BAAs) with Dropbox Standard, Advanced, Enterprise and Education customers who require them in order to comply with the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health Act (HITECH)." Those are the only plans the source names as eligible — Basic, Plus, Family, and Professional aren't listed. Signing itself is a self-serve, admin-only action, and even that carries a geographic limit: "If you're currently an admin of a Dropbox team account, you can sign a BAA electronically from the Account page in the admin console," but the compliance page adds, "[t]he ability to sign an electronic BAA via the Admin Console is available only to US-based customers." Dropbox's HIPAA/HITECH overview also states the ordering requirement plainly: "For customers subject to HIPAA/HITECH, remember that a BAA must be in place before you transfer PHI into your Dropbox account."
Signing a BAA doesn't make an account compliant by itself — Dropbox's own wording puts the rest of the work on the customer. The HIPAA/HITECH overview says: "While ultimately it's up to you make sure that you're complying with your regulatory obligations, we've put together some recommendations to help you keep your data safe and your accounts secured," and lists what that framework covers: "Configuring sharing permissions," "Disabling permanent deletions," "Monitoring account access and activity," and "Understanding the role of 3rd party apps." That last item carries a specific carve-out: third-party apps and integrations linked to a Dropbox team account sit outside the agreement — "they're not part of our included services. Therefore, they're not covered by your Dropbox terms of use, including a BAA that you might sign with Dropbox. You're responsible for evaluating these apps to determine if using them is consistent with your legal and regulatory requirements."
Two structural facts this archive has documented separately sit underneath any BAA. Dropbox's standard architecture holds the encryption keys itself rather than giving the customer sole control — this archive's entry on that design states: "In Dropbox's standard architecture the keys are held server-side by Dropbox, not derived from a passphrase only the user knows," meaning "a Dropbox employee with sufficient access, an attacker who breaches Dropbox, or a government with a valid legal order can all potentially obtain readable user files." And because Dropbox is a US company, the 2018 CLOUD Act reaches its data regardless of where the servers physically sit — this archive's entry on that law notes that a US warrant can reach an overseas user's files, and that "[a] non-US Dropbox user whose files happen to live on European infrastructure is not, by that fact, beyond the reach of a US warrant served on Dropbox." Neither fact is specific to healthcare customers, but both apply to PHI stored under a BAA the same as to any other file. Separately, if a HIPAA-covered signing workflow matters to you, note that Dropbox Sign is billed on its own per-seat subscription rather than bundled with storage — this archive's entry on that pricing documents that capabilities including "advanced compliance like HIPAA" are "staircased across the higher tiers" of Sign's separate plan ladder, so a BAA covering your storage plan doesn't automatically cover a Dropbox Sign subscription.
None of this is legal advice, and Dropbox's own help pages don't publish enough to substitute for it: if HIPAA compliance is a requirement for your organization, confirm eligibility, the BAA's actual terms, and your admin console's region directly with Dropbox in writing before storing protected health information. For the separate question of government-specific frameworks like FedRAMP and CMMC, see this archive's answer at /questions/is-dropbox-fedramp-or-cmmc-compliant, and see the related entries below on the encryption-key design, the CLOUD Act, and Dropbox Sign's separate pricing.
This answer is informational, not legal or security advice. Dropbox Watchdog is independent and not affiliated with Dropbox, Inc.