1 min read

HIPAA breaches and cloud providers

Man speaking in front of a brick wall

I think we can all agree, cloud computing is here to stay. It's cheaper, more reliable and oftentimes more secure than maintaining your own server infrastructure. Some cloud providers even offer HIPAA compliant infrastructure as an add-on service. Whether you opt to use cloud services like Google Docs or cloud solutions like Paubox, keep in mind that cloud providers must adhere to the same rules as other Business Associates.

 

Google Docs is not HIPAA compliant unless...

For example, let's take a look at a recent HIPAA breach at Oregon Health & Science University. Protected health information for over 3,000 patients was compromised after several residents and physicians-in-training inappropriately used Google docs to maintain a spreadsheet of patient data. The HIPAA violation occurred when Google did not sign a Business Associate Agreement (BAA) with OHSU. As we've covered before, a Business Associate Agreement is a contractual agreement between a covered entity and Business Associate. When a Business Associate stores, handles, or discloses protected health information on behalf of a covered entity, a BAA is required by law.

 

Choose a Cloud Service that adheres to HIPAA Regulations

If you are a covered entity, a BAA is a must for any technology vendor that handles PHI for you. Insist that all of your Business Associates sign such an agreement with you. Here at Paubox, we have a Business Associate Agreement ready for your review and signature. Contact us today to get started.

Learn more about Paubox encrypted email or contact Paubox

 
Try Paubox Email Suite for FREE today.
Google Cloud office building with signage

Is Google Cloud Identity Management HIPAA compliant? (2025 update)

Google Cloud Identity is an identity and access management (IAM) platform that provides tools for managing user accounts, authentication, and device...

Read More
Microsoft Azure logo

How do I make Microsoft Azure HIPAA compliant?

Last month, I had a call with a digital health startup in Toronto. During our call, we discussed their use of Microsoft Azure services in their...

Read More
Person holding smartphone with messaging app icon

Is Google Meet HIPAA compliant? (2026 update)

Google Meet is Google’s video conferencing platform for online meetings, calls, screen sharing, captions, recordings, transcripts, and collaboration...

Read More

Subscribe to Paubox Weekly

Every Friday we bring you the most important news from Paubox. Our aim is to make you smarter, faster.