11 Best HIPAA-Compliant Data Rooms in 2026 (Who Actually Signs a BAA)
Co-founder at Peony. Former M&A at Nomura, early-stage VC at Backed VC, and growth-equity / secondaries investor at Target Global. I write about investors, fundraising, and deal advisors from the deal-side perspective I spent years in.
11 Best HIPAA-Compliant Data Rooms in 2026 (Who Actually Signs a BAA)
Last updated: August 2026
Quick answer: The most defensibly HIPAA-compliant data rooms in 2026 are the ones that will put a Business Associate Agreement (BAA) in writing — not the ones with the most badges. Among purpose-built deal rooms, Firmex is the standout: it is the only legacy VDR that publishes BAA language on its own site, and Peony signs a BAA on request. Among general platforms, Microsoft 365, Google Workspace, Box, Dropbox, ShareFile, and Egnyte all sign BAAs (several are tier-gated). Everyone else — iDeals, Intralinks, ShareVault — claims HIPAA but publishes no BAA language, and Datasite and Ansarada make no HIPAA claim at all. The uncomfortable truth underneath all of it: there is no official HIPAA certification. HHS certifies nobody. "HIPAA-compliant" means a BAA plus the Security Rule safeguards, so every vendor badge you see is a third-party assessment, not a government seal.
I'm Sean Yu, co-founder of Peony, a virtual data room company. Over the past few weeks my team pulled up the compliance, trust, and security pages of every serious document platform a healthcare deal team might use and asked one narrow question: does this vendor claim HIPAA, and — separately — does it publicly commit to signing a BAA? Those are not the same question, and the gap between them is the single most useful thing to know before you upload protected health information. A lot of vendors put "HIPAA" on a marketing page. Far fewer will name a BAA in their own documentation, and fewer still will tell you which plan tier it requires.
This is not a neutral review. I run Peony, a data room company, so Peony is our product — weigh this entry accordingly. But the whole point of this post is a matrix that would be worthless if I fudged it, so where a competitor is genuinely stronger on compliance posture — Firmex's published BAA language, Microsoft's automatic BAA, Datasite's deep ISO stack — I say so plainly, and where Peony has a gap, I state it plainly. The goal is that a compliance officer, a corp-dev lead, or a clinic owner can read one table and know exactly who to call and what to ask for.
If you want the healthcare vertical ranking — which room fits a biotech fundraise, a clinical-stage partnering process, or a medtech deal by clinical workflow — that lives in our healthcare and life sciences data rooms guide. This post is the companion that ranks by compliance posture: who signs a BAA, on which tier, and what the badges actually mean. Read that one for workflow fit; read this one before you sign anything.
At-a-glance: who claims HIPAA vs who publicly commits to a BAA
Here is the matrix no competitor publishes. The left column is what the vendor claims about HIPAA on its own site. The middle column — the one that actually matters — is whether the vendor publicly commits to signing a BAA in its own documentation. A vendor can genuinely be a fine choice for PHI and still land in "Not stated publicly," because plenty of vendors sign BAAs privately without publishing the language; that column tracks published commitment, not private willingness. Verify everything on the vendor's own pages, not on affiliate or aggregator sites — as you will see with Ansarada below, aggregators get this wrong.
| Provider | HIPAA claim on own site | Publicly states it signs a BAA | Tier gate | Notes |
|---|---|---|---|---|
| Peony | Yes (stated on its security page) | Yes — "on request" | On request — no tier gate published | Our product. SOC 2 Type II; not ISO 27001 certified (stated honestly) |
| Firmex | Yes (verified) | Yes — published BAA language | Not stated | Only legacy VDR that publishes BAA language; SOC 2 Type 2; GDPR |
| Box | Yes | Yes — self-serve request | Enterprise, Enterprise Plus, or Enterprise Advanced | Plain "Business" tier does NOT qualify despite the name |
| Microsoft 365 | Yes | Yes — automatic, no signing | All business plans (incl. Business Basic) | BAA via the Data Protection Addendum by default; consumer accounts excluded |
| Google Workspace | Yes | Yes — admin accepts in console | Workspace (not free Gmail/Drive) | Admin accepts BAA under Legal and compliance; scope limited to Included Functionality |
| Dropbox | Yes | Yes — self-serve electronic BAA | Team plans (Standard/Advanced/Enterprise/Business/etc.) | US-based customers only; consumer tiers not eligible |
| ShareFile | Yes | Yes — under executed BAA | Premium, VDR, or Industry Advantage account | Popular with CPA and wealth-management firms |
| Egnyte | Yes | Yes — enters BAA on signup | Not stated | Only official BAA-language doc is marked "Revised April 2014" (freshness flag) |
| iDeals | Yes (3rd-party verified) | Not stated publicly | — | ISO 27001/27017/27018/27701, SOC 2 & SOC 3, GDPR; no published BAA language |
| Intralinks | Only on life-sciences page | Not stated publicly | — | HIPAA absent from /trust and healthcare pages — internally inconsistent |
| ShareVault | Yes (listed among standards) | Not stated publicly | — | Claims ISO 27001, SOC 1/2/3, PCI DSS, HIPAA, GDPR, CCPA, 21 CFR Part 11 |
| Datasite | No HIPAA claim anywhere | Not stated | — | Deepest ISO stack (first VDR ISO/IEC 42001; ISO 27001 since 2007) |
| Ansarada | No HIPAA claim — points to Firmex | Not stated | — | Its own compare page concedes Firmex holds HIPAA; aggregators wrongly call it HIPAA-compliant |

Two things to read off this table before the detail below. First, the vendors that make the BAA easiest are the general platforms — Microsoft's is automatic, Google's and Dropbox's are self-serve, and Box's is a console request — but several gate it to a specific plan, and the naming is a trap (Box's "Business" tier is not enough). Second, among purpose-built deal rooms, published BAA commitment is rare: Firmex publishes the language, Peony states it signs on request, and the rest of the legacy VDRs claim HIPAA without naming a BAA at all. The sections below explain each entry, ending with the two vendors — Datasite and Ansarada — that decline to claim HIPAA at all.
What does "HIPAA-compliant data room" actually mean?
"HIPAA-compliant data room" means a room whose vendor will sign a Business Associate Agreement with you and that implements the HIPAA Security Rule's required safeguards — nothing more official than that exists. This is the reframe the entire market gets wrong, so it is worth saying flatly: there is no official HIPAA certification. The U.S. Department of Health and Human Services does not certify, license, endorse, or seal any software as "HIPAA-compliant." No government body issues a HIPAA certificate. When a vendor says it is "HIPAA-certified," what actually exists behind that phrase is a third-party firm's assessment or the vendor's own internal program — useful evidence, but not a government approval, and not equivalent to the guarantee the word "certified" implies elsewhere.
One: the vendor signs a BAA. A Business Associate Agreement is required whenever a vendor creates, receives, maintains, or transmits protected health information on behalf of a covered entity or another business associate (45 CFR 164.502(e)). The data room stores and transmits your files; if any of those files contain PHI, the room's vendor is your business associate, and HIPAA requires a BAA between you. The BAA is the legal instrument that binds the vendor to protect the PHI, restricts how it may use it, and obligates it to report breaches. No BAA, no lawful path to put PHI in that vendor's system — regardless of how many badges the marketing page carries.
Two: the platform implements the Security Rule safeguards. The Security Rule (45 CFR Part 164, Subpart C) requires three categories of safeguards for electronic PHI:
- Administrative safeguards (45 CFR 164.308): risk analysis, workforce access management, a designated security official, and documented policies.
- Physical safeguards (45 CFR 164.310): facility access controls and device/media controls at the data centers that hold the data.
- Technical safeguards (45 CFR 164.312): access controls, audit controls, integrity controls, and transmission security — in plain terms, per-user access, a complete audit log, and encryption in transit and at rest.
A serious data room already ships the technical safeguards as table stakes: encryption, per-user permissions, and an audit trail. What separates a compliant deployment from a badge is the combination — the safeguards plus the executed BAA plus your own correct configuration. Every honest vendor on this list makes that last point: the platform can be in scope and you can still be non-compliant if you configure it wrong or skip the BAA. Firmex says it directly ("clients are responsible for configuring Firmex in a HIPAA compliant manner"), and Microsoft says it too ("using Microsoft services doesn't on its own achieve HIPAA compliance"). That honesty is the tell that a vendor understands the regime. For the full control-by-control mapping across SOC 2, GDPR, and HIPAA control mapping, that guide goes deeper than this post needs to; here, the takeaway is the reframe — chase the BAA and the safeguards, not the badge.
Which data room providers actually sign a BAA?
The providers that actually sign a BAA split cleanly into two groups: purpose-built deal rooms (Peony, Firmex) and general file platforms that will act as your business associate (Box, Microsoft 365, Google Workspace, Dropbox, ShareFile, Egnyte). Then there is a third group — iDeals, Intralinks, ShareVault — that claims HIPAA but publishes no BAA language, which I cover at the end of this section so you know exactly what to ask them. The honest difference between the two working groups is fit, not legality. A general platform is genuinely fine for ongoing operational PHI — the day-to-day storage and sharing a covered entity does inside its own walls. A deal workflow needs room controls that file-sync tools do not center: dynamic watermarking, granular guest permissions, a structured Q&A workflow, and clean audit exports. Both can be HIPAA-compliant; they are built for different jobs.
I have ranked the entries by how directly each fits a diligence or deal-room use case, which is why the two purpose-built rooms come first.
Purpose-built deal rooms
These are rooms designed for outside parties reviewing your documents under access controls — the diligence, fundraising, and licensing use case. Both entries below will put a BAA in writing.
Peony — flat-rate room that signs a BAA on request (our product)
The disclosure first: Peony is our product, so weigh this entry accordingly. With that on the table — the exact canon is that Peony signs a Business Associate Agreement (BAA) on request. That is the commitment, stated plainly — "on request," with no published tier gate. Hold us to the same standard this post applies to everyone else: ask for the BAA when you sign up, and have the executed copy in hand before PHI touches the room. Peony is SOC 2 Type II. Peony is not ISO 27001 certified — you should read that here rather than discover it in a security questionnaire. If ISO 27001 is a hard procurement requirement for you, Datasite or iDeals will satisfy it and Peony will not.
On the controls that matter for PHI in a deal room, Peony ships encryption in transit and at rest, granular per-group permissions, dynamic watermarking that stamps each viewer's name and email on every page (a Data Room-tier feature — the Business tier has screenshot protection and a simple NDA gate instead), and an exportable audit trail. On the AI question that healthcare teams ask hardest — because a room may hold clinical data or claims — the canon is exact: Peony does not train any model on your documents — AI Q&A and extraction call a third-party LLM at query time with no training and no retention. On residency, Standard plans run on US AWS (us-east-1) with Standard Contractual Clauses, and Enterprise offers custom UK/EU residency, BYOK, and self-hosted deployment for teams whose data-locality rules demand it.
Pricing is flat-rate and public: Business is $30/month, Data Room is $52/month, and Deal Team is $64/user/month with a four-seat minimum — cancel anytime. Because it is flat monthly, the deal math is predictable: a Data Room plan is $156 for a three-month deal, $312 for six months, and $624 for a year, versus per-page or per-project invoices that meter every page. Peony serves 6,800+ customers and has supported $26.3B in closed transactions, with a G2 rating of 4.8 (12 reviews) and Capterra 4.9 (19 reviews) — I cite the review counts because a 4.8 across 12 reviews is a different signal than a 4.8 across 12,000, and you should weigh it accordingly. Where Peony fits: a clinic sale, a home-health acquisition, a provider roll-up, or a clinical-data licensing room where you want deal-room controls and a BAA without an enterprise quote. Where it does not: if you need ISO 27001 on paper, look elsewhere.
Firmex — the only legacy VDR that publishes BAA language
Firmex is the standout among traditional VDRs, and it earns that on one specific fact: it is the only legacy virtual data room whose own site publishes BAA language. Firmex's own news page states that "clients using Firmex's virtual data room platform to store electronic public health records must therefore sign a Business Associate Agreement (BAA) with Firmex." That is a published, unambiguous commitment — not a private willingness you have to extract in a sales call, and not a badge on a marketing page. Firmex's HIPAA compliance is verified under the Sword and Shield HIPAA Compliance Program, and it carries SOC 2 Type 2 and GDPR. It also states the shared-responsibility caveat honestly — in Firmex's own words, "clients are responsible for configuring Firmex in a HIPAA compliant manner" — which is exactly the framing a vendor that understands HIPAA uses. One gap worth noting for completeness: ISO 27001 is not confirmed on Firmex's own pages, so if you need that certification specifically, do not assume it from the HIPAA verification.
On cost, Firmex runs roughly $150–$500/month at entry, typically $5,000–$10,000 for a three-month deal, and $25,000+/year at the enterprise end. For a healthcare M&A team that wants a traditional VDR and a BAA in writing, Firmex is the most defensible pick in the legacy tier — its published BAA language is precisely the thing every other legacy VDR here fails to provide.
General platforms that sign BAAs
These platforms are built for storing and sharing files, not for running a gated diligence process, but each will sign a BAA and act as your business associate — which makes them a legitimate home for operational PHI (the sharing a covered entity does day to day). The recurring trap across this group is the tier gate: the BAA is often restricted to specific plans, and the plan names are misleading. Read each entry for exactly which tier qualifies.
Box — signs a BAA, but the "Business" tier does not qualify
Box signs BAAs, but only on its Enterprise-family plans — and this is the single most common HIPAA mistake I see, because Box's plain "Business" tier does not qualify despite the name. Box's own HIPAA/HITECH support FAQ states that "customers who are required by law to comply with HIPAA… must have an Enterprise, Enterprise Plus, or Enterprise Advanced account with Box and sign a HIPAA Business Associate Agreement." Read that literally: a "Box Business" plan, which sounds enterprise-grade, is not on the qualifying list. To get the BAA, an admin requests it from the admin console (Request a HIPAA BAA), and Box's legal team emails the addendum, typically within three to five business days. If your team is on Box Business today and storing PHI, you are on the wrong plan for HIPAA — upgrade to an Enterprise-family tier and execute the BAA before you treat it as compliant.
Microsoft 365 — the BAA is automatic
Microsoft 365 (which includes OneDrive for Business, SharePoint Online, and Teams) has the easiest BAA of anyone on this list: it is automatic, with no signing step. Per Microsoft's HIPAA offering page, "the Microsoft HIPAA Business Associate Agreement is available through the Microsoft Online Services Data Protection Addendum by default to all customers who are covered entities or business associates under HIPAA." In-scope services explicitly include OneDrive for Business, SharePoint Online, and Teams, and it is not gated to a top business tier — even Business Basic is in scope. The honest caveats are two. First, consumer Personal and Family accounts are not the in-scope enterprise services, so a personal OneDrive is not covered. Second, Microsoft states plainly that "using Microsoft services doesn't on its own achieve HIPAA compliance" — the BAA and the in-scope services are necessary, but your configuration and safeguards still have to be right. For a covered entity that already runs on Microsoft 365, OneDrive and SharePoint are a legitimate operational PHI home out of the box.
Google Workspace — the admin accepts the BAA in the console
Google Workspace signs BAAs, and the mechanism is an admin acceptance rather than a negotiation. Per Google's HIPAA guidance page (updated July 29, 2026), "administrators must review and accept a BAA before using PHI in Google services." The path is Account settings → Legal and compliance, where a Workspace admin reviews and accepts the agreement. The important scope limit: coverage extends only to the services on Google's "HIPAA Included Functionality" list, so PHI must stay inside the in-scope services rather than roaming to every Google product. And the hard boundary — free, consumer Gmail and personal Drive are not BAA-eligible, which means a personal Google account is never a lawful home for PHI. For an organization already standardized on Workspace, accepting the BAA in the admin console and keeping PHI within Included Functionality is a clean path.
Dropbox Business — self-serve electronic BAA, US-only
Dropbox signs BAAs, and for team plans it is genuinely self-serve. Per Dropbox's HIPAA page (updated September 2025), "if you're currently an admin of a Dropbox team account, you can sign a BAA electronically from the Account page in the admin console." That electronic BAA covers the team plans — Standard, Advanced, Enterprise, Education, Business, and Business Plus — plus Dropbox Sign. Two limits define eligibility. First, geography: "the ability to sign an electronic BAA via the Admin Console is available only to US-based customers." Second, tier: the consumer plans — Basic, Plus, Professional, and Family — are not eligible, so personal Dropbox is out for PHI. For a US team already on a Dropbox business plan, signing the BAA is a few clicks in the admin console; outside the US, or on a consumer plan, it is not available through that path.
ShareFile — BAA under a named tier gate, popular with CPA and wealth firms
ShareFile (a Progress product) signs BAAs, gated to named plans and only under an executed agreement. Per ShareFile's HIPAA support documentation, "ShareFile with HIPAA support is available only with a ShareFile Premium, VDR, Industry Advantage Account," and PHI handling is supported "only under a valid, mutually executed Business Associate Agreement (BAA) with Progress." So there are two conditions, not one: the right plan and the signed BAA. ShareFile is especially common with CPA firms and wealth-management practices — a real query pattern, since those firms handle a mix of financial and occasionally health-adjacent records and want HIPAA support on a familiar platform. If you are one of those firms, confirm you are on Premium, VDR, or Industry Advantage before you rely on the HIPAA support, and get the BAA executed with Progress.
Egnyte — enters a BAA on signup, with a freshness caveat worth stating
Egnyte offers a BAA on signup, and states so directly — but the documentation raises a freshness flag I would rather surface than hide. Egnyte's HIPAA Statement says: "Egnyte is a Business Associate to its customers who are Covered Entities. As such, we will enter into a Business Associate Agreement with you upon your signing up of our service." Clear enough. The caveat: that official HIPAA Statement PDF is marked "Revised April 2014," which makes the only official BAA-language document Egnyte publishes twelve years old, while its current marketing page (which says compliance with HIPAA "is automatic with Egnyte") omits the BAA terms entirely. That does not mean Egnyte will not sign — the statement says it will — but a twelve-year-old compliance document is worth a direct question to their team about the current BAA process and terms before you rely on it. Surface it, confirm it in writing, then proceed.
Providers that claim HIPAA but publish no BAA language
Three legacy VDRs — iDeals, Intralinks, and ShareVault — assert HIPAA compliance on their own sites but do not publish any BAA language. That does not mean they won't sign one; it means their published position stops at the claim, and you have to get the BAA commitment in writing yourself. The precise distinction matters, so I am careful with the verbs: these vendors claim HIPAA compliance; I do not say they "sign BAAs," because their own pages do not.
iDeals makes the strongest HIPAA claim of the three, and grounds it in a third party. In its own words, on its security page, "Ideals compliance with HIPAA has been verified by a 3rd party, our data centers are compliant with U.S. Health Insurance Portability and Accountability Act of 1996 (HIPAA)." Its certification stack is deep — ISO 27001, ISO 27017, ISO 27018, and ISO 27701, plus SOC 2 and SOC 3, and GDPR. What is absent is any published BAA language. So iDeals is a credible HIPAA claim with a broad certification base and typical mid-market pricing of $500–$1,000/month; just get the BAA commitment explicitly before you upload PHI, because the site does not state it.
Intralinks is the internally inconsistent one, and it is worth flagging factually rather than editorializing. Intralinks claims HIPAA only on its life-sciences page — which reads "Our platform is HIPAA-compliant, ISO 27001-certified…" — but HIPAA is absent from its main /trust page and from its healthcare solutions page. The /trust page lists SOC 1, SOC 2, and SOC 3, ISO 27701, and ISO 27001, but not HIPAA. That inconsistency is not proof of anything either way; it simply means the HIPAA claim is not carried consistently across Intralinks' own compliance surface, so if HIPAA matters to you, pin it down directly with Intralinks rather than relying on the one page that mentions it. Pricing is commonly $25,000–$100,000/year.
ShareVault lists HIPAA among a broad set of standards. Its security page states that "ShareVault complies with top security standards such as ISO/IEC 27001:2013, SOC 1, 2, 3, PCI DSS, HIPAA, GDPR, and CCPA," and it also cites 21 CFR Part 11. That is a comprehensive list, but HIPAA appears as one item in a standards enumeration, not as a BAA commitment, and there is no published BAA language. On price, a ShareVault "Express" plan at $199/month circulates in third-party coverage, but treat that as quote-only — it is not vendor-published — and ShareVault's pricing is otherwise quote-based. As with the other two, the claim is real; the BAA is the thing to confirm in writing.
Which providers do NOT claim HIPAA compliance at all?
Two prominent VDRs — Datasite and Ansarada — make no HIPAA claim anywhere on their own sites, and that absence is itself informative. It is not a weakness in either platform; both are excellent at what they target. It simply means neither is positioning itself for PHI-in-the-room, and one of them says so out loud. This is the section no other comparison includes, because most listicles pull vendor claims from aggregators and never notice the ones that decline to claim.
Datasite makes no HIPAA claim on its own site — I checked both its compliance FAQ and its security FAQ, and HIPAA does not appear on either. What Datasite has instead is the deepest ISO stack in this entire group: it was the first VDR certified to ISO/IEC 42001 (the AI management standard), it has held ISO 27001 since 2007, and it maintains SOC 2 Type II annually. So Datasite is arguably the most rigorously certified platform here — it just does not certify against HIPAA specifically, and it does not publish a BAA commitment. If your deal is a large-cap M&A process where the buyer's bankers expect a Datasite room and PHI is being kept out of the room by design (de-identified diligence, records transferring post-close), Datasite's silence on HIPAA is consistent with that workflow. If PHI genuinely must enter the room, Datasite's own pages do not claim to cover it, and you should ask directly rather than assume.
Ansarada is the more striking case, because it does not merely stay silent on HIPAA — it actively concedes the point to a competitor. On Ansarada's own comparison page (ansarada.com/compare/ansarada-vs-firmex), Ansarada states: "For teams requiring direct HIPAA compliance, Firmex holds this certification directly," and adds that "for teams in healthcare, life sciences, or other HIPAA-regulated sectors, Firmex's HIPAA compliance is a meaningful differentiator." That is a vendor telling you, in its own words, to use a competitor when HIPAA is the requirement — an unusually candid signal, and a reliable one. Ansarada's own strengths are elsewhere: ISO 27001 (held for 10+ years), ISO 42001, and GDPR. Note that Ansarada does not state SOC 2 on its own pages, and it makes no HIPAA claim, consistent with pointing HIPAA-driven teams to Firmex.
There is a trap here worth stating loudly, because it is exactly the kind of error a listicle propagates: third-party aggregators claim "Ansarada is HIPAA compliant" — and Ansarada's own site contradicts them. When the vendor's own comparison page tells you to go to Firmex for HIPAA, an aggregator asserting Ansarada is HIPAA-compliant is simply wrong. This is the single best illustration of the rule that governs this whole post: verify compliance on the vendor's own pages, not on aggregators. Aggregators optimize for lead capture, not accuracy, and HIPAA is precisely the claim they get wrong. If you take one operational habit from this post, take that one.
Is Dropbox, Google Drive, or OneDrive HIPAA compliant?
Short answers first, because these three questions absorb a lot of searches from people who just want a verdict: Dropbox — yes on a team plan with a signed BAA, no on consumer tiers. Google Drive — only inside Google Workspace with an admin-accepted BAA, never on free/personal Drive. OneDrive — yes on OneDrive for Business under Microsoft's automatic BAA, no on personal accounts. The pattern across all three is identical and worth internalizing: the business version can be HIPAA-compliant with the BAA in place; the consumer version never is.
Is Dropbox HIPAA compliant? On a Dropbox team plan, yes, provided you sign the BAA — Dropbox lets a team admin sign it electronically from the admin console, and that self-serve electronic BAA is available only to US-based customers. On consumer Dropbox (Basic, Plus, Professional, Family), no — those tiers are not BAA-eligible, so personal Dropbox is not a lawful home for PHI. If you need deal-room controls on top of compliance, a purpose-built room is the better fit for diligence, but for straightforward team file-sharing, a US-based Dropbox team plan with the BAA signed is compliant.
Is Google Drive HIPAA compliant? Only through Google Workspace. Free consumer Gmail and personal Drive are not BAA-eligible and are never HIPAA-compliant for PHI. With Workspace, an administrator must review and accept a BAA before using PHI in Google services (Account settings → Legal and compliance), and PHI must stay within Google's "HIPAA Included Functionality" list. So the honest answer to "is Google Drive HIPAA compliant without Google Workspace" is a flat no — the BAA does not exist for personal accounts.
Is OneDrive HIPAA compliant? OneDrive for Business, yes — Microsoft's HIPAA BAA is available by default through its Data Protection Addendum to all customers who are covered entities or business associates, and OneDrive for Business, SharePoint Online, and Teams are explicitly in scope, without a top-tier gate. Personal OneDrive (Microsoft Personal or Family), no — those are not the in-scope enterprise services. And even on OneDrive for Business, remember Microsoft's own line: "using Microsoft services doesn't on its own achieve HIPAA compliance" — the BAA gets you the legal footing, but you still have to configure access, sharing, and retention correctly.
The through-line for all three: a general file tool on its business plan, with the BAA executed, gives you HIPAA-compliant file sharing — compliant for storing and sharing PHI. What none of them center is the deal workflow — dynamic watermarking, granular guest permissions, a Q&A thread, and audit exports for outside reviewers. That is the line between "compliant file storage" and "a data room built for diligence," and it is why healthcare deal teams reach for a purpose-built room even when their org already runs on Microsoft or Google.
Does a healthcare M&A data room actually contain PHI?
Usually it does not — and this is the fact that reframes the whole BAA question for anyone running a healthcare deal. In most healthcare M&A, the data room does not hold patient charts. Buyers do their diligence on de-identified or aggregate data: payer mix, encounter and procedure volumes, quality and outcome metrics, coding and billing summaries, staffing, and financials. The actual patient records typically transfer after close, as part of the asset handover, not during diligence. A buyer evaluating a clinic, a home-health agency, or a provider group does not need to read individual charts to price the deal; it needs the aggregate operational and financial picture, and that data — properly de-identified — is not PHI.
This is house canon across our deal-side coverage, and it holds up in practice: our behavioral health data room, clinic sale data room, and home health accreditation data room guides all draw the PHI line in the same place — de-identify for diligence, transfer charts post-close. When data can be de-identified under HIPAA Safe Harbor (45 CFR 164.514(b)(2)) — which requires stripping 18 categories of identifiers — it falls outside HIPAA scope entirely, and a BAA is not strictly required for that data.
So when does the BAA actually matter? Two situations. First, when PHI genuinely must enter the room. Some deals require chart-level data: a billing and coding audit, a payer dispute, a clinical-data or real-world-evidence transaction, a revenue-cycle review that touches individual claims. In those, PHI is the substance of the diligence, the BAA is mandatory, and the room's HIPAA posture is load-bearing. Second, as insurance against accidental PHI. Even in a de-identified deal, PHI slips into exhibits — a patient name in the corner of a scanned contract, an identifier left in a spreadsheet tab, a chart attached by mistake. Because that happens in real deals, many teams sign a BAA even for a nominally de-identified room, so a single overlooked exhibit does not turn into a reportable breach. The disciplined posture: de-identify aggressively, gate and watermark anything sensitive, and get the BAA in place before upload so you are covered either way. That is why the BAA matrix at the top of this post matters even for deals you expect to keep PHI-free.
What does a HIPAA-compliant data room cost?
HIPAA compliance is almost never a separate charge — you pay for the platform, and the BAA typically rides along on a qualifying plan, though some vendors gate it to a named tier. There is no "HIPAA add-on fee" among the vendors here; the cost question is really just the platform's price, plus making sure you are on a tier that includes BAA eligibility. Here are the canon figures, purpose-built rooms first.
| Provider | Model | Figure |
|---|---|---|
| Peony | Flat-rate monthly | $30/mo (Business), $52/mo (Data Room), $64/user/mo (Deal Team, 4-seat min) |
| Firmex | Subscription / per-deal | ~$150–$500/mo entry; typically $5,000–$10,000 per 3-month deal; $25,000+/yr enterprise |
| iDeals | Subscription | ~$500–$1,000/mo (mid-market) |
| Intralinks | Enterprise annual | Commonly $25,000–$100,000/yr |
| Datasite | Per-deal / enterprise | ~$68,000 average contract (third-party Vendr data) |
| ShareVault | Quote-based | "Express" ~$199/mo circulates third-party — quote-only, not vendor-published |
| Box / Dropbox / Microsoft 365 / Google Workspace / ShareFile / Egnyte | Per-user subscription | BAA gated to specific plans (see each entry above); no single sticker |
A few things to read off this. Peony's flat monthly pricing makes the deal math simple — a Data Room plan is $156 over three months, $312 over six, and $624 over a year — where per-deal legacy pricing meters the same room by pages and duration. Firmex's typical $5,000–$10,000 for a three-month deal is the reference point for a traditional VDR with published BAA language. And the general platforms are priced per user by subscription; their "HIPAA cost" is really the cost of being on a BAA-eligible tier (an Enterprise-family plan for Box, a team plan for Dropbox, Premium/VDR/Industry Advantage for ShareFile), not a compliance surcharge. For the full cross-vendor cost breakdown — per-page economics, flat-rate math, and where each model wins — see our virtual data room cost guide; this section is the canon-locked summary, and that guide is the depth.
BAA checklist: what to confirm before you upload PHI
Before any protected health information goes into any room, walk this checklist. A signed BAA is necessary but not sufficient — the terms inside it are what protect you when something goes wrong, and the plan you are on determines whether the BAA is even available. Confirm all of these in writing:
- The named tier qualifies. Verify your specific plan is BAA-eligible, not just the vendor generally. This is where deals go wrong — Box requires an Enterprise-family plan (not "Business"), ShareFile requires Premium/VDR/Industry Advantage, and Google and Dropbox require a Workspace/team plan, not a consumer account. Being a paying customer is not the same as being on a HIPAA-eligible tier.
- The BAA is executed, not verbal. A sales rep saying "yes, we're HIPAA-compliant" is not a BAA. You need a mutually executed agreement — signed by both parties (or accepted through the vendor's documented mechanism, like Microsoft's Data Protection Addendum or Google's admin acceptance). Get the document, not the assurance.
- Subcontractor flow-down is addressed. Your vendor uses its own subprocessors (cloud hosting, sub-services). Confirm the BAA obligates the vendor to bind its subcontractors to equivalent PHI protections, so the chain does not break one layer down.
- Breach-notification windows are specified. The BAA should state how quickly the vendor must notify you of a breach or suspected breach. HIPAA sets outer limits; a good BAA names a concrete, workable window so you can meet your own notification obligations downstream.
- Termination and return/destruction of PHI is defined. When the engagement ends, what happens to the PHI? The BAA should require the vendor to return or securely destroy all PHI (and copies) at termination, or, where that is infeasible, to extend protections for as long as it retains the data. For a deal room, confirm this maps to how the room is closed and exported.
- Audit rights and safeguard documentation. Confirm you can obtain evidence of the vendor's safeguards — its SOC 2 report, its security documentation, and where relevant its right-to-audit or attestation terms. You are accountable for choosing a vendor with adequate safeguards; keep the paper that shows you did.
- Scope of covered services is explicit. Especially for general platforms, PHI must stay inside the in-scope services (Google's "HIPAA Included Functionality," Microsoft's listed services). Confirm the exact products your BAA covers, and keep PHI out of anything outside that boundary.
- Configuration responsibility is understood. Every honest vendor states that the platform being in-scope does not make you compliant — Firmex ("clients are responsible for configuring Firmex in a HIPAA compliant manner") and Microsoft ("using Microsoft services doesn't on its own achieve HIPAA compliance") both say it. Know which safeguards are yours to configure: access controls, sharing settings, retention, and audit review.
Run that list before upload, not after. The matrix at the top tells you who to call; this checklist tells you what to nail down once they pick up.
Frequently asked questions
Which data room providers actually sign a BAA in 2026?
Among purpose-built deal rooms, Firmex is the standout — it is the only legacy VDR that publishes BAA language, stating on its own news page that clients storing electronic public health records "must therefore sign a Business Associate Agreement (BAA) with Firmex." Peony signs a Business Associate Agreement (BAA) on request. Among general platforms, Microsoft 365, Google Workspace, Box, Dropbox, ShareFile, and Egnyte all sign BAAs — but several are tier-gated: Box requires an Enterprise-family plan (its plain "Business" tier does not qualify), and ShareFile requires a Premium, VDR, or Industry Advantage account. iDeals, Intralinks, and ShareVault claim HIPAA compliance on their own sites but publish no BAA language, so treat their BAA availability as unconfirmed until you get it in writing. Datasite and Ansarada make no HIPAA claim on their own sites at all.
Where can I buy a data room that meets HIPAA and GDPR compliance?
You can buy a data room that meets both HIPAA and GDPR from several vendors, but the honest filter is who commits to a Business Associate Agreement (BAA) in writing, because HIPAA has no government certification — the BAA plus the Security Rule safeguards is what "HIPAA-compliant" actually means. Firmex publishes BAA language and states it is HIPAA-verified and GDPR-compliant. Peony signs a BAA on request, is SOC 2 Type II, and is GDPR-compliant, running Standard plans on US AWS with SCCs and offering custom UK/EU residency on Enterprise. iDeals carries ISO 27001/27017/27018/27701, SOC 2 and SOC 3, GDPR, and a third-party-verified HIPAA claim, though it publishes no BAA language. For the multi-framework control mapping, our document-sharing compliance guide covers SOC 2, GDPR, and HIPAA side by side.
Is there an official HIPAA certification for data rooms?
No. There is no official HIPAA certification, for data rooms or any other software — HHS certifies nobody and endorses no product. "HIPAA-compliant" means the vendor will sign a Business Associate Agreement (BAA) and implements the HIPAA Security Rule safeguards — administrative, physical, and technical (45 CFR 164.308, 164.310, and 164.312). Any vendor "HIPAA certification" you see is a third-party assessment or an internal program, not a government seal, so the durable test is the BAA and the safeguards, not the badge.
Is Dropbox HIPAA compliant — and what's the compliant alternative?
Dropbox can be HIPAA-compliant on a team plan with a signed BAA, but not on consumer tiers. Dropbox's own HIPAA page states that if you are an admin of a Dropbox team account you can sign a BAA electronically from the admin console, and that self-serve electronic BAA is available only to US-based customers. The consumer tiers — Basic, Plus, Professional, and Family — are not BAA-eligible, so personal Dropbox is not a HIPAA-compliant place for PHI. If you need deal-room controls on top of compliance — dynamic watermarking, granular guest permissions, a Q&A workflow, exportable audit trails — a purpose-built room like Peony (which signs a BAA on request) fits the diligence use case better than a general file-sync tool.
Is OneDrive HIPAA compliant?
OneDrive for Business can be HIPAA-compliant, and Microsoft makes the BAA unusually easy: per Microsoft's HIPAA offering page, the Business Associate Agreement is available through the Microsoft Online Services Data Protection Addendum by default to all customers who are covered entities or business associates under HIPAA — no separate signing step. OneDrive for Business, SharePoint Online, and Teams are explicitly in scope, and it is not gated to a top-tier business plan. The two honest caveats: consumer Personal and Family accounts are not the in-scope enterprise services, and, in Microsoft's own words, "using Microsoft services doesn't on its own achieve HIPAA compliance" — your configuration and safeguards still have to be right.
Does a healthcare M&A data room actually contain PHI?
Usually not, or only at the edges. In most healthcare M&A, buyers do their diligence on de-identified or aggregate data — payer mix, encounter volumes, quality metrics, coding summaries — and the actual patient records transfer after close, not during diligence. The BAA and the HIPAA controls matter when PHI genuinely must enter the room (billing and coding audits, chart-level clinical-data deals) and as insurance against accidental PHI landing in an exhibit. So the practical posture is: de-identify what you can under Safe Harbor, gate and watermark anything sensitive, and have a BAA in place before any protected health information is uploaded.
What safeguards does HIPAA require for document sharing?
The HIPAA Security Rule requires three categories of safeguards for electronic PHI: administrative (risk analysis, workforce access controls, a designated security official — 45 CFR 164.308), physical (facility and device controls — 45 CFR 164.310), and technical (access controls, audit controls, integrity controls, and transmission security such as encryption — 45 CFR 164.312). For a data room that translates to encryption in transit and at rest, per-user access controls and granular permissions, a complete audit trail, and a signed BAA with the vendor. For the deeper multi-framework mapping across SOC 2, GDPR, and HIPAA, see our document-sharing compliance guide.
Do I need a BAA with my data room provider if the room only holds de-identified data?
If the data is genuinely de-identified under HIPAA Safe Harbor (45 CFR 164.514(b)(2)), it is no longer protected health information, it falls outside HIPAA scope, and a BAA is not strictly required for that data. The practical caution: de-identification is stricter than most people assume — Safe Harbor requires removing 18 categories of identifiers, and a stray identifier in a spreadsheet, a scanned exhibit, or a file name can re-introduce PHI. Because accidental PHI in exhibits is common in real deals, many teams sign a BAA anyway as cheap insurance, so a single overlooked chart does not become a reportable breach.
What does a HIPAA-compliant data room cost?
HIPAA compliance itself is rarely a separate line item — you pay for the platform, and the BAA typically comes at no extra charge on a qualifying plan, though some vendors gate it to a named tier. Purpose-built deal rooms range widely: Peony is flat-rate at $30/month (Business), $52/month (Data Room), and $64/user/month for Deal Team with a 4-seat minimum; Firmex runs about $150–$500/month at entry, typically $5,000–$10,000 for a three-month deal; iDeals typically runs $500–$1,000/month in the mid-market; Intralinks is commonly $25,000–$100,000/year; and Datasite averages around $68,000 per contract by third-party (Vendr) data. General platforms like Box, Dropbox, Microsoft 365, Google Workspace, ShareFile, and Egnyte price per user by subscription, with the BAA gated to specific plans. For the full breakdown, see our virtual data room cost guide.
Is Google Drive HIPAA compliant without Google Workspace?
No. Free consumer Gmail and personal Google Drive are not eligible for a BAA, so they are not a HIPAA-compliant place for PHI. HIPAA compliance on Google requires Google Workspace, where, per Google's HIPAA guidance, administrators must review and accept a BAA before using PHI in Google services (the path is Account settings → Legal and compliance). Even then, coverage is limited to Google's "HIPAA Included Functionality" list, so PHI must stay inside the in-scope services. Personal Drive sits entirely outside that BAA, which is why it is not a lawful home for protected health information.
Bottom line
The best HIPAA-compliant data room is the one that will sign a BAA on the plan you are actually on, and whose safeguards fit your workflow — not the one with the most badges, because no badge is a government certification in the first place. For a healthcare deal team that wants purpose-built room controls and a BAA in writing, Firmex (published BAA language, SOC 2 Type 2) and Peony (signs a BAA on request, SOC 2 Type II, flat-rate) are the two most defensible picks. For operational PHI inside an org already standardized on a general platform, Microsoft 365 (automatic BAA), Google Workspace, Box (Enterprise-family only), Dropbox (US team plans), ShareFile (Premium/VDR/Industry Advantage), and Egnyte all sign BAAs — mind the tier gates. iDeals, Intralinks, and ShareVault claim HIPAA but publish no BAA language, so pin the BAA down directly. And Datasite and Ansarada do not claim HIPAA at all — with Ansarada honestly pointing HIPAA-driven teams to Firmex.
For the healthcare vertical ranking by clinical workflow rather than compliance posture, our healthcare and life sciences data rooms guide is the companion piece — that post ranks by clinical fit, this one by who signs a BAA. For the control-by-control depth across frameworks, see the document-sharing compliance guide; for the certification side of the same vendor set — who actually holds SOC 2 Type II versus ISO 27001, checked against each vendor's own trust page — the SOC 2 and ISO 27001 data room matrix is the sibling audit; for defense and pharma-supply siblings, the CMMC-compliant file sharing and GDP compliance pack carves cover those regimes; and for clinical-trial workflows specifically, our clinical research solution page maps the room to that use case, while the clinical trial data sharing guide walks the de-identification and agreement mechanics step by step. If you want to test whether a flat-rate room that signs a BAA fits your specific deal — a clinic sale, a home-health acquisition, or a clinical-data licensing room — Peony's pricing is public and you can start immediately, then request the BAA on any paid plan. Peony serves 6,800+ customers and has supported $26.3B in closed transactions across exactly this kind of gated, compliance-sensitive work.
Sources
- Peony pricing — https://www.peony.ink/pricing
- Peony — https://www.peony.ink/
- Peony, best data rooms for healthcare and life sciences — https://www.peony.ink/blog/best-data-rooms-for-healthcare-and-life-sciences
- Peony, document-sharing compliance guide — https://www.peony.ink/blog/document-sharing-compliance-guide
- Peony, virtual data room cost guide — https://www.peony.ink/blog/virtual-data-room-cost-guide
- Firmex, HIPAA / Business Associate Agreement news — https://www.firmex.com/
- iDeals, virtual data room security — https://www.idealsvdr.com/virtual-data-room-security/
- Intralinks, life sciences — https://www.intralinks.com/industries/life-sciences
- Intralinks, trust center — https://www.intralinks.com/trust
- ShareVault, security — https://www.sharevault.com/security
- Datasite, security and compliance — https://www.datasite.com/
- Ansarada, Ansarada vs Firmex — https://www.ansarada.com/compare/ansarada-vs-firmex
- Microsoft, HIPAA / HITECH offering — https://learn.microsoft.com/en-us/compliance/regulatory/offering-hipaa-hitech
- Google Workspace, HIPAA compliance — https://knowledge.workspace.google.com/
- Box, HIPAA / HITECH support — https://support.box.com/
- Dropbox, HIPAA compliance — https://help.dropbox.com/
- ShareFile (Progress), HIPAA support — https://docs.sharefile.com/
- Egnyte, HIPAA statement — https://www.egnyte.com/
- HHS, HIPAA Security Rule (45 CFR Part 164, Subpart C) — https://www.hhs.gov/hipaa/for-professionals/security/index.html
You might also like
Aug 16, 2026
Healthcare Data Rooms: The Complete Guide (2026)
Aug 16, 2026
How to Share Confidential Clinical Trial Data With Partners (2026)
Aug 6, 2026
Home Health Accreditation: The Survey-Ready Document Room (ACHC, CHAP, Joint Commission)

