January 18, 2023
Individuals in a covered component of the University of Illinois Covered Entity may request a Box Health Data Folder (BHDF) that is capable of securely storing protected health information. As Box is at its heart a sharing and collaboration tool, researchers using a BHDF are responsible for reading and following the guidance in the Protecting PHI with Box Health Data Folders document linked below before applying for a BHDF.
Introduction
Key points to remember
Applying for a BHDF
Folder Naming & PHI Storage Requirements
Understanding Box Folder Icons
Folder Naming Requirements
PHI Storage Requirements
Box Collaboration
Box Security Settings
Box Collaborators and Permitted Actions
Preconfigured Settings for BHDFs
Invitation Restrictions
Using Box Sync with BHDFs
Using Box Apps with BHDFs and Files
Descriptions
Tags
Email Uploads Are Prohibited
Latest version
Recognizing the need for a secure and HIPAA compliant collaboration tool, the University of Illinois (University) has signed a Business Associate Agreement (BAA) with Box.com (Box). A BAA with Box allows Individuals to disclose (release, transfer, provide access to) Protected Health Information (PHI) to Box, an external cloud-based service, if they are otherwise not restricted from disclosing it.[1]
Box is built as a collaboration tool, with the purpose of making it easier to share data. As a result, controls are necessary to ensure it is used with PHI in compliance with HIPAA. This document outlines the Privacy Official’s required and recommended actions that members of the University community must follow to use Box.com with PHI in a compliant manner. However, it is ultimately up to those Workforce members disclosing PHI to Box and using its tools to further disclose it to collaborators to understand the technology and use it in a manner that complies with the University’s HIPAA Directive and this document.
General HIPAA training, that all Workforce Members are required to complete, is separate from the required and recommended actions contained in this document.
Folders in Box appear differently based on whether they are shared or private, hosted at the University or hosted externally, owned by you or someone else, and synced or not synced. You should know the difference between the five different folder icons in Box.
Figure 1: Meaning Behind Box Folder Icon Appearances:

The settings behind the icon appearances will be addressed later in this document. The important feature to note about these icons is that Box does not have any folder icons that indicate the sensitivity of the data it contains. A standard Box folder (or subfolder) icon that contains PHI will look the same as a standard Box folder (or subfolder) icon that does not contain PHI.
The Privacy Official has established folder naming requirements for all BHDFs and subfolders of BHDFs. These folder naming requirements do not, in and of themselves, protect folders containing PHI from being inappropriately accessed but they can help. Following these naming requirements should eliminate the necessity to access a Box folder just to determine if it contains PHI and prevent unintentional access of PHI.
All BHDFs and subfolders of BHDFs (and only BHDFs and subfolders of BHDFs) must follow these requirements, not individual filenames or Box descriptions and tags (those are additional options explained below). Both folder and file names within Box have a 255-character limit.
All BHDFs (and subfolders) must appear as follows: “[Box Health – X] foldername”
An example folder name for a research project might be: [Box Health – External] Jones Pancreatic Cancer Study Team
The Privacy Official has established the following rules to maintain the security of PHI stored within the Box:
Although Box itself is designed to be usable as a secure platform for collaboration, individual choices determine how secure a given piece of data within Box is. Folder “ownership” and its settings are key to the security of any data within Box. When you log into Box for everyday work, you may interact with a variety of shared and private folders for any given collaborative project, each with its own level of security set by its “owner.”
Security settings can be accessed by clicking on the ellipsis icon for the BHDF folder, then click on settings.![]()
As discussed in the introduction, the BAA the University has with Box allows disclosure of PHI to Box (e.g., store PHI within Box). The BAA does not, as a result, authorize disclosure of PHI within Box to any individual who has access to Box. Disclosure of PHI to another individual within Box (i.e., providing access to the PHI within Box), must independently comply with HIPAA. It is the responsibility of the “owner” or “co-owner” to disclose (i.e., provide access to) the PHI to individuals within Box in accordance with the University’s HIPAA Directive.
If disclosure of PHI to an individual is permitted by the University’s HIPAA Directive, it can be accomplished through Box by inviting the individual into the appropriate BHDF as a collaborator. However, it remains the responsibility of the “owner” or “co-owner” to always make an intentional choice about the permission level of each collaborator in a BHDF, giving each collaborator the lowest level necessary to accomplish his or her tasks.
A Box collaborator can be classified into seven different categories. Each category is permitted, or prevented, from taking certain actions (See Figure 3 Below). By default, Box collaborators are “Editors.”
Figure 2: Comparison of Collaborator Categories & Permitted Actions
| Action | Collaborator Categories | |||||||
|---|---|---|---|---|---|---|---|---|
| Owner | Co-Owner | Editor | Viewer Uploader | Previewer Uploader | Viewer | Previewer | Uploader | |
| Download | permitted | permitted | permitted | permitted | Not Permitted | permitted | Not Permitted | Not Permitted |
| Comment | permitted | permitted | permitted | permitted | permitted | permitted | permitted | Not Permitted |
| Delete | permitted | permitted | permitted | Not Permitted | Not Permitted | Not Permitted | Not Permitted | Not Permitted |
| Create tasks | permitted | permitted | permitted | permitted | Not Permitted | permitted | Not Permitted | Not Permitted |
| Tag | permitted | permitted | permitted | Not Permitted | Not Permitted | Not Permitted | Not Permitted | Not Permitted |
| Invite people | permitted | permitted | Not Permitted | Not Permitted | Not Permitted | Not Permitted | Not Permitted | Not Permitted |
| Edit folder name | permitted | permitted | permitted | Not Permitted | Not Permitted | Not Permitted | Not Permitted | Not Permitted |
| Edit folder properties | permitted | permitted | Not Permitted | Not Permitted | Not Permitted | Not Permitted | Not Permitted | Not Permitted |
| Preview | permitted | permitted | permitted | permitted | permitted | permitted | permitted | Not Permitted |
| Send view-only links | permitted | permitted | permitted | permitted | Not Permitted | permitted | Not Permitted | Not Permitted |
| Upload | permitted | permitted | permitted | permitted | permitted | Not Permitted | Not Permitted | permitted |
| View items in folder | permitted | permitted | permitted | permitted | permitted | permitted | permitted | permitted |
| Sync folder | permitted | permitted | permitted | Not Permitted | Not Permitted | Not Permitted | Not Permitted | Not Permitted |
| Set access permissions | permitted | permitted | permitted | Not Permitted | Not Permitted | Not Permitted | Not Permitted | Not Permitted |
| Restrict invitations | permitted | permitted | Not Permitted | Not Permitted | Not Permitted | Not Permitted | Not Permitted | Not Permitted |
| View access stats | permitted | permitted | permitted | Not Permitted | Not Permitted | Not Permitted | Not Permitted | Not Permitted |
| Create/edit Box Notes | permitted | permitted | permitted | permitted | Not Permitted | Not Permitted | Not Permitted | Not Permitted |
| View Box Notes | permitted | permitted | permitted | permitted | permitted | permitted | permitted | Not Permitted |
The Privacy Official has preconfigured some collaboration settings for BHDFs. These settings, marked as number 1, 2, 3, 4 and 5 in Figure 3 below, have been set and cannot be changed.
Figure 3: Collaboration Settings Screenshot:

Syncing folders in Box allows data to be transferred from within Box to an endpoint computer or device without a log trail, which presents a security risk for PHI. In addition, having extra copies of data on a local device increases the risk of inappropriate access.
Note: Be aware that “tags” and “descriptions,” described below, do not propagate via sync.
The Privacy Official reminds all users of Box that only some of the official and third-party Box Applications (Apps) are approved for use with University data. Apps not listed on the approved list may not be used to share or maintain any of the University’s data, including PHI, and are not covered by the university’s Box agreement. Certain Apps are approved for use with most University data, but not approved for PHI; these may not be used with any PHI in BHDFs.
Uploads of PHI to a BHDF must be done using the secure web interface and may not be done by email. Box does allow for email uploads but it should never be selected to upload PHI (See Figure 4 Below).
Figure 4: Uploading screenshot:

Allowing email uploads to BHDFs is strictly prohibited. If anyone (“owner,” “co-owner,” or “collaborator”) were to send sensitive data via an unencrypted email message, the data would not be protected in transit which is a violation of the University’s HIPAA Directive.
View the most recent version of the Protecting PHI with Box Health Data Folders document.
[1] PHI received by a Workforce Member may be subject to restrictions on further disclosure. For example, a data use agreement to obtain the PHI may restrict further disclosure. In addition, some PHI may be subject to laws more restrictive than HIPAA that prohibit re-disclosure without further patient authorization.
