iCloud has stated that it does not enable HIPAA compliance because Apple won’t sign a Business Associate Agreement (BAA).
iCloud provides cloud-based storage solutions, with security protections for both data storage and transfer. Authentication controls and access management are necessary for cloud services to meet HIPAA compliance standards. A healthcare provider must be able to monitor who accessed the data and what the user does with the information. iCloud’s controls only meet the minimum HIPAA requirements.
When healthcare providers use cloud services with protected health information (PHI), business associates must sign a BAA.