
Google Workspace can hold patient information, but it is not HIPAA compliant by default. Google Workspace HIPAA compliance starts when a super administrator accepts Google’s Business Associate Amendment in the Admin console. That agreement covers only the services on Google’s HIPAA Included Functionality list, and your organization still has to configure those services.
We read every Google page cited here in September 2026. This is general information, not legal advice. If you are still choosing a suite, our Google Workspace vs Microsoft 365 price comparison covers cost and features for any small business; this post answers only the HIPAA question.
Does Google sign a BAA for Workspace?
Yes, electronically. Google makes its BAA available for acceptance in the Admin console. A super administrator opens Account settings > Legal and compliance, finds the Google Workspace/Cloud Identity HIPAA Business Associate Amendment under Security and Privacy Additional Terms, answers three questions confirming the organization is a HIPAA covered entity, and accepts. Google’s help center (checked September 2026) says the electronic acceptance has the same legal effect as a paper agreement, and that a screenshot of the acceptance can serve as your record.
Four points in Google’s BAA text are worth knowing before you rely on it:
- It applies only to Covered Services, not to PHI you keep outside them, including in third-party applications.
- It requires you to use the controls available in the services, including those in Google’s HIPAA Implementation Guide, to keep PHI inside covered services.
- Google must report a breach it discovers without unreasonable delay and no later than 60 calendar days after discovery.
- Google can remove a service from the covered list only with at least 12 months’ notice.
Which Google Workspace services does the BAA cover?
Google keeps the list on its HIPAA Included Functionality page, dated August 31, 2026 when we checked. Anything not on it is outside the BAA, even inside your Workspace account. The right-hand column comes from Google’s implementation guide and help center.
| Covered by Google’s BAA | Keep PHI out |
|---|---|
| Gmail, Google Calendar, Google Chat, Google Meet | Google Contacts, a core service Google lists as not permitted for PHI |
| Google Drive, including Docs, Sheets, Slides, Forms, Vids and Pics | Additional Google Services such as YouTube, Blogger and Google Photos |
| Google Keep, Sites, Tasks, Groups and Cloud Search | Third-party apps and Marketplace add-ons |
| Google Vault (if applicable) and Google Voice (managed users only) | Conversations with Google technical support |
| AppSheet, Apps Script and Cloud Identity Management | Pre-GA (preview) offerings |
| Gemini in Workspace, the Gemini app and the Gemini Mac App | Gemini in Chrome, and the Gemini app offered as an Additional Product |
Which Workspace plans cover HIPAA?
Google does not publish a list of eligible editions. Its acceptance instructions say you must be signed in to an administrator account for your organization’s Google Workspace or Cloud Identity account, and that users of the legacy free edition, sometimes called Google Apps Standard Edition, cannot review and accept a BAA. A personal @gmail.com address has no organizational Admin console, so it cannot be covered. If your Admin console does not offer the HIPAA amendment, ask Google before any patient data goes in.
The edition still decides which tools you get around the BAA. Google Vault, Google’s retention and eDiscovery service, is included in Business Plus, Enterprise Standard and Enterprise Plus, all Education editions, and Frontline Standard and Plus. On editions without it, such as Business Starter and Business Standard, Google’s answer is an upgrade or add-on Vault licenses where compatible. Google also says Vault isn’t a data archive, while HIPAA requires a data backup plan with retrievable exact copies of ePHI (45 CFR 164.308(a)(7)(ii)(A)). Plan backups separately.
What should you set up after accepting the BAA?
The BAA makes configuration your job: Google’s terms require you to use the available controls to keep PHI inside covered services. These are the settings we start with, drawn from Google’s HIPAA Implementation Guide:
- Separate the people who handle PHI. Put them in their own organizational unit and turn off services outside the covered list, such as YouTube, for that unit.
- Tighten Drive sharing. Restrict sharing outside the domain, make new files private to the owner, keep patient names out of file and folder titles, and review Google’s file exposure reports.
- Limit calendars. Share only free/busy information outside the domain and mark appointments that contain PHI as private.
- Close side doors. Block unreviewed Marketplace apps, Docs add-ons and Chat apps, and turn off Gemini in Chrome for staff who handle PHI.
- Watch the account. Turn on alerts for suspicious sign-ins, new admin privileges and passwords changed by an administrator.
We add 2-Step Verification for everyone in that unit, which supports the Security Rule’s person or entity authentication standard (45 CFR 164.312(d)). Gmail is on the covered list, but sending patient information to outside addresses still raises the transmission question. Our guide to HIPAA rules for email covers encryption and patients who ask for plain email.
Where NetSys fits
We administer Google Workspace and Microsoft 365 for clients. Our HIPAA compliance services for practices turn the settings above into documented controls and keep Google’s BAA in a vendor register next to every other business associate agreement your practice holds. A HIPAA compliance audit shows whether your current setup matches what you accepted. Practices on Microsoft should read our Microsoft 365 HIPAA guide, and more on how we support clinics is on our IT for medical practices page.
Frequently asked questions
Is Gmail HIPAA compliant?
Gmail can carry PHI once your organization accepts Google’s BAA, because Gmail is on Google’s HIPAA Included Functionality list. The BAA does not make every message safe. You still decide how patient information leaves your domain, for example with data loss prevention rules, and you record that decision in your risk analysis.
Is Google Drive HIPAA compliant?
Google Drive, including Docs, Sheets, Slides and Forms, is covered by Google’s BAA after an administrator accepts it. Coverage is not the same as safe sharing. Google’s implementation guide recommends restricting sharing outside the domain, making new files private by default, keeping PHI out of file titles, and reviewing file exposure reports.
Can a practice use a free Gmail account for patient information?
No. Google’s BAA is accepted by an administrator of an organization’s Google Workspace or Cloud Identity account, and Google says users of the legacy free edition cannot accept it. A personal Gmail address has no organizational Admin console. Move patient communication to a Workspace account with the BAA accepted.
Is Gemini covered by Google’s HIPAA BAA?
Partly. Google lists Gemini in Workspace, the Gemini app and the Gemini Mac App as Included Functionality, but excludes Gemini in Chrome, and its guide says the Gemini app offered as an Additional Product is not HIPAA compliant. Turn off those routes for staff who handle PHI. We compare other AI tools and their BAAs separately.
Does the Workspace BAA cover Google Cloud?
No. The Workspace BAA covers the Workspace services on Google’s Included Functionality list. Google’s implementation guide tells Apps Script developers not to send PHI to Google Cloud Platform services and APIs without signing a BAA with Google Cloud Platform, which is a separate agreement. Review it on its own before building there.
Sources (checked September 2026)
- HIPAA Compliance with Google Workspace and Cloud Identity, Google Workspace Admin Help, checked September 2026.
- Privacy compliance and records for Google Workspace and Cloud Identity, the BAA acceptance steps and the legacy free edition note, checked September 2026.
- HIPAA Included Functionality, Google’s list of covered services, dated August 31, 2026, checked September 2026.
- Google Workspace HIPAA Business Associate Addendum, the agreement text, checked September 2026.
- Google Workspace and Cloud Identity HIPAA Implementation Guide (PDF), checked September 2026.
- Google Vault overview, the editions that include Vault, checked September 2026.
- 45 CFR 164.308 and 45 CFR 164.312, HIPAA Security Rule safeguards on the eCFR, checked September 2026.
Related reading
ComplianceBusiness Associate Agreement for HIPAA Compliance: Does Your IT Company Need One?
Read Article
Healthcare ITHIPAA IT Compliance Checklist for Small Medical and Dental Practices
Read Article
ComplianceMicrosoft 365 HIPAA Compliance: The BAA, Copilot and Required Settings
Read ArticleAlso on this topic: NIST vs ISO 27001 vs CIS Controls: Key Differences · HIPAA Security Rule Delayed to 2027: What Practices Do Now
Discuss microsoft 365 management & backup for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.
