Medcurity Get Started
Last updated: March 2026

Is Google Workspace HIPAA Compliant?

Quick Answer

Yes, Google Workspace can be HIPAA compliant when you sign a Business Associate Agreement (BAA) and properly configure security settings. Google offers BAAs for Workspace domains with appropriate plans, but compliance requires careful configuration of Gmail, Drive, and Meet security controls.

BAA Availability & Requirements

Business Associate Agreement

Google Workspace requires signing a Business Associate Agreement for HIPAA compliance. The BAA is available for qualifying customers and covers processing of Protected Health Information (PHI) under HIPAA regulations. Organizations must request the BAA separately during account setup or contact Google Cloud sales.

Eligible Plans

Google Workspace HIPAA compliance is available for Business Standard, Business Plus, and Enterprise plans. Starter and basic plans do not support HIPAA BAAs. You'll need to verify with Google that your account qualifies and that BAA coverage has been activated.

Gmail Security & Configuration

Feature Configuration for HIPAA
Encryption in Transit Enforced for all connections; TLS 1.2+ required
Encryption at Rest Google-managed encryption by default; customer-managed keys available
External Email Sharing Should be restricted to approved external domains/recipients
Message Retention Configure retention policies for compliance; permanent deletion after specified period
Security Sandbox Enable to quarantine suspicious attachments

Gmail Best Practices

Google Drive Configuration

Sharing Controls

Restrict Drive sharing by disabling public sharing, allowing only specific domains, and using link sharing with expiration dates. Enable audit logs to track file access and sharing changes. Remove "Anyone with the link" option to prevent accidental public exposure of PHI.

File Encryption & Recovery

All files are encrypted at rest. Enable recovery settings to require confirmation when users attempt to share files containing sensitive data. Configure data loss prevention (DLP) rules to prevent sharing of files containing PHI patterns.

Google Meet Security Settings

Security Feature Recommended Setting
Meeting Encryption End-to-end encryption enabled for all calls
Recording Storage Store in Google Drive with restricted access; auto-delete after retention period
Participant Access Require sign-in; restrict to organization domain only
Screen Sharing Only presenter can share; disable guest screensharing
Recording Notifications Automatic notification to participants when recording starts

Admin Controls & Governance

Security Settings to Configure

Audit & Compliance

Compliance Considerations

Signed BAA Required

A signed Business Associate Agreement with Google is mandatory. Without it, Google Workspace cannot be considered HIPAA compliant. Ensure the BAA covers all services you use: Gmail, Drive, Meet, and Calendar.

Encryption in Transit & At Rest

Google provides encryption for all data. In-transit encryption uses TLS 1.2 or higher. At-rest encryption is automatic, but Enterprise customers can use Customer-Managed Encryption Keys (CMEK) for additional control.

User Training Required

All staff must be trained on handling PHI in Google Workspace. Cover email security, secure file sharing, secure meeting practices, and when NOT to use these tools for sensitive data. Document training completion.

Frequently Asked Questions

Can I use personal Google accounts for healthcare communications? +
No. Personal Google accounts (@gmail.com) do not have BAA coverage and cannot be used for PHI. You must use a Google Workspace organization account with an active BAA agreement in place.
How do I request a BAA from Google? +
Contact Google Cloud sales directly to request a Business Associate Agreement. You'll need to provide your organization's information, confirm your Workspace plan tier, and sign Google's standard BAA. The process typically takes 1-2 weeks.
Does Google Meet support end-to-end encryption for PHI calls? +
Yes, Google Meet supports end-to-end encryption for calls involving 3 or fewer participants. For larger meetings, Google provides encryption in-transit and at-rest but not true end-to-end encryption. Plan your meetings accordingly.
What about Google Workspace third-party integrations? +
Third-party apps must have their own BAAs if they access PHI through Workspace integrations. Carefully review all connected apps and their privacy policies. Restrict app permissions to only what's necessary and audit connected apps quarterly.

Implementation Checklist

Before Going Live with PHI

✓ Signed BAA with Google active
✓ Two-step verification enabled for all users
✓ Gmail external sharing restrictions configured
✓ Drive public sharing disabled
✓ Meet encryption and participant controls configured
✓ DLP rules created to detect PHI
✓ Audit logging enabled and monitored
✓ User training completed and documented
✓ Security incident response plan in place

Ensure Your Google Workspace is HIPAA Compliant

Medcurity provides comprehensive compliance audits and configuration services for Google Workspace. Let us verify your setup protects patient data.

Schedule Your Free Audit