Yes, Google Workspace can be HIPAA compliant when you sign a Business Associate Agreement (BAA) and properly configure security settings. Google offers BAAs for Workspace domains with appropriate plans, but compliance requires careful configuration of Gmail, Drive, and Meet security controls.
Google Workspace requires signing a Business Associate Agreement for HIPAA compliance. The BAA is available for qualifying customers and covers processing of Protected Health Information (PHI) under HIPAA regulations. Organizations must request the BAA separately during account setup or contact Google Cloud sales.
Google Workspace HIPAA compliance is available for Business Standard, Business Plus, and Enterprise plans. Starter and basic plans do not support HIPAA BAAs. You'll need to verify with Google that your account qualifies and that BAA coverage has been activated.
| Feature | Configuration for HIPAA |
|---|---|
| Encryption in Transit | Enforced for all connections; TLS 1.2+ required |
| Encryption at Rest | Google-managed encryption by default; customer-managed keys available |
| External Email Sharing | Should be restricted to approved external domains/recipients |
| Message Retention | Configure retention policies for compliance; permanent deletion after specified period |
| Security Sandbox | Enable to quarantine suspicious attachments |
Restrict Drive sharing by disabling public sharing, allowing only specific domains, and using link sharing with expiration dates. Enable audit logs to track file access and sharing changes. Remove "Anyone with the link" option to prevent accidental public exposure of PHI.
All files are encrypted at rest. Enable recovery settings to require confirmation when users attempt to share files containing sensitive data. Configure data loss prevention (DLP) rules to prevent sharing of files containing PHI patterns.
| Security Feature | Recommended Setting |
|---|---|
| Meeting Encryption | End-to-end encryption enabled for all calls |
| Recording Storage | Store in Google Drive with restricted access; auto-delete after retention period |
| Participant Access | Require sign-in; restrict to organization domain only |
| Screen Sharing | Only presenter can share; disable guest screensharing |
| Recording Notifications | Automatic notification to participants when recording starts |
A signed Business Associate Agreement with Google is mandatory. Without it, Google Workspace cannot be considered HIPAA compliant. Ensure the BAA covers all services you use: Gmail, Drive, Meet, and Calendar.
Google provides encryption for all data. In-transit encryption uses TLS 1.2 or higher. At-rest encryption is automatic, but Enterprise customers can use Customer-Managed Encryption Keys (CMEK) for additional control.
All staff must be trained on handling PHI in Google Workspace. Cover email security, secure file sharing, secure meeting practices, and when NOT to use these tools for sensitive data. Document training completion.
✓ Signed BAA with Google active
✓ Two-step verification enabled for all users
✓ Gmail external sharing restrictions configured
✓ Drive public sharing disabled
✓ Meet encryption and participant controls configured
✓ DLP rules created to detect PHI
✓ Audit logging enabled and monitored
✓ User training completed and documented
✓ Security incident response plan in place
Medcurity provides comprehensive compliance audits and configuration services for Google Workspace. Let us verify your setup protects patient data.
Schedule Your Free Audit