Is Google Workspace HIPAA compliant? The “easy” answer is yes and no. You can use Google Workspace for collaboration and productivity in your healthcare or medical business and stay HIPAA compliant, but you’ll need to follow a few critical steps.
Just like Zoom and Microsoft Teams, Google Workspace supports HIPAA compliance, but it’s not HIPAA compliant as standard. You need to ensure you’re using the right version of Google Workspace (the free plan won’t cut it), and implementing the right security tools.
Here, I’ll walk you through everything you need to know about HIPAA compliance with Google Workspace and how to avoid fines.
What Makes Software HIPAA Compliant?
As I noted in previous articles about Microsoft Teams and Zoom HIPAA Compliance, very few pieces of software are HIPAA compliant “by design”. There are plenty, like Google Workspace that enable HIPAA compliance, with access to robust security tools, access controls, and encryption.
To be HIPAA compliant, software solutions need to offer two things: access to a business associate agreement, and safeguards to protect “Personal Health Information”, or PHI.
HIPAA safeguards require healthcare organizations to implement various “safeguards” for all of their data, including:
- Administrative safeguards: Policies and procedures that govern the proper use and disclosure of PHI to adhere to the HIPAA privacy rule. The privacy rule sets limits on how companies can collect data and gives patients the right to access their data.
- Physical safeguards: Physical safeguards are designed to protect an organization’s physical location, such as locks and alarm systems. They can also include the use of security keys, to help safeguard the integrity of PHI, according to the HIPAA security rule.
- Technical safeguards: Measures implemented to protect electronic PHI, according to the HIPAA rule sets. This might include firewalls and encryption options, and auditing tools that allow companies to comply with investigations.
Is Google Workspace HIPAA Compliant?
Officially, Google says that Workspace is compatible with HIPAA compliance standards. Of course, there are some limitations here. First, Google Workspace offers security and privacy tools that can help businesses achieve HIPAA compliance.
For example, Google allows companies to implement secure access controls like multi-factor authentication (recommended by HIPAA standards). It also allows companies to implement policies to control how data is stored and managed and enables entity authentication.
Additionally, Google Workspace does leverage end-to-end encryption, but you will need to set up your own encryption standards to ensure you’re adhering to HIPAA rules.
Google is also willing to sign a Business Associate Agreement (BAA) with healthcare organizations, which is crucial to HIPAA compliance (more on that in a moment).
However, you’ll only achieve HIPAA compliance with Google Workspace if you:
- Configure your Google Workspace to support HIPAA compliance
- Sign a BAA with Google (reviewed by administrators)
- Use a paid version of Google Workspace
Which Google Workspace Plans Support HIPAA Compliance?
As mentioned above, only the paid versions of Google Workspace can be HIPAA compliant. The main reason for this is that only premium customers can access a BAA from Google. The good news is that virtually all Workspace plans, aside from the free version, are compatible with HIPAA compliance. The bad news is that Google’s BAA doesn’t cover all Workspace products.
You can check the list of “HIPAA ready” applications here, but for now, all of the following features are covered by Google’s BAA:
- Gmail:
- Google Meet:
- Gemini AI for Workspace (not including the web version or mobile version of Gemini)
- Google Calendar
- Google Drive
- Sheets, Docs, Slides, and Forms
- App Script
- Google Keep
- Google Sites
- Jamboard
- Google Chat
- Google Voice (only for managed users)
- Cloud Identity Management
- Google Cloud Search
- Vault
- Google Groups
- Google Tasks
- AppSheet
Crucially, all of these apps need to be configured and used according to HIPAA standards too. You’ll need to ensure you’re using the correct access controls, features, and encryptions. For instance, Gmail won’t offer end-to-end encryption as standard on free plans, and end-to-end encryption with TLS can be turned off by administrators.
Notably, third-party apps and tools integrated with Google Workspace aren’t covered by the BAA either, so you’ll need to keep that in mind when creating your ecosystem.
How to Make Google Workspace HIPAA Compliant
Simply put, the answer to: “Is Google Workspace HIPAA compliant?” is: “It can be”, but you need to follow the right processes. First, you’ll need a paid version of Google Workspace, you’ll also need to take the following steps:
Step 1: Sign a BAA With Google
The only way to ensure Google Workspace is HIPAA compliant, regardless of what security methods you implement, is to sign a Business Associate Agreement with Google. Fortunately, this is pretty straightforward, but I do recommend carefully reviewing the Terms of Service Agreement offered by Google, and the HIPAA implementation guide that Google offers here, first.
The terms of service do note that your company is still responsible for end-user compliance, and that you’ll need to notify Google if you encounter any data breaches. Failure to comply with any service terms could render your agreement invalid.
To request a BAA from Google, simply sign into your Google Workspace account as an admin, and “opt-in” to the HIPAA BAA option like this:
- Click on your Company Profile
- Click Show More, then Legal & Compliance
- Click Review and Accept next to “HIPAA BAA”
- Answer the questions asked by Google
- Click I Accept
Step 2: Train Teams on Google Workspace HIPAA Compliance
Once you’ve signed your BAA with Google, you’ll need to ensure you configure Google Workspace for HIPAA compliance. This means you need to manage your people, processes, and technology effectively. I’d recommend starting with your people.
How your staff embraces secure practices when using Workspace applications, devices, and sharing data is crucial to ensuring continued compliance. Don’t just provide initial onboarding training on how to set passwords and use multi-factor authentication.
Set up a regular training cadence to refresh your team’s knowledge and keep them up to date on new threats and emerging regulatory guidelines. Update your training every time you introduce a new feature to Google Workspace, like Google Gemini.
Step 3: Implement Robust Access Controls
Access controls are critical to HIPAA compliance. Fortunately, Google’s admin console allows you to limit exactly who can access PHI, and what they’ll be able to do with it. Ideally, you’ll want to limit access to sensitive data as much as possible.
When fewer people can access your data, you’re much less likely to fall victim to data breaches caused by human error or phishing scams. Once you’ve implemented your access controls, implement multi-factor or two-factor authentication.




