Call now for cybersecurity help: 888-646-1616

Is Google Workspace HIPAA Compliant?

Many practices want to use cloud storage services like Google Drive and hosted email.  Is Google's Google Workspace HIPAA compliant?

First, let's review what's actually in Google Workspace, Google's paid version of a variety of productivity tools.

Feature Download: FREE checklist to avoid a HIPAA disaster you can use right now (Download Now)

Is Your Google Workspace HIPAA Compliant and Secure? Don’t Wait for a Breach, Start your cloud security journey with our comprehensive audit.. Our specialists are committed to helping your business stay safe and seamlessly achieve HIPAA compliance and encryption requirements.

HIPAA Compliant Email

Most famously, Google Workspace includes Gmail, an excellent and easy-to-use email platform.  Users go through the famous Gmail portal, but their email address is their own custom email (@yourcompany.com).  Google Workspace customers get 30GB of inbox storage and are able to use Microsoft Outlook and other email clients.

One important note is that the paid version of Gmail doesn't scan your emails to show you ads.  Paid Gmail users never see ads.

HIPAA Compliant Calendar

The calendar in Google Workspace lets you plan meetings with other people, and schedule appointments.  Many EMR/EHR systems offer integration with Google's Calendar for scheduling.  The calendar is also well integrated into other Google Workspace applications like Gmail, Drive, Contacts, Sites, and Hangouts.

HIPAA Compliant Cloud File Storage

Google Workspace includes Google Drive, a tool to easily store, sync and share files.  Files sync between your desktop, mobile devices, and the cloud.  You can control who can see which files.

HIPAA Compliant Collaboration Tools

Google Workspace includes web-based versions of some simple but solid productivity tools.  This includes:

  • Docs (kind of like Microsoft Word)
  • Sheets (kind of like Microsoft Excel)
  • Slides (kind of like Microsoft PowerPoint)
  • Forms (for building forms on the web)
  • Sites (a tool for building an intranet)

HIPAA Compliant Note-Taking

Google Workspace includes a tool called Google Keep for note-taking (kind of like Evernote).

HIPAA Compliant Google Meet

Due to the coronavirus COVID-19 response, we’ve seen a dramatic increase in interest surrounding Google Meet. The good news: Google Meet can be HIPAA compliant and Google Meet can be used for telehealth! But it needs to be set up the correct way.

There are currently 2 ways to place video calls using your Google Workspace account:

  1. Using Classic Hangouts, which is where you start a video call using the chat on the left side of the Gmail Interface. This is not HIPAA compliant, and if you’re using video you should tell your staff not to use this.
  2. The other is using Google Meet. You use Google Meet by going to meet.google.com and starting a call.  This service can be HIPAA compliant.

Google’s BAA covers the chat feature in Classic Hangouts, so you should not use the video function in Classic Hangouts. Use Google Meet!

Check out our article Is Google Meet HIPAA-Compliant? for answers to common questions.

The Google Workspace Learning Center has excellent tutorials and explanations on how to use Google Meet, including if you need to switch from using Zoom, WebEx, or Skype.

Google Meet information was updated on 4/20/2020.

Will Google sign a BAA for Google Workspace?

Yes, Google will execute a HIPAA Business Associate agreement (BAA) with paying customers of Google Workspace.

Be aware of the stipulations

It's important to note that the Google Workspace Business Associate Agreement covers ONLY some of the Google Workspace services.  As of this publishing, here are the services that are and aren't part of the Google Workspace BAA:

g-suite-hipaa-compliant-services

You are still responsible for verifying your compliance

Just because Google is ensuring security when it comes to the actual storage of your PHI doesn’t mean that you can sit back and let them do all the work. You still need to be proactive when it comes to making sure your information is protected. Two-factor authentication, permissions management, password policies, employee use policies — all of these are still your responsibility to implement and test.  But keeping these things in mind, Google Workspace can now be a convenient tool in helping to manage your PHI.

So is Google Workspace HIPAA compliant?

Yes, Google Workspace can be used by medical practices in ways that are HIPAA compliant.  However, this is only true if you:

  1. Use the paid version of Google's Google Workspace,
  2. Sign a HIPAA Business Associate Agreement (BAA) with Google, and
  3. Take the correct steps to set up Google Workspace to make sure your practice is HIPAA-compliant

What should you do next?

  1. Get our free “Checklist on Gmail and HIPAA Compliance”.
  2. Know someone who might like this article?  Share it!
  3. Have questions or something to add?  Let us know in the comments below!

Do you think we might be a good match?

Copyright 2025 Adelia Associates, LLC | All Rights Reserved