Quick Answer
Google Workspace can be used in a HIPAA-compliant way, but no plan is “HIPAA compliant” automatically. Any paid Google Workspace Business plan, Starter, Standard, or Plus, qualifies for a Business Associate Agreement (BAA) with Google, not just the higher tiers as many guides claim. Once a super admin signs the BAA, a specific list of Google services, including Gmail, Drive, Docs, Meet, Chat, Calendar, and Gemini in Workspace, becomes covered for handling Protected Health Information (PHI). Free personal Gmail and Google Workspace Individual are never eligible for a BAA, regardless of configuration.
Few questions generate as much conflicting information online as this one, partly because a lot of guides confuse “which product is covered” with “which plan tier you’re on,” and partly because the answer genuinely requires two separate things to both be true: a signed agreement and correct configuration. This guide sorts out both, using Google’s own current terms rather than secondhand summaries.
Is Google Workspace HIPAA Compliant?
Google Workspace can support HIPAA compliance, but it isn’t compliant by default just because you’re paying for it. Compliance requires two things: a signed Business Associate Agreement (BAA) with Google, and correct configuration and use of the specific services covered under that agreement. Google Workspace customers are responsible for determining whether they’re subject to HIPAA and for not using PHI in any Google service until the BAA has been signed. Skipping the BAA and using Gmail or Drive for patient data anyway is a HIPAA violation regardless of how securely the account is otherwise configured.

Which Google Workspace Plan Is HIPAA Compliant?
This is where a lot of guides get it wrong. There’s a persistent claim online that only Business Plus or Enterprise tiers qualify for a BAA. That’s not accurate. Google’s BAA is available to Google Workspace and Cloud Identity customers on paid plans generally, Business Starter included, not restricted to higher tiers. What does vary by tier is which covered features are actually included in your plan to begin with; for example, Google Vault (covered under the BAA “if applicable”) is only included starting on certain tiers, so a Business Starter customer wouldn’t have Vault to use even though Starter itself isn’t excluded from signing the BAA. The practical takeaway: pick your Google Workspace plan based on which features (storage, Vault, advanced security) your organization actually needs, not based on a mistaken belief that only expensive tiers can be made HIPAA compliant.
Is Google Workspace Individual HIPAA Compliant?
No. Google Workspace Individual, the consumer-facing plan aimed at solo professionals without a business domain, and free personal Gmail accounts are both excluded from the BAA entirely, regardless of configuration. If you’re a solo healthcare provider or practice considering Workspace Individual specifically because it’s cheaper, it’s not a HIPAA-eligible option; a standard Business Starter plan with a signed BAA is the entry point for compliance instead.
What’s Actually Covered Under the Google Workspace BAA
As of August 2026, Google’s official HIPAA Included Functionality list covers: AppSheet, Apps Script, Cloud Identity Management, the Gemini app (excluding Gemini in Chrome), Gemini Mac App, Gemini in Workspace, Gmail, Google Calendar, Google Chat, Google Cloud Search, Google Drive (including Docs, Forms, Sheets, Slides, and Vids), Google Groups, Google Keep, Google Meet, Google Pics, Google Sites, Google Tasks, Google Vault (if included in your plan), and Google Voice (managed users only). This list is maintained directly by Google and can change, so it’s worth checking the current version before assuming a specific app is covered.

Is Gmail HIPAA Compliant?
Yes, Gmail is on the list of Included Functionality, meaning it can be used for PHI once your organization has signed the BAA. That coverage extends to Gmail’s smart features too: Help Me Write, contextual smart replies, and the side panel are explicitly confirmed as covered under Google Workspace with Gemini. Coverage doesn’t remove your responsibility for how PHI is actually shared, though; sending PHI to an external domain still needs to follow your organization’s own sharing policies, since the BAA covers the platform, not how carefully your staff use it.
Is Google Drive HIPAA Compliant?
Yes. Google Drive is covered, along with Docs, Forms, Sheets, Slides, and Vids, all falling under the same Drive umbrella in Google’s Included Functionality list. As with Gmail, coverage means the platform can be used for PHI once the BAA is signed; it doesn’t automatically mean every file is shared securely. Sharing settings still need to be configured deliberately, restricting PHI-containing files to specific recipients rather than broad link-sharing, to actually meet HIPAA’s access control expectations.
Is Google Meet HIPAA Compliant?
Yes, Google Meet is Included Functionality under the BAA. For healthcare organizations using video visits, this covers the meeting platform itself; if you’re recording sessions, those recordings need to be stored and access-controlled appropriately once saved, since a saved recording containing PHI is subject to the same protection requirements as any other stored PHI.
Is Google Chat HIPAA Compliant?
Yes, Google Chat is included in the covered functionality list, meaning it can be used for PHI-related team communication once the BAA is in place, with the same access control expectations applying as with any other covered service.
Is Gemini for Google Workspace HIPAA Compliant?
Yes, with one specific exception. The Gemini app, Gemini Mac App, and Gemini in Workspace (the AI features built into Gmail, Docs, Sheets, and Meet) are all covered under the current BAA. Gemini in Chrome specifically is excluded from Included Functionality, so that particular integration point shouldn’t be used with PHI even though other Gemini surfaces are covered.
Is Google Voice HIPAA Compliant?
Partially. Google Voice is covered under the BAA, but only for managed users, meaning Voice provisioned and administered through your Google Workspace organization, not the consumer Google Voice app used independently outside a managed account. A healthcare provider using personal Google Voice for patient calls, rather than a Voice number managed through their Workspace domain, isn’t covered.
What’s Not Covered Under the Google Workspace BAA
Third-party applications and add-ons, including anything installed through the Google Workspace Marketplace, are explicitly not included in Included Functionality, even if they integrate closely with covered Google services. Neither the BAA nor the Cloud Data Processing Addendum extends to what Google calls “Additional Google Services,” a separate category of features outside the core Included Functionality list. If your workflow depends on a third-party add-on touching PHI, that tool needs its own separate BAA with its own vendor; Google’s agreement doesn’t extend coverage to it.
How to Sign a BAA With Google Workspace
- Confirm your organization is on a paid Google Workspace Business plan (Starter, Standard, or Plus all qualify).
- Sign in as a super administrator and go to the Admin console home page.
- Navigate to Account settings, then Legal and compliance.
- Review and electronically accept the HIPAA BAA there.
- Keep a record of the acceptance; a screenshot of the Legal and compliance section showing acceptance serves as documentation, since Google doesn’t send a separately countersigned copy.
How to Actually Make Google Workspace HIPAA Compliant, Beyond the BAA
Signing the BAA is a legal prerequisite, not the end of the compliance work. After signing, restrict PHI to the specific services covered under Included Functionality; don’t assume every app in your subscription is automatically in scope. Enable two-factor authentication organization-wide, since HIPAA’s Security Rule expects strong access controls, not just a signed agreement. Configure Data Loss Prevention rules to catch PHI leaving your domain inappropriately. Set up audit logging so you can demonstrate who accessed what PHI and when, if ever required to. And train staff specifically on your organization’s PHI handling policies within Google Workspace, since a technically compliant setup can still result in a violation if an employee shares data carelessly. Google’s own HIPAA Implementation Guide, linked from the Admin console’s compliance section, walks through this configuration in more technical detail than general guidance like this can cover.
How Do I Know If My Google Workspace Is HIPAA Compliant?
Check these specifically: has a super admin actually accepted the BAA in Account settings, Legal and compliance (not just assumed it’s covered by being on a paid plan)? Is PHI restricted to services on the current Included Functionality list, and kept out of third-party add-ons and Additional Google Services? Is 2FA enforced organization-wide? Are sharing settings for PHI-containing files and folders restricted rather than open by default? Has staff received documented training on your organization’s specific PHI handling policies? If any of these is uncertain, that’s a compliance gap worth closing before assuming your setup qualifies, regardless of which plan you’re paying for.
What People Ask About This on Reddit
Discussions of Google Workspace HIPAA compliance on Reddit tend to circle a consistent set of concerns: confusion over which plan tier actually matters (often repeating the inaccurate “only Business Plus qualifies” claim), questions about whether specific third-party add-ons used alongside Workspace are covered (generally, they’re not), and general uncertainty about whether signing the BAA alone is “enough” (it isn’t). As with most community discussion on a compliance topic, it’s useful for seeing what other admins are confused about, but it’s not a substitute for checking Google’s current official terms or consulting a HIPAA compliance professional for anything specific to your organization’s risk exposure.
Common Mistakes When Evaluating Google Workspace HIPAA Compliance
Assuming only Business Plus or Enterprise plans qualify for the BAA. This is the single most repeated inaccuracy across online guides on this topic. Business Starter qualifies too; what varies by tier is which specific features (like Vault) are included in your plan to begin with.
Treating a signed BAA as the finish line. The BAA is a legal prerequisite, but access controls, DLP, audit logging, and staff training still need to be configured correctly for a deployment to actually meet HIPAA’s Security Rule expectations.
Buying Google Workspace Direct vs Through a Reseller for a Healthcare Setup
The BAA signing process and Included Functionality list are identical regardless of how you purchased your Google Workspace licenses, since it’s a standard part of the plan itself, not a reseller-specific feature. Where an authorized reseller can genuinely help is in the surrounding setup work, choosing the right plan tier for your organization’s actual feature needs, and initial configuration of security settings, if you’re building a HIPAA-relevant Workspace deployment for the first time without in-house IT or compliance expertise. See our full Google Workspace pricing breakdown to compare plan tiers before choosing which one fits your organization’s specific requirements.
Honest Limitation
This guide reflects Google’s current published terms as of the date noted below, but HIPAA compliance ultimately depends on your organization’s full environment, staff practices, and how PHI moves through your systems beyond Google Workspace alone. Google’s Included Functionality list can change, and specific configuration requirements go deeper than general guidance like this can responsibly cover. For anything specific to your organization’s actual compliance risk, consulting a qualified HIPAA compliance professional, not just a product’s own documentation, is the appropriate next step.
FAQs
Is Google Workspace HIPAA compliant?
Google Workspace can be used in a HIPAA-compliant way, but it isn’t automatically compliant. It requires a signed Business Associate Agreement with Google and correct configuration of the specific services covered under that agreement.
Which Google Workspace plan is HIPAA compliant?
Any paid Business plan, Starter, Standard, or Plus, qualifies for a BAA with Google; this isn’t restricted to higher tiers despite common claims online. What varies by tier is which covered features, like Google Vault, are actually included in your specific plan.
Is Google Workspace Individual HIPAA compliant?
No. Google Workspace Individual and free personal Gmail accounts are both excluded from the BAA entirely, regardless of how they’re configured.
Is Gmail HIPAA compliant?
Yes, Gmail is included in Google’s HIPAA Included Functionality list, meaning it can be used for PHI once your organization has signed the BAA and configured appropriate access controls.
Is Gemini for Google Workspace HIPAA compliant?
Yes, with one exception. Gemini in Workspace, the Gemini app, and Gemini Mac App are covered under the current BAA. Gemini in Chrome specifically is excluded from Included Functionality.
Is Google Voice HIPAA compliant?
Only for managed users provisioned through your Google Workspace organization. The consumer Google Voice app used independently, outside a managed Workspace account, is not covered.
How do I sign a BAA with Google Workspace?
A super administrator reviews and electronically accepts the BAA through the Admin console, under Account settings, then Legal and compliance. Acceptance there is legally binding, the same as a paper agreement.
Conclusion
Google Workspace can support genuine HIPAA compliance, but two specific, common misconceptions cause most of the confusion around this question: the belief that only expensive plan tiers qualify (Business Starter is eligible too) and the belief that signing the BAA alone is sufficient (it’s the starting point, not the finish line). Get the plan-tier myth and the configuration requirements right, and Google Workspace is a legitimate, widely used platform for handling PHI across healthcare organizations of every size.







