CompyMax

HIPAA compliant productivity suites

Email, documents, calendars and storage bundled together. Coverage is usually per-service, so the suite being covered does not mean every app inside it is.

A suite is sold as one subscription, which makes it easy to assume one agreement blankets everything inside it. Coverage is granted service by service. The mail, calendar and document apps are typically named; the extras bolted on around them, including browser assistants, consumer-branded side apps and anything the vendor labels as additional or optional, are frequently written out of scope in the very document that covers the core.

These lists also move. Services are added, and features are carved out of services that were already listed, sometimes more than once a year. The suites worth trusting publish a dated, named list of covered services and let an administrator switch off the uncovered ones for specific staff. The ones to avoid say only that their platform supports healthcare customers and leave you to work out which apps that includes.

2 productivity suites compared

2 of 2 can be used with patient information under a signed agreement. Each row is drawn from that vendor’s published documentation as read on the date shown — open an entry for the full conditions and sources.

VendorVerdictAgreement and planHow to get itNot coveredReviewed
Google WorkspaceGoogle Workspace and Cloud IdentityConditionalOffered for electronic acceptance in the Admin console. Google's documentation does not name an edition restriction.Sign in as a super administrator → Admin console → Account settings → Legal and compliance → review and accept the HIPAA Business Associate Amendment.Additional Google Services. Google states neither the Cloud Data Processing Addendum nor the Workspace agreement extends to them.
Microsoft 365Microsoft 365 (Teams, Exchange Online, SharePoint, OneDrive)ConditionalApplies by default to business and enterprise Online Services customers who are covered entities or business associates.Nothing to request. To keep proof, sign in to the Service Trust Portal and download the 'Microsoft General – HIPAA BAA' document.Any Microsoft cloud service not named on the in-scope list. The published table carries rows for Commercial and Government Community Cloud only.

What to check before you adopt one

  • Get the vendor's named list of covered services in writing, with the date it took effect, rather than a marketing claim that the platform as a whole supports healthcare customers.
  • Check whether the add-on marketplace sits inside or outside the agreement, and whether an administrator can restrict which extensions staff are able to install.
  • Establish who has authority to accept the agreement, and whether acceptance is a click in an admin console or already applies through your master contract.
  • Ask whether the AI assistant built into the suite is covered, since AI is the part of these lists that has been changing most often.
  • Verify that coverage applies to your specific subscription type, because consumer and legacy free versions of the same suite are usually outside it.

The expensive mistake

Accepting the agreement once and never re-reading the covered-services list. Staff adopt whatever new app the vendor ships into the suite, assuming the original acceptance stretched to cover it. These lists are revised regularly, and features do get carved out of services already named on them. Put a reminder in the calendar to re-read the list before anyone adopts something new.

Tracking which of these your organization uses?

The vendor and BAA register keeps every tool that touches patient information, its agreement status and its renewal date in one place — seeded from this research. See pricing.

Information, not certification and not legal advice. Each entry reflects that vendor’s published documentation as read on the date shown on its page. Vendors change terms without notice — confirm anything you rely on directly with them.