Is Google Calendar HIPAA compliant?
Yes inside Google Workspace once an administrator has accepted the agreement — Google names Calendar in its included functionality — but an invitation is a disclosure, and whatever you type in the title travels to every attendee's inbox.
Applies to Google Calendar in Google Workspace. Last reviewed against Google's own documentation. Next review February 5, 2027.
Reviewed by Dr. Rachel Foster, MD — Pediatrician and small practice owner.
What you must do
- An administrator must accept the Workspace agreement: Admin console, Account settings, then Legal and compliance. Google names Google Calendar in its included functionality list.
- Use organisational Workspace accounts. A personal Google account is not your tenant and carries none of this.
- Decide deliberately what goes in an event title and description, because invitations and notification emails carry both to every attendee — including external ones who are outside your agreement entirely.
- Keep third-party calendar add-ons out of anything involving patients: Google states add-ons are not included.
- Re-read the included-functionality list on a schedule. It is dated and Google revises it.
Does Google Calendar sign a business associate agreement?
Yes. Google offers one. Google Workspace under an accepted agreement. The included-functionality list does not enumerate eligible editions — confirm yours in the Admin console. Super administrator → Admin console → Account settings → Legal and compliance → review and accept the agreement.
What this means in practice
Calendar is covered as part of Workspace rather than on its own, so the real question is whether your administrator ever accepted the Workspace agreement. Google names Google Calendar directly in its included-functionality list, which makes this one of the more clear-cut answers in the suite.
The risk here is not the platform, it is the habit. A calendar entry is a small, informal-feeling box that people fill in with whatever makes the day legible — a name, a procedure, a reason for the visit. Invitations and notification emails then carry that text to every attendee, and an invitation sent to a patient, a family member or an outside specialist has left your tenant and your agreement behind. The platform is covered; the disclosure is still a disclosure.
The practical fix is a convention rather than a control: initials or a record number in the title, clinical detail in the record system where it belongs, and a deliberate decision about whether external attendees are invited at all.
How organizations get this wrong
The specific mistakes we see with Google Calendar, not generic advice.
- Putting a patient's full name and reason for visit in the event title, which is then delivered by email to every attendee.
- Inviting patients or outside specialists directly, which sends the same text to inboxes outside your tenant.
- Connecting a third-party scheduling or booking add-on, which Google states is not included.
- Reaching for Calendar when the actual need is patient self-booking, which is a different product category with different agreements.
What the agreement does not cover
- Third-party applications and add-ons, which Google states are not included.
- Additional Google Services, which the agreement does not extend to.
- What an external attendee's own mail system does with an invitation once it has left your tenant.
Alternatives
Listed on merit. We take no payment for placement and use no affiliate links.
Built for patient self-booking rather than internal calendaring, with its own agreement
The equivalent calendar inside a commercial Microsoft tenant, covered through the Product Terms
Signing the agreement is step one. Proving it is step two.
Once you have the agreement with Google Calendar, someone has to know it exists, where the copy is, when it needs revisiting and who owns it. That register is what a client's security questionnaire is actually asking about, and it is the section of an evidence pack most organizations cannot produce on request.
$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.
Sources
Every statement above comes from Google’s own published documentation, read on the date shown.
- HIPAA Included Functionality — Google. Published May 14, 2026. Read August 10, 2026.
- HIPAA compliance with Google Workspace and Cloud Identity — Google. No publication date given. Read August 10, 2026.
Change history
- — First published.
This page is information, not certification and not legal advice. It reflects Google’s published documentation as read on August 10, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.
Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.