Is Google Drive HIPAA compliant?
Yes on a Google Workspace or Cloud Identity account where a super administrator has accepted Google's business associate amendment — but Drive on a personal Google account cannot be covered, because there is no administrator to accept it.
Applies to Google Drive on Google Workspace or Cloud Identity. Last reviewed against Google's own documentation. Next review January 12, 2027.
Reviewed by Lisa Tran, CISSP — Healthcare Information Security Executive.
What you must do
- Be on Google Workspace or Cloud Identity, not a personal Google account.
- A super administrator must accept the amendment before any patient information goes into Drive: Admin console → Account settings → Legal and compliance.
- Drive is named on Google's HIPAA Included Functionality list effective 14 May 2026, which covers Google Drive including Docs, Forms, Sheets, Slides and Vids.
- Turn off or restrict Additional Google Services for anyone handling patient information — Google states neither the Cloud Data Processing Addendum nor the Workspace agreement extends to them.
- Vet Marketplace add-ons and any third-party app with Drive access. Google excludes third-party applications including add-ons from Included Functionality.
- Sharing is your configuration, not Google's obligation. Link sharing, 'anyone with the link', external sharing defaults and shared-drive membership are all yours to control.
Does Google Drive sign a business associate agreement?
Yes. Google offers one. Google Workspace or Cloud Identity. Google scopes coverage by service through Included Functionality rather than by subscription tier. Nothing to request and no signature to chase — a super administrator accepts it in the Admin console under Account settings → Legal and compliance.
What the agreement does not cover
- Drive on a personal Google account. The amendment is accepted in the Admin console, which a consumer account does not have.
- Additional Google Services, which Google places outside both the addendum and the Workspace agreement.
- Third-party applications and Marketplace add-ons connected to the drive.
- Anything a user copies out of Drive into an uncovered service.
Alternatives
Listed on merit. We take no payment for placement and use no affiliate links.
Team plans with the agreement signed electronically in the admin console
Covered by default through Microsoft's Data Protection Addendum, with nothing to accept
Enterprise-tier storage with stronger governance tooling
Signing the agreement is step one. Proving it is step two.
Once you have the agreement with Google Drive, someone has to know it exists, where the copy is, when it needs revisiting and who owns it. That register is what a client's security questionnaire is actually asking about, and it is the section of an evidence pack most organizations cannot produce on request.
$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.
Sources
Every statement above comes from Google’s own published documentation, read on the date shown.
- HIPAA Included Functionality — Google. Published May 14, 2026. Read August 13, 2026.
- HIPAA compliance with Google Workspace and Cloud Identity — Google. No publication date given. Read August 13, 2026.
Change history
- — First published.
This page is information, not certification and not legal advice. It reflects Google’s published documentation as read on August 13, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.
Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.