CompyMax

Is Google Forms HIPAA compliant?

Only under specific conditions

Yes, if you use Forms inside a paid Google Workspace account where a super administrator has accepted Google's amendment — Forms is covered as part of Google Drive.

Applies to Google Forms (Google Workspace). Last reviewed against Google's own documentation. Next review January 8, 2027.

Reviewed by Margaret O'Brien — HIPAA Privacy Officer.

What you must do

  • A super administrator must accept the amendment before any patient information is collected: Admin console → Account settings → Legal and compliance.
  • Use Forms inside your managed Workspace or Cloud Identity account, not on a personal Google account.
  • The Included Functionality list effective 14 May 2026 names Google Drive including Google Forms and Google Sheets, so the form and its response spreadsheet are both in scope.
  • Turn off or restrict Additional Google Services for staff who handle patient information.
  • Do not install Forms add-ons — Google excludes third-party applications and add-ons.
  • Control sharing on the response spreadsheet and any uploaded files, limiting access to named recipients rather than anyone with the link.

Does Google Forms sign a business associate agreement?

Yes. Google offers one. A paid Google Workspace or Cloud Identity subscription. Google names no edition requirement, and there is no separate Forms product to buy. Sign in as a super administrator → Admin console → Account settings → Legal and compliance → accept the HIPAA Business Associate Amendment.

See their documentation.

What this means in practice

There is no separate Forms agreement to chase. Google covers Forms as part of Drive on its Included Functionality list, so the moment a super administrator accepts the Workspace amendment in the Admin console, the form and the response spreadsheet behind it are both in scope.

That makes Forms the cheapest workable intake option for a practice already paying for Workspace. What it does not give you is intake tooling — no conditional routing into a chart, no signed consent, no payment capture — and responses inherit Drive's sharing model, so a link-shared response sheet is your problem to control, not Google's.

The real exposure is add-ons. Google states plainly that third-party applications and add-ons sit outside the amendment, which includes every Marketplace add-on advertised as adding HIPAA features to Forms.

How organizations get this wrong

The specific mistakes we see with Google Forms, not generic advice.

  • Installing a Marketplace add-on that promises HIPAA features for Forms. Google excludes third-party applications and add-ons entirely.
  • Building the intake form on a personal Gmail account instead of inside the managed Workspace tenant that accepted the amendment.
  • Leaving the response spreadsheet shared with anyone who has the link, which puts patient answers outside your own access controls.
  • Assuming acceptance already happened. Nothing is covered until a super administrator has actually accepted the amendment.

What the agreement does not cover

  • Forms created under a free personal Google account.
  • Third-party applications and add-ons, including Marketplace add-ons advertised as adding HIPAA features to Forms.
  • Additional Google Services.
  • Gemini in Chrome.
  • Any Google product not named on the Included Functionality list.

Alternatives

Listed on merit. We take no payment for placement and use no affiliate links.

  • Jotform

    Purpose-built intake with conditional logic, e-signature and payment fields that Forms lacks

  • Formstack

    Healthcare plan with database encryption for higher-volume intake

Signing the agreement is step one. Proving it is step two.

Once you have the agreement with Google Forms, someone has to know it exists, where the copy is, when it needs revisiting and who owns it. That register is what a client's security questionnaire is actually asking about, and it is the section of an evidence pack most organizations cannot produce on request.

$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.

Sources

Every statement above comes from Google’s own published documentation, read on the date shown.

  1. HIPAA Included FunctionalityGoogle. Published May 14, 2026. Read July 29, 2026.
  2. HIPAA Compliance with Google Workspace and Cloud IdentityGoogle. Published July 22, 2026. Read July 29, 2026.

Change history

  • First published.

This page is information, not certification and not legal advice. It reflects Google’s published documentation as read on July 29, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.

Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.