CompyMax

Is Google Meet HIPAA compliant?

Only under specific conditions

Yes, if you run Meet inside a managed Google Workspace account and a super administrator accepts the amendment before any patient visit takes place.

Applies to Google Meet in Google Workspace. Last reviewed against Google's own documentation. Next review January 14, 2027.

Reviewed by Carlos Mendez — IT Security Manager, regional healthcare network.

What you must do

  • Host from a managed Google Workspace or Cloud Identity account.
  • A super administrator accepts the amendment first: Admin console → Account settings → Legal and compliance.
  • Meet is named on the Included Functionality list effective 14 May 2026.
  • Keep recordings, transcripts and notes inside covered services — Drive, including Docs, is on the same list.
  • Restrict Additional Google Services for staff running clinical visits.
  • Block or review Marketplace add-ons and any external meeting assistant.

Does Google Meet sign a business associate agreement?

Yes. Google offers one. A Google Workspace or Cloud Identity subscription. No minimum edition is published. Super administrator → Admin console → Account settings → Legal and compliance → accept the amendment.

See their documentation.

What this means in practice

Meet has no agreement of its own. It is one line on Google's Included Functionality list — the version effective 14 May 2026 names Google Meet alongside Gmail, Calendar, Chat and Drive — and it becomes covered when a super administrator accepts the Workspace amendment in the Admin console. There is no per-product toggle and no separate healthcare tier to buy.

Because coverage is granted service by service rather than feature by feature, the live call is rarely where practices come unstuck. Recordings, transcripts and notes have to land somewhere, and that somewhere must also be a covered service. Drive, including Docs, is on the same list, which is why keeping meeting artefacts inside Workspace matters more than any in-call setting.

Two boundaries belong in your written policy. Google excludes third-party applications and add-ons, so an external notetaking bot sitting in a telehealth visit is outside the amendment regardless of its own marketing. And the amendment reaches only information handled inside covered services — anything copied into an Additional Google Service leaves its scope.

How organizations get this wrong

The specific mistakes we see with Google Meet, not generic advice.

  • Letting an external AI notetaker join telehealth visits, when Google excludes third-party applications from what the amendment covers.
  • Running visits from a personal Google account because a clinician was never given a licence on the managed domain.
  • Accepting the amendment but leaving Additional Google Services enabled, so recordings get moved outside the covered list.
  • Sharing a recording link broadly rather than restricting it — Google covers the service, not your sharing settings.

What the agreement does not cover

  • Meet used from a free personal Google account.
  • Third-party applications and add-ons, including external AI notetakers that join meetings.
  • Additional Google Services.
  • Gemini in Chrome.

Alternatives

Listed on merit. We take no payment for placement and use no affiliate links.

  • Microsoft Teams

    Named on Microsoft's in-scope list with the agreement applying automatically

  • Doxy.me

    Purpose-built telehealth if the use is patient visits rather than internal meetings

Signing the agreement is step one. Proving it is step two.

Once you have the agreement with Google Meet, someone has to know it exists, where the copy is, when it needs revisiting and who owns it. That register is what a client's security questionnaire is actually asking about, and it is the section of an evidence pack most organizations cannot produce on request.

$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.

Sources

Every statement above comes from Google’s own published documentation, read on the date shown.

  1. HIPAA Included FunctionalityGoogle. Published May 14, 2026. Read July 29, 2026.
  2. Google Workspace HIPAA Business Associate AmendmentGoogle. Published September 12, 2025. Read July 29, 2026.

Change history

  • First published.

This page is information, not certification and not legal advice. It reflects Google’s published documentation as read on July 29, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.

Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.