CompyMax

Is Google Workspace HIPAA compliant?

Only under specific conditions

Yes, if a super administrator accepts Google's business associate amendment in the Admin console and you keep patient information only inside the specific Google services it covers.

Applies to Google Workspace and Cloud Identity. Last reviewed against Google's own documentation. Next review November 27, 2026.

Reviewed by Lisa Tran, CISSP — Healthcare Information Security Executive.

What you must do

  • A super administrator must accept the amendment before any patient information goes into Google services: Admin console → Account settings → Legal and compliance.
  • Keep patient information only within Google's published HIPAA Included Functionality list. The version effective 14 May 2026 covers AppSheet, Apps Script, Cloud Identity Management, the Gemini app, Gemini in Workspace, Gmail, Calendar, Chat, Cloud Search, Drive (including Docs, Forms, Sheets, Slides and Vids), Groups, Keep, Meet, Sites, Tasks, Vault and Voice.
  • Turn off or restrict Additional Google Services for anyone who handles patient information.
  • Vet and restrict Marketplace and third-party add-ons — the agreement does not reach them.
  • Google Voice is covered for managed users only, so provision Voice users as managed users.

Does Google Workspace sign a business associate agreement?

Yes. Google offers one. Offered for electronic acceptance in the Admin console. Google's documentation does not name an edition restriction. Sign in as a super administrator → Admin console → Account settings → Legal and compliance → review and accept the HIPAA Business Associate Amendment.

See their documentation.

What this means in practice

Google's amendment costs nothing and takes about a minute, which is exactly why it gets skipped. A super administrator has to open Account settings, go to Legal and compliance, and accept it. Paying Google every month does not do this for you, and there is no reminder. Plenty of practices have run patient email through Gmail for years on the assumption that a paid account implies coverage.

The second half is harder and more permanent. The amendment does not cover Google as a whole; it covers a published list of services, currently including Gmail, Calendar, Drive, Chat, Meet, Keep, Sites, Tasks, Vault and Voice. Everything Google groups as Additional Google Services sits outside it, as do Marketplace add-ons and, oddly, Gemini in Chrome even though the Gemini app itself is included.

In practice that means the administrator has a standing job: turn off Additional Google Services for anyone who touches patient information, keep an allowlist of add-ons, provision Voice users as managed users, and re-read the covered list at review time because it does change.

How organizations get this wrong

The specific mistakes we see with Google Workspace, not generic advice.

  • Assuming that paying for Workspace means the amendment is accepted, when nobody with super administrator rights has ever opened Legal and compliance.
  • Leaving Additional Google Services switched on for clinical staff, so patient information drifts into products the amendment does not reach.
  • Letting staff run Gemini in Chrome over patient documents because the Gemini app is on the covered list and it feels like the same thing.
  • Installing a Drive or Gmail add-on from the Marketplace without checking whether its own vendor will sign anything with you.

What the agreement does not cover

  • Additional Google Services. Google states neither the Cloud Data Processing Addendum nor the Workspace agreement extends to them.
  • Third-party applications and add-ons, which Google explicitly excludes from included functionality.
  • Gemini in Chrome, carved out of the otherwise-covered Gemini functionality.
  • Google Voice for users who are not managed users.

Alternatives

Listed on merit. We take no payment for placement and use no affiliate links.

  • Microsoft 365

    Equivalent suite where the agreement applies by default through the Data Protection Addendum

  • Box

    If the requirement is really just document storage with enterprise governance

Signing the agreement is step one. Proving it is step two.

Once you have the agreement with Google Workspace, someone has to know it exists, where the copy is, when it needs revisiting and who owns it. That register is what a client's security questionnaire is actually asking about, and it is the section of an evidence pack most organizations cannot produce on request.

$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.

Sources

Every statement above comes from Google’s own published documentation, read on the date shown.

  1. HIPAA Compliance with Google Workspace and Cloud IdentityGoogle. No publication date given. Read July 29, 2026.
  2. HIPAA Included FunctionalityGoogle. Published May 14, 2026. Read July 29, 2026.
  3. Google Workspace HIPAA Business Associate AmendmentGoogle. Published September 12, 2025. Read July 29, 2026.

Change history

  • First published.
  • Source URL updated: Google's HIPAA compliance page moved from support.google.com/a/answer/3407054 to knowledge.workspace.google.com. The old address now redirects. Re-read at the new location on the same date — the verdict, conditions and Included Functionality list are unchanged.

This page is information, not certification and not legal advice. It reflects Google’s published documentation as read on July 29, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.

Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.