Google Workspace: HIPAA status
Gmail, Drive and the rest of Google's business suite. Google offers a HIPAA BAA that customers accept in the Admin console.
Google Workspace signs a Business Associate Agreement. Accepted electronically in the Admin console (Account settings > Legal and compliance). Covers the services on Google's HIPAA Included Functionality list.
Source: Google — HIPAA compliance with Google Workspace and Cloud Identity · checked
Google Workspace and HIPAA at a glance
Google Workspace signs a Business Associate Agreement. A BAA alone does not make its use HIPAA compliant: you still need to review and accept the HIPAA BAA in the Admin console under Account settings > Legal and compliance, and enforce 2-Step Verification for all users in the Admin console. Facts checked against Google's own documentation on 2026-10-05.
| Signs a BAA | Yes |
|---|---|
| How you get it | Accepted electronically in the Admin console (Account settings > Legal and compliance). Covers the services on Google's HIPAA Included Functionality list. |
| You still need to | Review and accept the HIPAA BAA in the Admin console under Account settings > Legal and compliance. |
| Main limitation | Third-party applications and add-ons are not covered by Google's BAA. |
| Last checked | 2026-10-05 |
BAA details
What you still have to configure
- Review and accept the HIPAA BAA in the Admin console under Account settings > Legal and compliance. source
- Enforce 2-Step Verification for all users in the Admin console. source
- Keep PHI out of third-party add-ons and Marketplace apps unless they have their own BAA. source
Limitations
- Third-party applications and add-ons are not covered by Google's BAA. source
- Additional Google Services outside the core Workspace services are not covered by the BAA. source
- Client-side (end-to-end) encryption for Gmail is only available on Enterprise Plus, Frontline Plus and Education Standard/Plus editions. source
Against our criteria
| Encryption in transit | Yes — Encrypted in transit by default. | Google Workspace security whitepaper — encryption |
|---|---|---|
| Encryption at rest | Yes — Encrypted at rest by default. | Google Workspace security whitepaper — encryption |
| Secure delivery to patients | Partial — Client-side encryption only on Enterprise Plus, Frontline Plus and Education editions; Business editions have no built-in encrypted delivery to outside recipients. | Google — About client-side encryption |
| Enforceable MFA | Yes — Admins can enforce 2-Step Verification for the whole organization or specific groups. | Google — Deploy 2-Step Verification |
| Audit logs for customers | Yes — Gmail log events can be searched on all editions; the security investigation tool needs Enterprise or higher. | Google — Gmail log events |