Screenata

HIPAA · Email

Is Gmail HIPAA compliant?

Conditional

Gmail can be used with PHI, but only as part of Google Workspace with an accepted BAA. A personal @gmail.com account cannot be made HIPAA compliant, because Google does not offer a BAA for consumer accounts.

Which plans the BAA covers
Google Workspace and Cloud Identity, accepted electronically by an administrator in the Admin console. Not available for consumer @gmail.com accounts.
All tools

Scope

What the BAA does and does not cover.

Covered

  • Gmail is on Google's HIPAA Included Functionality list
  • As of 2026-05-14 Google's HIPAA Included Functionality list covers AppSheet, Apps Script, Cloud Identity Management, the Gemini app (excluding Gemini in Chrome), Gemini Mac App, Gemini in Workspace, Gmail, Calendar, Chat, Cloud Search, Drive (including Docs, Forms, Sheets, Slides and Vids), Groups, Keep, Meet, Sites, Tasks, Vault where applicable, and Voice for managed users.
  • Gemini in Workspace smart features (help me write, contextual smart replies, side panel) are covered

Not covered

  • Consumer @gmail.com accounts — no BAA is offered for them at any price
  • Third-party applications and Marketplace add-ons, explicitly excluded from Included Functionality
  • Additional Google Services, which neither the BAA nor the Cloud Data Processing Addendum extends to

Your side of the agreement

A signed BAA is not a configured system.

Signing shifts liability; it does not change a setting. These are the steps that remain yours once Gmail is in scope.
  1. 1Accept the BAA in the Admin console — it is not active by default, and using PHI before accepting it is a gap an auditor will find
  2. 2Turn off or scope any Additional Google Services, which the BAA does not reach
  3. 3Audit third-party Marketplace add-ons: they are explicitly outside the BAA even when installed on a covered account
  4. 4Restrict PHI to the covered services above, and train staff on which surfaces those are

Evidence

What an auditor will actually ask for.

Every item below is evidence someone has to produce, date and re-produce at the next audit. Screenata's agent collects these on a schedule instead.
  • A copy of the accepted BAA, with the acceptance date
  • Admin console screenshot showing HIPAA-covered services enabled and Additional Services restricted
  • The Marketplace add-on inventory for the domain, showing what has access to mailboxes
  • Access reviews for accounts that can read PHI-bearing mailboxes

See how Screenata handles this on HIPAA programs, or read what healthcare SaaS needs beyond SOC 2.

Sources

Verified against vendor documentation on 2026-08-08. BAA terms change — re-check before relying on this.