Screenata

HIPAA · Team chat

Is Google Chat HIPAA compliant?

Conditional

Google Chat is on Google's HIPAA Included Functionality list, so it is covered once your administrator has accepted the Workspace BAA. Retention and export settings are the part auditors ask about.

Which plans the BAA covers
Google Workspace and Cloud Identity, accepted by an administrator in the Admin console.
All tools

Scope

What the BAA does and does not cover.

Covered

  • Google Chat is named on the Included Functionality list
  • As of 2026-05-14 Google's HIPAA Included Functionality list covers AppSheet, Apps Script, Cloud Identity Management, the Gemini app (excluding Gemini in Chrome), Gemini Mac App, Gemini in Workspace, Gmail, Calendar, Chat, Cloud Search, Drive (including Docs, Forms, Sheets, Slides and Vids), Groups, Keep, Meet, Sites, Tasks, Vault where applicable, and Voice for managed users.

Not covered

  • Third-party Chat apps and integrations
  • Additional Google Services
  • Consumer accounts

Your side of the agreement

A signed BAA is not a configured system.

Signing shifts liability; it does not change a setting. These are the steps that remain yours once Google Chat is in scope.
  1. 1Accept the BAA in the Admin console — it is not active by default, and using PHI before accepting it is a gap an auditor will find
  2. 2Turn off or scope any Additional Google Services, which the BAA does not reach
  3. 3Audit third-party Marketplace add-ons: they are explicitly outside the BAA even when installed on a covered account
  4. 4Restrict PHI to the covered services above, and train staff on which surfaces those are
  5. 5Configure Chat retention in Google Vault to match your data retention policy, rather than leaving the default

Evidence

What an auditor will actually ask for.

Every item below is evidence someone has to produce, date and re-produce at the next audit. Screenata's agent collects these on a schedule instead.
  • The accepted BAA from the Admin console
  • Vault retention rules covering Chat, matching your written retention policy
  • Chat history and external-chat settings for PHI-handling OUs

See how Screenata handles this on HIPAA programs, or read what healthcare SaaS needs beyond SOC 2.

Sources

Verified against vendor documentation on 2026-08-08. BAA terms change — re-check before relying on this.