HIPAA · Team chat
Is Google Chat HIPAA compliant?
Conditional
Google Chat is on Google's HIPAA Included Functionality list, so it is covered once your administrator has accepted the Workspace BAA. Retention and export settings are the part auditors ask about.
- Which plans the BAA covers
- Google Workspace and Cloud Identity, accepted by an administrator in the Admin console.
Scope
What the BAA does and does not cover.
Covered
- Google Chat is named on the Included Functionality list
- As of 2026-05-14 Google's HIPAA Included Functionality list covers AppSheet, Apps Script, Cloud Identity Management, the Gemini app (excluding Gemini in Chrome), Gemini Mac App, Gemini in Workspace, Gmail, Calendar, Chat, Cloud Search, Drive (including Docs, Forms, Sheets, Slides and Vids), Groups, Keep, Meet, Sites, Tasks, Vault where applicable, and Voice for managed users.
Not covered
- Third-party Chat apps and integrations
- Additional Google Services
- Consumer accounts
Your side of the agreement
A signed BAA is not a configured system.
Signing shifts liability; it does not change a setting. These are the steps that remain yours once Google Chat is in scope.
- 1Accept the BAA in the Admin console — it is not active by default, and using PHI before accepting it is a gap an auditor will find
- 2Turn off or scope any Additional Google Services, which the BAA does not reach
- 3Audit third-party Marketplace add-ons: they are explicitly outside the BAA even when installed on a covered account
- 4Restrict PHI to the covered services above, and train staff on which surfaces those are
- 5Configure Chat retention in Google Vault to match your data retention policy, rather than leaving the default
Evidence
What an auditor will actually ask for.
Every item below is evidence someone has to produce, date and re-produce at the next audit. Screenata's agent collects these on a schedule instead.
- The accepted BAA from the Admin console
- Vault retention rules covering Chat, matching your written retention policy
- Chat history and external-chat settings for PHI-handling OUs
See how Screenata handles this on HIPAA programs, or read what healthcare SaaS needs beyond SOC 2.
Sources
Verified against vendor documentation on 2026-08-08. BAA terms change — re-check before relying on this.