HIPAA · File storage
Is Google Drive HIPAA compliant?
Conditional
Google Drive is covered by the Google Workspace BAA, including Docs, Forms, Sheets, Slides and Vids. It is not HIPAA compliant on a personal Google account, and sharing settings are where most Drive findings actually come from.
- Which plans the BAA covers
- Google Workspace and Cloud Identity, accepted by an administrator in the Admin console.
Scope
What the BAA does and does not cover.
Covered
- Drive is on the Included Functionality list, explicitly including Docs, Forms, Sheets, Slides and Vids
- As of 2026-05-14 Google's HIPAA Included Functionality list covers AppSheet, Apps Script, Cloud Identity Management, the Gemini app (excluding Gemini in Chrome), Gemini Mac App, Gemini in Workspace, Gmail, Calendar, Chat, Cloud Search, Drive (including Docs, Forms, Sheets, Slides and Vids), Groups, Keep, Meet, Sites, Tasks, Vault where applicable, and Voice for managed users.
Not covered
- Personal Google accounts
- Third-party Drive add-ons and Marketplace apps with Drive scopes
- Anything shared out via a public link — coverage by the BAA says nothing about who you handed the file to
Your side of the agreement
A signed BAA is not a configured system.
Signing shifts liability; it does not change a setting. These are the steps that remain yours once Google Drive is in scope.
- 1Accept the BAA in the Admin console — it is not active by default, and using PHI before accepting it is a gap an auditor will find
- 2Turn off or scope any Additional Google Services, which the BAA does not reach
- 3Audit third-party Marketplace add-ons: they are explicitly outside the BAA even when installed on a covered account
- 4Restrict PHI to the covered services above, and train staff on which surfaces those are
- 5Set link-sharing defaults so PHI files cannot be made public by accident, and review externally shared files on a schedule
Evidence
What an auditor will actually ask for.
Every item below is evidence someone has to produce, date and re-produce at the next audit. Screenata's agent collects these on a schedule instead.
- The accepted BAA from the Admin console
- Drive sharing policy configuration for PHI-handling organizational units
- A report of externally shared or link-shared files, reviewed periodically
- OAuth app inventory showing which third-party apps hold Drive scopes
See how Screenata handles this on HIPAA programs, or read what healthcare SaaS needs beyond SOC 2.
Sources
Verified against vendor documentation on 2026-08-08. BAA terms change — re-check before relying on this.