Screenata

HIPAA · Productivity suite

Is Google Workspace HIPAA compliant?

Conditional

Google Workspace can be used with PHI once an administrator accepts the BAA in the Admin console, but the agreement covers only the services on Google's HIPAA Included Functionality list — not third-party add-ons and not Additional Google Services.

Which plans the BAA covers
Available to Google Workspace and Cloud Identity customers, accepted electronically by an administrator in the Admin console.
All tools

Scope

What the BAA does and does not cover.

Covered

  • As of 2026-05-14 Google's HIPAA Included Functionality list covers AppSheet, Apps Script, Cloud Identity Management, the Gemini app (excluding Gemini in Chrome), Gemini Mac App, Gemini in Workspace, Gmail, Calendar, Chat, Cloud Search, Drive (including Docs, Forms, Sheets, Slides and Vids), Groups, Keep, Meet, Sites, Tasks, Vault where applicable, and Voice for managed users.

Not covered

  • Third-party applications including Marketplace add-ons
  • Additional Google Services, which the BAA and the Cloud Data Processing Addendum do not extend to
  • Gemini in Chrome, which is carved out of the Gemini app coverage
  • Consumer accounts outside a managed Workspace domain

Your side of the agreement

A signed BAA is not a configured system.

Signing shifts liability; it does not change a setting. These are the steps that remain yours once Google Workspace is in scope.
  1. 1Accept the BAA in the Admin console — it is not active by default, and using PHI before accepting it is a gap an auditor will find
  2. 2Turn off or scope any Additional Google Services, which the BAA does not reach
  3. 3Audit third-party Marketplace add-ons: they are explicitly outside the BAA even when installed on a covered account
  4. 4Restrict PHI to the covered services above, and train staff on which surfaces those are

Evidence

What an auditor will actually ask for.

Every item below is evidence someone has to produce, date and re-produce at the next audit. Screenata's agent collects these on a schedule instead.
  • The accepted BAA and its acceptance date from the Admin console
  • A service-by-service configuration export showing which Workspace services are on for PHI-handling OUs
  • Evidence that Additional Google Services are disabled or scoped away from PHI users
  • Quarterly access reviews for the covered services

See how Screenata handles this on HIPAA programs, or read what healthcare SaaS needs beyond SOC 2.

Sources

Verified against vendor documentation on 2026-08-08. BAA terms change — re-check before relying on this.