Screenata

Beyond SOC 2

How much does HIPAA compliant Gmail cost?

August 22, 20263 min read

How much does HIPAA compliant Gmail cost?

Roughly $7 to $22 per user per month. That is the price of a paid Google Workspace Business plan, and a paid plan is the only route, because Google signs a Business Associate Agreement (BAA) for Workspace and does not offer one for consumer accounts. The BAA itself costs nothing extra; an administrator accepts it in the Admin console. Free @gmail.com accounts can never be HIPAA compliant at any price.

One wording note: Google's own term is "HIPAA-eligible," not "HIPAA compliant," and the distinction is real. Workspace gives you an email service that can be used in a compliant way. Whether your organization is compliant depends on configuration and process, covered below.

What each option costs and what the BAA covers

OptionRough priceBAANotes
Free consumer Gmail (@gmail.com)$0Not availableCannot hold PHI under any configuration
Workspace Business StarterRoughly $7 per user per monthIncluded; accept in Admin consoleCovers Gmail, Drive, Calendar, Meet as HIPAA-eligible services
Workspace Business StandardRoughly $14 per user per monthIncludedAdds storage and features; BAA coverage is the same
Workspace Business PlusRoughly $22 per user per monthIncludedAdds Vault for retention and eDiscovery, useful for HIPAA record-keeping
Any plan, BAA acceptedNo added feeSignedCovers Google's obligations only; your configuration and policies are still on you

Prices are approximate and change; Google adjusts plan pricing periodically, so treat the range as a budgeting figure rather than a quote. For a 10-person practice, HIPAA-eligible email lands around $840 to $2,640 per year.

The BAA is free, and it is not the whole job

The BAA obligates Google to safeguard PHI in the covered services and report breaches on its side. It does not configure your account, and it does not govern your staff. To use Gmail with PHI defensibly you still need to do your part of the Security Rule:

  • Access controls. Unique accounts per user, 2-step verification enforced, and prompt offboarding when someone leaves.
  • Transmission security. Gmail encrypts mail in transit by default, but mail to a recipient whose server does not support TLS can fall back; sensitive workflows often add a secure-messaging layer or use Workspace rules to restrict where PHI can be sent.
  • Retention and auditability. Admin audit logs, and on Business Plus, Vault retention rules that match your record-keeping obligations.
  • Organizational measures. A documented risk assessment, written policies, and workforce training. A signed BAA with an untrained team is how most email-related violations happen.

The rest of your stack needs BAAs too

Email is rarely the only place PHI lives. Every vendor that stores or transmits PHI for you, EHR, scheduling, analytics, transcription, needs its own BAA. Our BAA directory tracks which common software vendors will sign one and on which plans, which makes it a quick check before PHI reaches a new tool.

Connect and see

See your SOC 2 with your real systems.

Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, and prioritized next actions before you commit to anything.