Beyond SOC 2
How much does HIPAA compliant Gmail cost?
How much does HIPAA compliant Gmail cost?
Roughly $7 to $22 per user per month. That is the price of a paid Google Workspace Business plan, and a paid plan is the only route, because Google signs a Business Associate Agreement (BAA) for Workspace and does not offer one for consumer accounts. The BAA itself costs nothing extra; an administrator accepts it in the Admin console. Free @gmail.com accounts can never be HIPAA compliant at any price.
One wording note: Google's own term is "HIPAA-eligible," not "HIPAA compliant," and the distinction is real. Workspace gives you an email service that can be used in a compliant way. Whether your organization is compliant depends on configuration and process, covered below.
What each option costs and what the BAA covers
| Option | Rough price | BAA | Notes |
|---|---|---|---|
| Free consumer Gmail (@gmail.com) | $0 | Not available | Cannot hold PHI under any configuration |
| Workspace Business Starter | Roughly $7 per user per month | Included; accept in Admin console | Covers Gmail, Drive, Calendar, Meet as HIPAA-eligible services |
| Workspace Business Standard | Roughly $14 per user per month | Included | Adds storage and features; BAA coverage is the same |
| Workspace Business Plus | Roughly $22 per user per month | Included | Adds Vault for retention and eDiscovery, useful for HIPAA record-keeping |
| Any plan, BAA accepted | No added fee | Signed | Covers Google's obligations only; your configuration and policies are still on you |
Prices are approximate and change; Google adjusts plan pricing periodically, so treat the range as a budgeting figure rather than a quote. For a 10-person practice, HIPAA-eligible email lands around $840 to $2,640 per year.
The BAA is free, and it is not the whole job
The BAA obligates Google to safeguard PHI in the covered services and report breaches on its side. It does not configure your account, and it does not govern your staff. To use Gmail with PHI defensibly you still need to do your part of the Security Rule:
- Access controls. Unique accounts per user, 2-step verification enforced, and prompt offboarding when someone leaves.
- Transmission security. Gmail encrypts mail in transit by default, but mail to a recipient whose server does not support TLS can fall back; sensitive workflows often add a secure-messaging layer or use Workspace rules to restrict where PHI can be sent.
- Retention and auditability. Admin audit logs, and on Business Plus, Vault retention rules that match your record-keeping obligations.
- Organizational measures. A documented risk assessment, written policies, and workforce training. A signed BAA with an untrained team is how most email-related violations happen.
The rest of your stack needs BAAs too
Email is rarely the only place PHI lives. Every vendor that stores or transmits PHI for you, EHR, scheduling, analytics, transcription, needs its own BAA. Our BAA directory tracks which common software vendors will sign one and on which plans, which makes it a quick check before PHI reaches a new tool.