<!-- Source: screenata.com -->
<!-- Content type: AEO answer page -->
<!-- Topics: SOC 2, ISO 27001, HIPAA, HITRUST, CMMC, compliance evidence -->

---
question: "How much does HIPAA compliant Gmail cost?"
title: "How Much Does HIPAA Compliant Gmail Cost"
seoTitle: "HIPAA Compliant Gmail Cost: Google Workspace Plans and BAA"
summary: "HIPAA-eligible Gmail costs roughly $7 to $22 per user per month, which is the price of a paid Google Workspace Business plan. Google signs a Business Associate Agreement (BAA) for Workspace at no extra charge; you accept it in the Admin console. Free consumer Gmail can never be HIPAA compliant at any price, because Google does not offer a BAA for consumer accounts. The BAA also does not make you compliant by itself: you still have to configure the account (access controls, 2-step verification, retention) and do the organizational work HIPAA requires, including a documented risk assessment and workforce training."
publishedAt: "2026-08-22"
keywords:
  - "HIPAA compliant Gmail cost"
  - "Google Workspace BAA"
  - "is Gmail HIPAA compliant"
  - "HIPAA compliant email pricing"
pillar: "Beyond SOC 2"
faqs:
  - question: "Does Google sign a BAA for Gmail?"
    answer: "Yes, but only for paid Google Workspace accounts. The BAA covers Gmail along with other core Workspace services such as Drive and Calendar, and it costs nothing beyond the Workspace subscription. An administrator accepts it in the Admin console; there is no negotiation and no separate contract to buy."
  - question: "Is free Gmail HIPAA compliant?"
    answer: "No, and it cannot be made compliant. Google does not offer a BAA for consumer @gmail.com accounts, and HIPAA requires a BAA with any vendor that stores or transmits PHI on your behalf. Sending or receiving PHI through a free Gmail account is a HIPAA violation regardless of how carefully the account is used."
  - question: "What else do I need besides a BAA?"
    answer: "Configuration and organizational measures. On the Google side that means access controls, 2-step verification, sensible sharing and retention settings, and admin audit logging. On your side it means a documented risk assessment, policies, workforce training, and BAAs with every other vendor that touches PHI. A signed BAA is the entry ticket, not the finish line."
  - question: "When should a BAA be signed?"
    answer: "Before any PHI touches the vendor's systems. The BAA is what makes disclosing PHI to a vendor lawful in the first place, so signing one after the fact does not cure the earlier violation; the period before signature remains an impermissible disclosure. In practice, accept the Google Workspace BAA in the Admin console before migrating any mailbox that will handle PHI."
  - question: "Is Google Workspace HIPAA certified?"
    answer: "No, because no product is: there is no official HIPAA certification for software or services. Google Workspace is HIPAA-eligible, meaning Google will sign a BAA covering Gmail and other core services on paid plans. Whether your use of it is compliant depends on configuration, policies, and training on your side."
---

## How much does HIPAA compliant Gmail cost?

Roughly $7 to $22 per user per month. That is the price of a paid Google Workspace Business plan, and a paid plan is the only route, because Google signs a Business Associate Agreement (BAA) for Workspace and does not offer one for consumer accounts. The BAA itself costs nothing extra; an administrator accepts it in the Admin console. Free @gmail.com accounts can never be HIPAA compliant at any price.

One wording note: Google's own term is "HIPAA-eligible," not "HIPAA compliant," and the distinction is real. Workspace gives you an email service that can be used in a compliant way. Whether your organization is compliant depends on configuration and process, covered below.

### What each option costs and what the BAA covers

| Option | Rough price | BAA | Notes |
|---|---|---|---|
| Free consumer Gmail (@gmail.com) | $0 | Not available | Cannot hold PHI under any configuration |
| Workspace Business Starter | Roughly $7 per user per month | Included; accept in Admin console | Covers Gmail, Drive, Calendar, Meet as HIPAA-eligible services |
| Workspace Business Standard | Roughly $14 per user per month | Included | Adds storage and features; BAA coverage is the same |
| Workspace Business Plus | Roughly $22 per user per month | Included | Adds Vault for retention and eDiscovery, useful for HIPAA record-keeping |
| Any plan, BAA accepted | No added fee | Signed | Covers Google's obligations only; your configuration and policies are still on you |

Prices are approximate and change; Google adjusts plan pricing periodically, so treat the range as a budgeting figure rather than a quote. For a 10-person practice, HIPAA-eligible email lands around $840 to $2,640 per year.

## The BAA is free, and it is not the whole job

The BAA obligates Google to safeguard PHI in the covered services and report breaches on its side. It does not configure your account, and it does not govern your staff. To use Gmail with PHI defensibly you still need to do your part of the Security Rule:

- **Access controls.** Unique accounts per user, 2-step verification enforced, and prompt offboarding when someone leaves.
- **Transmission security.** Gmail encrypts mail in transit by default, but mail to a recipient whose server does not support TLS can fall back; sensitive workflows often add a secure-messaging layer or use Workspace rules to restrict where PHI can be sent.
- **Retention and auditability.** Admin audit logs, and on Business Plus, Vault retention rules that match your record-keeping obligations.
- **Organizational measures.** A documented risk assessment, written policies, and workforce training. A signed BAA with an untrained team is how most email-related violations happen.

## The rest of your stack needs BAAs too

Email is rarely the only place PHI lives. Every vendor that stores or transmits PHI for you, EHR, scheduling, analytics, transcription, needs its own BAA. Our [BAA directory](/hipaa) tracks which common software vendors will sign one and on which plans, which makes it a quick check before PHI reaches a new tool.
