A behavioral health practice in the Midwest thought they were covered. They'd signed Google's Business Associate Agreement, upgraded to Google Workspace Enterprise, and told their clinicians to "just use Gmail." Six months later, a therapist shared a patient's treatment notes in a Google Doc — with link sharing set to "anyone with the link." That document sat exposed on the open internet for eleven weeks before anyone noticed.

HIPAA compliance G Suite — now called Google Workspace — is one of the most misunderstood areas I encounter in healthcare IT consulting. Organizations assume that signing a BAA flips some magic compliance switch. It doesn't. Google gives you the tools to comply. You have to actually configure them, enforce them, and train your people.

This post walks you through every setting, policy, and training requirement you need to make Google Workspace genuinely HIPAA-compliant for your covered entity.

The BAA Is the Starting Line, Not the Finish

Google will sign a Business Associate Agreement with organizations using eligible Google Workspace editions — Enterprise, Business Plus, Education Plus, and a few others. You can review Google's own guidance on their HIPAA compliance and Google Workspace page. Without that BAA in place, you cannot store, process, or transmit PHI through any Google service. Period.

But here's what catches people: the BAA only covers specific services. As of 2026, covered services include Gmail, Google Calendar, Google Drive (including Docs, Sheets, and Slides), Google Chat, Google Meet, Google Keep, and a handful of others explicitly listed in the agreement. Services like Google Maps, YouTube, and Google Contacts are not covered.

I've seen organizations let staff paste patient addresses into Google Maps for home health visits. That's PHI flowing through a non-covered service. No BAA protection. No excuse the OCR would accept.

Nine Admin Console Settings You Cannot Skip

Signing the BAA generates no automatic configuration changes. Every setting below is your responsibility as the covered entity's administrator.

1. Disable Non-Covered Services

Go into your Admin Console and turn off every Google service not listed in the BAA for your organization. If your staff can access it, they will use it. The only safe approach is to remove the option entirely.

2. Enforce Two-Factor Authentication

The HIPAA Security Rule requires access controls under 45 CFR §164.312. Enable 2-Step Verification for all users and enforce it — don't just "encourage" it. Hardware security keys are the strongest option, but app-based authenticators are a defensible minimum.

3. Lock Down External Sharing in Google Drive

This is the single most dangerous default in Google Workspace. By default, users can share files with anyone outside your organization. In the Admin Console under Apps > Google Workspace > Drive and Docs, restrict sharing to internal users only — or at most, to whitelisted external domains where you have a BAA.

4. Enable Data Loss Prevention (DLP) Rules

Google Workspace Enterprise editions support DLP scanning for Gmail and Drive. Configure rules that detect common PHI patterns — Social Security numbers, medical record numbers, ICD codes — and block or quarantine messages containing them before they leave your organization.

5. Configure Vault for Retention and eDiscovery

HIPAA requires you to retain certain records and produce them if HHS investigates. Google Vault lets you set retention policies and place legal holds. Set retention periods that align with your state's medical record laws and your organization's retention schedule.

6. Restrict Mobile Device Access

Under Device Management in the Admin Console, enforce mobile management policies. Require screen locks, enable remote wipe, and block access from devices that don't meet your security baseline. A clinician's lost phone with a cached inbox full of patient emails is a reportable breach.

7. Disable POP/IMAP Access

If users can pull Gmail into unsecured third-party email clients via POP or IMAP, your encryption and access controls mean nothing. Disable these protocols unless you have a documented, risk-assessed reason to keep them on.

8. Set Session Length Controls

Automatic session expiration reduces the risk of unauthorized access from unattended devices. Configure web session duration to a maximum that your clinicians can live with — eight to twelve hours is common — and enforce re-authentication.

9. Turn on Admin Audit Logs and Alerts

You need to know when someone changes a sharing setting, exports a user's mailbox, or disables 2FA. Configure alerts for critical admin actions and review audit logs at least monthly. The Security Rule's audit control requirement under §164.312(b) isn't optional.

What Exactly Does "HIPAA Compliant G Suite" Mean?

Let me answer this directly, because it's the question I see most often: Google Workspace is not HIPAA compliant out of the box. It is HIPAA-eligible. Compliance is a shared responsibility. Google handles encryption in transit and at rest, physical security of data centers, and infrastructure-level safeguards. You handle access controls, sharing policies, workforce training, and your own administrative and organizational policies.

If you skip any of those responsibilities, you own the violation — not Google.

The Training Gap That Gets Organizations Fined

Technical controls are half the equation. The other half is your people. The OCR has made this painfully clear through enforcement.

In 2019, the University of Rochester Medical Center paid $3 million to settle potential HIPAA violations related in part to a failure to implement adequate security measures — including a failure to manage devices and enforce policies. The HHS settlement page lays out the details.

Your staff needs to understand why they can't paste a patient's lab results into a Google Doc and share it with "anyone with the link." They need to know why forwarding a referral email to a personal Gmail account is a potential breach. Policy documents sitting in a shared drive that nobody reads won't protect you.

If your workforce is new to HIPAA or you're onboarding staff who'll be using Google Workspace daily, our HIPAA Introduction Training for 2026 covers the foundational rules every employee must understand before they touch PHI in any system.

Remote Staff Multiply the Risk

Remote workers access Google Workspace from home networks, shared family computers, and coffee shop Wi-Fi. Every one of those environments introduces risk that your on-site firewall can't mitigate. I've seen practices where remote billing staff had Google Drive synced to a personal laptop shared with a teenager.

If you have remote team members — and most healthcare organizations do in 2026 — enroll them in targeted education like our HIPAA Training for Remote Healthcare Workers. It addresses the specific threats remote environments create.

AI Features in Google Workspace: The New Frontier

Google has aggressively integrated AI capabilities across Workspace — Gemini in Gmail, Docs, and Sheets. These features can summarize emails, draft responses, and analyze spreadsheet data. The question every covered entity should be asking: does PHI fed into these AI features stay within the BAA-covered boundary?

As of 2026, Google states that Workspace AI features for enterprise customers with a BAA process data within the same infrastructure. But you need to verify this for your specific edition and configuration. And you need policies that tell staff exactly what they can and cannot use AI tools for when PHI is involved.

We built an entire course around this challenge: Using AI Tools & PHI. It covers not just Google's AI features but the broader landscape of AI in clinical and administrative workflows.

Your HIPAA Compliance G Suite Checklist

Here's a quick-reference list you can hand to your IT admin or compliance officer today:

  • Sign the Google Workspace BAA through the Admin Console
  • Verify your edition is BAA-eligible
  • Disable all non-covered Google services
  • Enforce 2-Step Verification for every user
  • Restrict external sharing in Drive to whitelisted domains or internal only
  • Configure DLP rules for PHI patterns in Gmail and Drive
  • Set up Google Vault retention policies
  • Enforce mobile device management with remote wipe capability
  • Disable POP and IMAP unless risk-assessed and documented
  • Set session length controls and re-authentication policies
  • Enable audit logs and configure alerts for admin actions
  • Train every workforce member — especially remote staff
  • Create written policies for AI feature usage with PHI
  • Conduct an annual risk assessment that specifically addresses your Google Workspace configuration

The Risk Assessment Ties It All Together

Every configuration decision above should flow from a documented risk assessment. The HIPAA Security Rule requires it. The OCR asks for it in every investigation. And it's the one document that proves you didn't just guess at your security posture — you analyzed it.

Your risk assessment should specifically address Google Workspace as a system that stores, processes, and transmits ePHI. Map each safeguard to the threats it mitigates. Document what you configured and why. When the OCR comes knocking — and enforcement activity has only increased — that document is your first line of defense.

HIPAA compliance G Suite isn't a product you can buy. It's a set of decisions you make, enforce, and train your people on — every single day. Google gives you a powerful, flexible platform. What you do with it determines whether your patients' data stays protected or ends up on the open internet for eleven weeks.

Start with the BAA. Lock down the settings. Train your workforce. Then prove you did all three.