More on the topic...
Generating detailed summary...
Failed to generate summary. Please try again.
Google’s guide lays out how health care organizations can use Workspace and Cloud Identity under HIPAA. If you handle Protected Health Information (PHI), you must sign a Business Associate Addendum (BAA) with Google. Once that’s in place, IT admins configure only the approved services—what Google calls “Included Functionality”—to process PHI. Those services include Gmail, Calendar, Chat, Drive (Docs, Sheets, Slides, Forms, Vids), Cloud Search, Groups, Keep, Meet, Sites, Tasks, Vault (if you subscribe), Voice (managed users only), and the Gemini app (but not Gemini in Chrome).
Anything outside that list—Contacts or any non-core Google service like YouTube or Photos—cannot store PHI. Administrators must set up organizational units to limit which user groups can access each service. They also bear full responsibility for HIPAA-related tasks: deciding if they’re a Business Associate, securing the right agreements, and handling user requests for access, amendments, and accounting as required by law. Google handles the platform security, but customers control their PHI workflows and configurations.
Beyond service selection, the guide points to best practices. It suggests monitoring account activity, auditing third-party integrations, and reviewing sharing settings in Docs, Drive, Chat, Meet, and other apps. You’ll find step-by-step advice on turning services on or off per department, locking down search history, and separating PHI users from non-PHI users within a single domain. Detailed tables list each Workspace core service and whether it’s HIPAA-compliant, so you can check boxes instead of guessing.
Questions about this article
No questions yet.