Is Google Drive HIPAA Compliant in 2020? (2024)

Yes, you can use Google Drive in a HIPAA compliant environment, but only if you’re careful! That’s the quick answer. Read on to learn more!

Every day we hear from practitioners who want to use Google Workspace in their medical practice. Google Workspace is easy-to-use, affordable, and can be HIPAA compliant. Most people want Google Workspace for Gmail, but having access to Google Drive and Docs really makes the subscription cost worthwhile.

Feature Download: FREE checklist about Gmail and Google Workspace HIPAA Compliance (Download Now)

In this article you will learn:

  • What is Google Workspace?
  • Is Google Workspace HIPAA compliant?
  • How to sign a BAA with Google
  • What is Google Drive?
  • Is using Google Docs HIPAA compliant?
  • What’s the difference between Google Drive and Dropbox?
  • How do I make Google Drive HIPAA compliant?

Contents hide

What is Google Workspace and is it HIPAA Compliant?

Google’s Business Associate Agreement (BAA)

BAA does not mean HIPAA compliance

Is using Google Docs HIPAA Compliant?

Is Google Drive and Docs safe for confidential information or medical records?

Can I use Google Drive on my Smartphone or Tablet?

Google Drive vs. Dropbox

How to make Google Drive HIPAA compliant

Talk to us!

What is Google Workspace and is it HIPAA Compliant?

Google Workspace is a collection of collaboration and productivity tools. You’re probably using some of these tools already: Gmail, Docs, Drive, Calendar, Meet and more.

Is Google Drive HIPAA Compliant in 2020? (1)

Google Workspace is a paid subscription service. If your email address ends with @gmail.com you are using Google’s free Gmail and apps, not Google Workspace.

What’s the difference between Google Workspace and free Gmail? Basically, the difference is having @gmail.com or @yourcompany.com at the end of your email address. You also get more cloud storage, phone/email support, additional security options and administrative controls with Google Workspace,.

You can use Google Workspace in a HIPAA compliant manner, but it is not HIPAA compliant right out of the box. Free Gmail/Google Apps cannot be HIPAA compliant since Google will not provide a BAA for free Gmail accounts. We have a bunch of articles about making Google Workspace HIPAA compliant:

  • HIPAA Compliant Gmail (17 Step How-To Guide for 2023)
  • Is Google Workspace HIPAA Compliant?
  • 5 Ways to Make Google Workspace HIPAA Compliant
  • Is Gmail Encryption HIPAA Compliant?

Google’s Business Associate Agreement (BAA)

Google will provide a BAA for Google Workspace account holders. Need help finding it? Check out this help article: https://support.google.com/a/answer/3407074?hl=en

Google’s BAA does not cover every service in Google Workspace. Protected Health Information (PHI) can be used in the following Google Workspace Apps: Gmail, Calendar, Drive (including Docs, Sheets, Slides, and Forms), Google Hangouts (chat messaging feature only), Hangouts Chat, Hangouts Meet, Keep, Google Cloud Search, Google Voice (managed users only), Sites, Google Groups, Jamboard, Cloud Identity Management, Tasks, and Vault.

Google Drive is included in that list! If you configure file sharing properly in Google Drive, it’s a great choice for HIPAA compliant cloud storage.

Is Google Drive HIPAA Compliant in 2020? (2)

BAA does not mean HIPAA compliance

But here’s a disclaimer that many private practice “influencers” miss: signing a BAA with Google does not make your Google Workspace/Google Drive HIPAA compliant.

Seriously – Google CLEARLY says

“Customers are responsible for … ensuring that they use Google services in compliance with HIPAA.”

“PHI is allowed only in a subset of Google services.”

“These Google covered services … must be configured by IT administrators to help ensure that PHI is properly protected."

So yes, Google Workspace CAN be HIPAA compliant, but it’s not compliant right out of the box.

You need to make sure your account is secure.

What is Google Drive?

Google Drive is a secure, easy-to-use cloud storage solution. It’s very easy to create and share files and folders. This is great from a collaboration standpoint, but not great from a HIPAA-standpoint. This is why it’s imperative that you set up Google Drive correctly to avoid sharing documents with the wrong recipients!

Google Drive is kind of like a cross between Dropbox (where you can back up your files to the cloud) and Microsoft Office (for creating and editing documents). It’s all in your web browser, and is really easy to learn and use.

You can upload any type of file to Drive and convert files to a Google document format: Docs (like Microsoft Word), Sheets (like Microsoft Excel) or Slides (like Microsoft PowerPoint).

How much cloud storage do you get? There are three levels of Google Workspace, and each has a different price/user and amounts of Drive cloud storage:

  • Basic $6/user/month, 30 GB cloud storage per user
  • Business $12/user/month, 2 TB cloud storage per user
  • Business Plus $18/user/month, 5 TB cloud storage per user
  • Enterprise contact Google for pricing, unlimited cloud storage

12/31/2020: here's a link to their pricing page: https://workspace.google.com/pricing.html

Is using Google Docs HIPAA Compliant?

Google Docs are intuitive collaboration and documentation tools. They are web-based and very similar to Microsoft Word, Excel and PowerPoint. You can convert many types of files into Google Docs formats:

  • Docs (word processing similar to Microsoft Word)
  • Sheets (spreadsheets similar to Microsoft Excel)
  • Slides (presentations similar to Microsoft PowerPoint)

And the answer is YES! Google Docs (with a paid Google Workspace subscription, signed BAA and appropriately configured settings) can be HIPAA compliant. They clearly state this in Google’s HIPAA Implementation Guide (linked at the end of this article).

Is Google Drive HIPAA Compliant in 2020? (3)

Is Google Drive and Docs safe for confidential information or medical records?

Google’s BAA covers Google Drive and Docs, so these services are appropriate for storing PHI. Google’s HIPAA Implementation Guide recommends the following:

  • Avoid putting PHI in titles of files, folders or team drives
  • Set appropriate file sharing permissions
  • Review file sharing reports, especially to see which files are shared with external users
  • Consider disabling third-party applications

Yes, Google Drive and Docs is safe for storing medical records or confidential information, but only if it’s configured correctly. Files in Google Drive and all file metadata (titles and comments) are encrypted. Learn more about Google’s Security focus here: https://support.google.com/googlecloud/answer/6056693?hl=en&visit_id=637275245913296513-3573186912&rd=1

Can I use Google Drive on my Smartphone or Tablet?

Yes! Google Drive and the rest of Google Workspace is very mobile friendly. You can use Google Drive in a HIPAA compliant manner if you use the Google Drive app on your smartphone or tablet AND you have Google Workspace configured properly.

Google Workspace subscriptions include a Mobile Device Management system which allows you to require screenlocks or passwords in addition to removing confidential data from devices as needed.

Google Drive vs. Dropbox

Google Workspace is perfect for smaller medical practices that need HIPAA compliant email, cloud storage, telehealth and more - but what if you already have a solution for email and telehealth and you just need cloud storage? You might want to look at other options, just to see other offerings.

We have an article that quickly reviews 11 HIPAA compliant cloud storage options: https://adeliarisk.com/hipaa-compliant-cloud-storage/

One of the most popular cloud storage solutions is Dropbox. Here’s a quick comparison between Google Drive (as a part of Google Workspace, not the free version) and Dropbox:

Google DriveDropbox
Sign BAA?YesYes
Cost- $6/user/month Basic- $12/user/month Business- $18/user/month Business Plus- $17/month for 1 user- $12.50/user/month for 3 users
Storage30 GB - 5 TB/user depending on plan3-5 TB depending on plan
Two-step verificationYesYes
Encryption at restYesYes
Encryption in transitYesYes
Remote wipe*YesYes

*in case a device is lost or stolen, it’s important to be able to remove files containing PHI

If you’re considering Google Drive, Dropbox or any other cloud storage solution, it’s important to review the actual features that you intend to use. We didn’t look at every feature of these solutions in our comparison, so be sure to check their websites for more information.

How to make Google Drive HIPAA compliant

Most practitioners who want to use Google Drive in their practice want to use the entire Google Workspace service. You need to set up your Google Workspace account properly. Google strives to make services easy to use, collaborate and share — which is great, but HIPAA requires you to limit sharing. You only want to share things with intended recipients!

Feature Download: FREE checklist about Gmail and Google Workspace HIPAA Compliance (Download Now)

Talk to us!

Have questions or feedback? Please share them in the comments below.

Like this article? Share it!

Is Google Drive HIPAA Compliant in 2020? (2024)

FAQs

Is Google Drive HIPAA Compliant in 2020? ›

You can use Google Workspace in a HIPAA compliant manner, but it is not HIPAA compliant right out of the box. Free Gmail/Google Apps cannot be HIPAA compliant since Google will not provide a BAA for free Gmail accounts.

How do I make a Google Drive folder HIPAA compliant? ›

For Google Drive to be HIPAA Compliant the following must be implemented:
  1. Secure a Google BAA.
  2. Implement access controls.
  3. Enable 2-factor authentication.
  4. Turn off link sharing and file syncing.
  5. Sharing files outside the domain must be restricted.
  6. Use unique passwords.
  7. Set document visibility to private.
Sep 27, 2019

Does Google have HIPAA compliance? ›

Google ensures that the Google products covered under the BAA meet the requirements under HIPAA and align with our ISO/IEC 27001, 27017, and 27018 certifications and SOC 2 report.

Is Google Drive secure for medical records? ›

In order for Google Docs to be HIPAA compliant, stored data must be encrypted. Data must also be encrypted during uploading and downloading. We can confirm that Google uses 128-bit or stronger Advanced Encryption Standard (AES) to protect data in transit to the platform, and between and in its data centers.

Can PHI be stored in Google Drive? ›

Yes you are able to store records and other PHI or PII on google drive on your personal account. As there are no rules to allow preventing uploading files onto Google Drive. On a workplace account there may be restrictions set by the company to restrict putting up these types of files.

Why is Google Drive not HIPAA compliant? ›

Yes and no. It comes down to how you store and access files, having a signed BAA, and if your Google Drive has any security holes (that you may not even know about!). The good news is Google Drive can be HIPAA compliant if it's configured and used correctly—and this guide is going to walk you through how to do it.

Is Google Drive HIPAA and Ferpa compliant? ›

Google Drive, which is part of G Suite, has all of the required components that a HIPAA-compliant service needs. The platform is protected by TLS (Transport Layer Security) encryption, which does protect patient PHI by putting secure walls around your server.

Which Google account is HIPAA compliant? ›

Gmail is HIPAA compliant, and can be used to receive, store, or send Protected Health Information (PHI) when Google's email service is used as part of an Enterprise Workspace Plan supported by a Business Associate Addendum to the Workspace Terms of Service.

Which version of Google Workspace is HIPAA compliant? ›

Yes and no. Some Google Workspace products are HIPAA compliant while others are not. While the full Google Workspace product line meets HIPAA security standards, Google's BAA only covers certain products. Also, only users with a paid subscription have access to Google's BAA.

How do I know if my Google account is HIPAA compliant? ›

If you're using a regular ol' @gmail.com email, then not so much. But switch to the paid version of Gmail-aka Google Workspace's Gmail–and you will have all the necessary features for HIPAA compliance. You can share patient details now with your colleagues over Gmail but make sure you're using the right version first.

Is OneDrive HIPAA compliant? ›

OneDrive is HIPAA compliant and can be used to store, sync, and share files containing Protected Health Information provided organizations subscribe to a Microsoft 365 or Office 365 plan that supports HIPAA compliance and the file storage system is configured to comply with the Security Rule's safeguards.

Is Google Drive secure for legal documents? ›

These security features include encryption, single sign-on (SSO), user permissions, and more. Encryption is one of the most important features for lawyers. Fortunately, Google Drive utilizes 256-bit SSL/TLS encryption for files in transit and 128-bit AES keys for files at rest.

Is Gmail HIPAA compliant? ›

Gmail can be used as part of a HIPAA-compliant organization. However, only the paid version (Google Workspace Gmail, not @gmail.com email addresses) provides the features you need for HIPAA compliant email. You also probably will need to add some extra services to be able to send and receive email safely.

What should you not store in Google Drive? ›

Types of Files You Should NOT Store On Google Drive

Family IDs. Estate planning documents like wills or beneficiary designations. Life insurance documents. Account passwords.

Are all Google Drive files private? ›

Your files are private unless you choose to share them. You can share files with: One person or a few people using a link. Everyone by making the files public.

Is iCloud HIPAA compliant? ›

To be HIPAA compliant, cloud services not only need to offer a robust defense against unwarranted access but also to ensure they have the proper agreements and controls to handle healthcare information. iCloud, unfortunately, does not meet these criteria, making it non-compliant with HIPAA standards.

How do I create a safe folder in Google Drive? ›

Protect your files with Safe folder
  1. On your Android device, open the Files by Google app .
  2. Scroll to "Collections."
  3. Tap Safe folder.
  4. Tap either PIN or Pattern. If PIN is selected: Enter your PIN. Tap Next. In the "Confirm PIN" screen, re-enter your PIN. Tap Next. In the "Remember your PIN" screen, tap Got it.

How do I make a Google folder confidential? ›

Find the file or folder in Google Drive, Google Docs, Google Sheets, or Google Slides. Open or select the file or folder. Copy link . Select Restricted.

How do I make a folder accessible in Google Drive? ›

If you allow access to anyone with the link, anyone can open the folder.
  1. On your Android device, open the Google Driveapp.
  2. Next to the folder's name, tap More .
  3. Tap Manage access.
  4. Under "General access," tap Change.
  5. Choose who can access the file.

How do I make a Google Drive folder accessible to everyone? ›

If you allow access to anyone with the link, your folder won't restrict who can access it.
  1. On your computer, go to Google Drive.
  2. Click the folder you want to share.
  3. Click Share .
  4. Under "General access," click the Down arrow .
  5. Choose who can access the folder.

Top Articles
Latest Posts
Article information

Author: Neely Ledner

Last Updated:

Views: 5899

Rating: 4.1 / 5 (42 voted)

Reviews: 89% of readers found this page helpful

Author information

Name: Neely Ledner

Birthday: 1998-06-09

Address: 443 Barrows Terrace, New Jodyberg, CO 57462-5329

Phone: +2433516856029

Job: Central Legal Facilitator

Hobby: Backpacking, Jogging, Magic, Driving, Macrame, Embroidery, Foraging

Introduction: My name is Neely Ledner, I am a bright, determined, beautiful, adventurous, adventurous, spotless, calm person who loves writing and wants to share my knowledge and understanding with you.