HIPAA Compliant Email

Is Gmail HIPAA Compliant? The Honest Answer, And What To Do Next

Is Gmail HIPAA compliant? Free consumer Gmail is not, and it cannot be made compliant. Paid Google Workspace can be part of a HIPAA compliant email program, but only after you execute Google's Business Associate Agreement and configure the tenant correctly. The BAA is the starting line, not the finish. Petronella Technology Group, Inc. assesses the entire mail environment, closes the gaps, and documents the result so it survives an audit.

Compliance Consultancy, Not An Email Vendor | HIPAA Security Rule Specialists | 24+ Years Healthcare IT
Direct Answer

Is Gmail HIPAA Compliant? Yes And No

The question "is gmail hipaa compliant" has two answers because there are two very different products wearing the same name. A free Gmail account ending in gmail.com is a consumer service. Google does not offer a Business Associate Agreement for it. Without a BAA, a covered entity or business associate cannot lawfully route protected health information through that account, and no setting you toggle inside the mailbox changes that. There is no configuration path, no add-on, and no encryption plugin that makes a consumer account into hipaa compliant gmail.

Paid Google Workspace is a different matter. Google publishes a HIPAA Implementation Guide for Google Workspace and offers a Business Associate Agreement that a customer administrator accepts inside the Admin console. Gmail is one of the services the agreement covers when the customer restricts protected health information to the services Google identifies as included. That combination makes gmail hipaa compliant capable. Capable is not the same as compliant.

The gap between capable and compliant is where the real work lives, and it is where most of the findings in our assessments come from. Under the HIPAA Security Rule at 45 CFR Part 164 Subpart C, the covered entity or business associate remains responsible for administrative, physical, and technical safeguards. Google's agreement covers Google's obligations as a business associate. It does not cover your access controls, your audit log review, your retention schedule, your mobile devices, your workforce training, or the intern who forwards a chart to a personal address on a Friday afternoon.

So the accurate one-sentence answer is this: Gmail can be part of a HIPAA compliant email deployment when it runs on Google Workspace under an executed BAA and the tenant is configured and governed to meet the Security Rule. Everything below explains what that configuration and governance actually looks like, in the order we work through it during a real engagement.


Foundations

What Makes Any Email System HIPAA Compliant

HIPAA never names a product. It names outcomes. Any hipaa compliant email program has to satisfy the same set of safeguards regardless of whether the underlying platform is Google Workspace, Microsoft 365, or something you host yourself.

Technical Safeguards The Rule Expects

  • Access control: unique user identification, automatic logoff, and a documented basis for who may open a mailbox containing protected health information
  • Audit controls: mechanisms that record and examine activity in systems that hold or transmit electronic protected health information
  • Integrity: protection against improper alteration or destruction of messages and attachments
  • Person or entity authentication: proof that the account holder is who the directory says they are, which in practice means enforced multi-factor authentication
  • Transmission security: addressable encryption for messages that travel outside your controlled network, plus a documented decision when you choose an equivalent alternative

Administrative Work That Cannot Be Bought

  • A current risk analysis that names email as a system, identifies the threats, and records the decisions you made about them
  • Written policies covering acceptable use, patient consent for unencrypted communication, and what staff may never place in a subject line
  • Workforce training that is delivered, dated, and provable, not a slideshow nobody opened
  • Business Associate Agreements with every vendor that touches the mail stream, including archiving, e-signature, fax gateways, and marketing platforms
  • An incident response procedure that treats a misdirected message as a potential breach and starts the clock on notification analysis

The Fork In The Road

Consumer Gmail Versus Google Workspace

Almost every practice we assess has at least one consumer account still moving clinical information. Understanding the split is the first correction.

A consumer Gmail account is provided to an individual under consumer terms. Google does not extend a Business Associate Agreement to those accounts, and Google states plainly in its HIPAA guidance that the agreement applies to Google Workspace and Cloud Identity customers. A solo practitioner using drjones@gmail.com to send a referral letter has no contractual protection, no administrative console, no audit export, no retention control, and no way to remotely remove data from a lost phone. That deployment cannot be brought into compliance because the controls the Security Rule expects simply do not exist in the product.

Google Workspace changes the picture in three concrete ways. First, you own a domain and an Admin console, which means you can enforce policy centrally instead of relying on each user to behave. Second, a designated administrator can review and accept Google's Business Associate Agreement, which establishes Google's obligations as a business associate for the covered services. Third, the higher Workspace editions expose the security surfaces that make an evidence trail possible: data loss prevention rules, hosted S/MIME, Google Vault for retention and legal hold, admin and login audit logs, context aware access, and mobile device management.

The practical consequence is that a personal account is a compliance dead end while a Workspace tenant is a starting point. Migrating from one to the other is not just changing an address. It involves domain verification, mail flow cutover, forwarding cleanup, retention decisions about the historical mailbox, and a documented determination about whether prior messages constitute a reportable exposure. We handle that sequence regularly and we do not skip the documentation step, because the migration itself is evidence an auditor will ask about.

One more distinction matters. Google Workspace comes in several editions, and the controls available to you differ by edition. Hosted S/MIME, data loss prevention for Gmail, and Vault retention are not present in every tier. Telling a client "sign the BAA and you are fine" without checking which edition they bought is how a practice ends up with an executed agreement and no technical ability to enforce anything. We check the edition before we design the control set, and we say clearly when the edition needs to change.


The Agreement

Is Gmail HIPAA Compliant Once You Sign The BAA?

No. The Business Associate Agreement is necessary and it is not sufficient. Here is exactly what it does and does not do.

A Business Associate Agreement is a contract required by the HIPAA Privacy and Security Rules whenever a vendor creates, receives, maintains, or transmits protected health information on behalf of a covered entity. Google's agreement for Google Workspace establishes Google as your business associate for the services it lists, commits Google to safeguards for the information it handles, and sets expectations for reporting security incidents. Executing it is a hard prerequisite. Any practice moving clinical information through Gmail without it has a finding, full stop. Our deeper explanation of these contracts lives on our HIPAA Business Associate Agreement page.

What the BAA does cover

  • Google's obligations as a business associate for the covered Google Workspace services, including Gmail, when you keep protected health information inside those services.
  • Google's commitment to apply safeguards to the information it processes on your behalf and to restrict use and disclosure to what the contract permits.
  • A defined channel for Google to report security incidents affecting the covered services.

What the BAA does not cover

  • Your configuration. If sharing is wide open, if external forwarding is unrestricted, or if multi-factor authentication is optional, the agreement does not repair any of it.
  • Services outside the covered list. Third party add-ons from the marketplace, personal Drive accounts, unmanaged Chrome extensions, and consumer messaging tools sit outside the agreement even when your staff opens them in the same browser window.
  • Your workforce. Training, sanctions, onboarding and offboarding are administrative safeguards that belong to you.
  • Your risk analysis and your documentation. An assessor will ask you to produce them, not Google.
  • The recipient side. Sending a message to a patient's personal inbox moves the information beyond your control, which is why consent and minimum necessary practice matter more than any encryption toggle.

We have reviewed environments where the administrator accepted the agreement years ago, nobody recorded who accepted it or when, and no one could produce it during a payer audit. The agreement exists in the Admin console, so retrieving it is straightforward, but the fact that nobody knew where to look is itself a governance finding. Part of what we deliver is a documentation set that answers those questions in one place.


The Real Work

Configuration That Remains After The BAA

This is the layer that single-product vendors tend to skip, because it is not a product. It is engineering and governance inside your tenant.

Encryption In Transit

Gmail uses opportunistic TLS with other mail servers, which means delivery can fall back to plaintext if the receiving server does not support TLS. For domains you exchange clinical information with, configure secure transport enforcement so that mail to those destinations either travels encrypted or does not go at all. Document the list, review it, and record what happens when a partner fails the requirement.

Hosted S/MIME And Message-Level Protection

Transport encryption protects the hop, not the message at rest on the far side. Hosted S/MIME signs and encrypts at the message level for recipients whose certificates you hold. Where S/MIME is impractical, a secure delivery portal that notifies the recipient and requires authentication is the workable alternative. Choosing between them is a risk decision that belongs in your documentation, not a default.

Data Loss Prevention Rules

DLP is where a tenant stops relying on staff memory. Detectors for medical record numbers, dates of birth, insurance identifiers, and common chart attachment types let you quarantine, warn, or force encrypted routing before a message leaves. Tuning matters. Rules that fire on everything get disabled within a month, so we start narrow, measure, and expand.

Retention, Vault, And Legal Hold

HIPAA requires six year retention for required documentation, and state medical record laws often impose their own periods. Google Vault gives you retention rules, holds, and defensible export. Without it, a departing employee's mailbox can be deleted along with evidence you are obligated to keep. Set the rule, test the export, and store the test result.

Admin And Login Audit Logs

Audit controls are a required implementation specification. Workspace produces admin, login, and Gmail log events, but producing them is not reviewing them. Route the logs to a place where someone actually looks, define what an alert looks like, and keep the record of review. The review record is the artifact that satisfies an assessor.

Mobile Devices And Endpoint Policy

Most clinical email is read on a phone. Enforce device screen lock, encryption, and remote wipe through endpoint management, and decide whether personal devices may sync mail at all. A lost unmanaged phone with a synced mailbox is a breach analysis you do not want to run without controls in place.

Access Control And Least Privilege

Super administrator accounts should be few, named, hardware-key protected, and never used for daily mail. Delegated mailbox access should be granted deliberately and reviewed on a schedule. Offboarding should suspend, transfer, and preserve in a defined order. We see stale accounts with live credentials in nearly every first assessment.

External Forwarding And Sharing

Automatic external forwarding is the single most common quiet leak. Disable it at the org level, allow exceptions by policy only, and alert when a new filter forwards outside the domain. Pair that with restrictions on unmanaged marketplace add-ons, which can read mail with permissions users grant without any review. See our HIPAA compliance practice for how these controls fit the wider program.


Procedure

How To Make Gmail HIPAA Compliant, Step By Step

This is the sequence we follow. The order matters, because each step produces a decision or an artifact the next step depends on.

1

Inventory Every Mailbox

List every account that has ever handled clinical information, including consumer accounts, shared front desk logins, scanner and fax relay addresses, and vendor portals that email results. You cannot protect a mail stream you have not found, and the inventory becomes an appendix to your risk analysis.

2

Retire Consumer Accounts

Move every clinical workflow off free Gmail onto a Workspace tenant on a domain you control. Record what was in the old account, decide on retention or destruction, and document whether prior use requires a breach risk assessment.

3

Confirm The Right Edition

Verify the Workspace edition actually provides DLP, hosted S/MIME, Vault, and endpoint management. If it does not, change the edition before designing controls you cannot enforce.

4

Execute The BAA

Have an authorized administrator review and accept Google's Business Associate Agreement in the Admin console, then export and file the record with the date and the accepting individual. Confirm your understanding of which services the agreement covers and restrict clinical data to those services.

5

Harden Authentication

Enforce multi-factor authentication for every user, require hardware keys for administrators, disable legacy protocols that bypass modern authentication, and set session and reauthentication policies that match clinical workflow.

6

Lock Down Mail Flow

Disable automatic external forwarding, enforce TLS to named partner domains, publish SPF, DKIM, and DMARC records, and restrict who may create routing rules. Test each control by attempting the thing you just prohibited.

7

Deploy Encryption For Outbound PHI

Configure hosted S/MIME where certificates exist and a secure portal path where they do not. Define which message categories must use which path, and make the safe path the easy path so staff do not route around it.

8

Turn On DLP And Tune It

Start with high confidence detectors and warn-only actions, review two weeks of hits, then move the accurate rules to block or force-encrypt. Keep a change log so you can show an assessor how the rule set evolved.

9

Set Retention And Test Export

Apply Vault retention aligned to HIPAA and your state's medical record law, configure holds for known litigation, and run a test export so you know the process works before you need it under pressure.

10

Manage Devices

Enroll company devices, apply policy to personal devices that sync mail or block them entirely, and verify remote wipe on a live handset. Write down which choice you made and why.

11

Wire Up Log Review

Export admin, login, and Gmail log events to a monitored destination, define alert conditions, assign an owner, and keep dated evidence that review happened. Audit controls without review is a control on paper only.

12

Update The Risk Analysis

Fold the new email architecture into your HIPAA risk assessment, record the addressable specifications you implemented and the ones you satisfied another way, and set a review date.

13

Train The Workforce

Deliver role-specific HIPAA training that covers subject line discipline, verifying recipients, what patient consent does and does not permit, and how to report a misdirected message within minutes rather than days.

14

Rehearse The Incident Path

Walk through a misdirected message end to end: containment, recall attempt, breach risk assessment factors, documentation, and notification decision. A rehearsed path turns a panic into a procedure.

15

Re-Verify On A Schedule

Tenants drift. Administrators add exceptions, vendors change defaults, and staff install add-ons. Re-verify the control set at a defined interval and after any material change to the mail stack.


The Alternative Path

Microsoft 365 As The Other Route To HIPAA Compliant Email

Plenty of practices are already standardized on Outlook. The compliance logic is identical even though the console is different.

Microsoft offers a HIPAA Business Associate Agreement for its enterprise cloud services, and Exchange Online can carry protected health information under the same two-part logic that applies to Google: contract first, configuration second. If your organization already runs Microsoft 365 for documents, identity, and telephony, moving mail to Google purely for compliance reasons is usually the wrong trade. The control surfaces you need exist in both ecosystems.

The equivalents map cleanly. Transport rules and connectors replace Gmail routing and secure transport enforcement. Microsoft Purview data loss prevention replaces Gmail DLP. Message encryption and sensitivity labels replace hosted S/MIME for most practical purposes. Retention policies and eDiscovery replace Vault. Entra ID conditional access replaces context aware access. Intune replaces Workspace endpoint management. The unified audit log replaces admin and login log events.

The decision between the two platforms should turn on where your identity lives, what your clinical applications integrate with, what your staff already know, and what licensing you already pay for. It should not turn on a vendor claim that one platform is inherently the HIPAA compliant email choice. Neither is compliant out of the box. Both can be made compliant with disciplined configuration and documentation. We assess whichever one you have, and we tell you honestly when switching would cost more than it returns.

Mixed environments deserve special attention. We frequently find a Microsoft tenant for staff, a Google tenant left over from a merged practice, and a third party scheduling tool emailing reminders from its own domain. Three mail paths means three sets of controls, three BAAs, and three places a message can leak. Consolidation is often the highest value remediation we recommend, and it usually pays for itself in license reduction alone.


Field Findings

Common Email Violations We Find In Real Assessments

These recur across practice sizes and specialties. None of them are exotic. All of them are avoidable.

  • Automatic forwarding to a personal inbox. A provider sets a forward so they can read mail on a phone, then forgets. Clinical information flows to an account with no BAA, indefinitely, invisibly.
  • Protected health information in subject lines. Subject lines appear in notifications, previews, and logs that are frequently outside the encrypted body. A patient name plus a condition in a subject line is a disclosure.
  • Shared front desk mailbox with a shared password. This defeats unique user identification and makes audit logs useless, because no entry can be attributed to a person.
  • No BAA with a downstream vendor. The mail platform agreement is executed, but the transcription service, the appointment reminder tool, or the fax gateway that receives the same messages has no agreement at all.
  • Departed staff with active sessions. Offboarding suspends the account in the HR system but not in the directory, or suspends the directory account while an application-specific password keeps working.
  • Multi-factor authentication as an option. Enrollment is encouraged and not enforced, so the accounts with the widest access are frequently the ones without it.
  • Marketplace add-ons with mailbox read scope. A staff member installs a productivity tool that requests full mail access. The tool is not a business associate, and nobody reviewed the permission grant.
  • Audit logs nobody reads. Logging is enabled, retention is fine, and no human has ever opened it. An assessor asks for evidence of review and there is none.
  • Unencrypted attachments to patients. Staff send chart summaries as plain attachments because the secure path takes six clicks. Usability failures become compliance failures.
  • Retention set to delete. A cleanup policy purges mail older than a year, quietly destroying records the organization is required to retain.
  • No documented consent standard. The practice emails patients at their request but has no record of what was explained about the risk of unencrypted delivery and no consistent way to capture that agreement.
  • A risk analysis that never mentions email. The document exists, it was purchased as a template, and it describes a network that does not resemble the one in the building.

The pattern behind all of these is the same. Each one sits in the space between the vendor's responsibility and the customer's responsibility. A product vendor sells you the platform. Nobody sells you the discipline. That is the gap a compliance consultancy exists to close.


Channel Choice

When Email Is The Wrong Channel Entirely

Making Gmail compliant is worth doing. It is not worth doing for traffic that never belonged in email.

Email is asynchronous, hard to recall, easy to misaddress, and it lands in inboxes you do not control. For a large share of routine patient communication there is a better channel. Appointment reminders, medication adherence nudges, intake links, and short clinical check-ins usually belong in secure messaging or a patient portal, where identity is verified, the message stays inside a controlled system, and the audit trail is native.

Two-way conversational traffic in particular is a poor fit for email and a natural fit for a compliant messaging platform. If your staff are already texting patients from personal phones, that is an urgent finding regardless of how well the mail tenant is configured. Our HIPAA compliant texting page covers what a compliant messaging deployment requires and how it differs from consumer messaging apps.

Portals earn their place for anything document-heavy or long-lived: results, care plans, billing statements, and forms. The patient authenticates, the document never traverses an uncontrolled inbox, and the access record is automatic. The tradeoff is adoption. Portals that are hard to log into push patients back toward asking staff to "just email it," which recreates the risk you were trying to remove. Channel strategy is therefore a usability problem as much as a security one, and we design it that way.

The right answer for most practices is a deliberate split. Email carries administrative and provider-to-provider traffic under enforced encryption. Secure messaging carries short patient conversations. The portal carries documents. Each channel has a written rule, staff know which is which, and the risk analysis reflects the split. That design decision does more to reduce exposure than any single technical control.


How We Work

How Petronella Technology Group Assesses And Remediates

We are a compliance consultancy. We do not sell you a mailbox and call it compliance. We assess the environment you have, fix what is broken, and leave you with evidence.

Assessment Against The Rule, Not A Checklist

We map your mail environment to the administrative, physical, and technical safeguards in 45 CFR Part 164 Subpart C, then record which implementation specifications are required, which are addressable, and what you decided for each. The output is a findings register with severity, owner, and target date, not a color-coded spreadsheet with no path forward.

Whole Environment, Not One Product

Email touches identity, endpoints, backup, vendors, and clinical applications. We look at all of it, because a hardened mail tenant next to an unmanaged laptop is not a compliant organization. That whole-environment view is what separates a consultancy from a single-product vendor.

Remediation We Actually Perform

We configure the tenant with you or for you: authentication, routing, encryption, DLP, retention, endpoint policy, and log review. Each change is tested by attempting the behavior it prohibits, and each test result is captured as evidence.

Documentation That Survives Scrutiny

Policies, procedures, the risk analysis update, the BAA register, the training record, and the review log. An assessor rarely disputes a well-documented decision. They dispute the absence of one. See our full HIPAA compliance practice for the complete documentation set.

Training Your Staff Will Remember

Generic annual training does not change behavior at the front desk. Our HIPAA training is role-specific and built around the mistakes that actually cause breaches, with dated completion records you can produce on request.

Vendor And BAA Governance

We build the register of everyone touching your mail stream and chase the agreements that are missing. Details on the contract itself are on our HIPAA Business Associate Agreement page.


Who We Help

Organizations That Need HIPAA Compliant Email

If your organization creates, receives, maintains, or transmits protected health information by email, the Security Rule applies to you.

Medical Practices Dental Offices Behavioral Health Hospitals And Health Systems Home Health Agencies Physical Therapy Clinics Pharmacies Medical Billing Companies Telehealth Providers Urgent Care Centers Medical Device Vendors Healthcare IT Business Associates

FAQ

HIPAA Compliant Email Questions We Get Every Week

Direct answers to the questions practices ask before, during, and after a mail environment assessment.

Is Gmail HIPAA compliant?

Not by itself. Free consumer Gmail is not covered by a Business Associate Agreement and cannot be made HIPAA compliant. Paid Google Workspace can support HIPAA compliant email once an administrator executes Google's Business Associate Agreement and the tenant is configured for access control, audit logging, encryption in transit, retention, and device management. The platform makes compliance possible; your configuration and documentation make it real.

Can a free Gmail account ever be made HIPAA compliant?

No. Google does not offer a Business Associate Agreement for consumer accounts, and those accounts lack the administrative console, audit export, retention control, and device management the HIPAA Security Rule expects. Any encryption add-on you bolt on leaves the contractual gap and the governance gap untouched. The correct remediation is migrating to a Google Workspace tenant on a domain you control.

How do I make Gmail HIPAA compliant for my practice?

Move every clinical workflow to Google Workspace, confirm your edition includes data loss prevention, hosted S/MIME, Vault, and endpoint management, execute Google's Business Associate Agreement and file the record, enforce multi-factor authentication, disable automatic external forwarding, enforce TLS to partner domains, deploy message-level encryption, tune DLP rules, set retention, manage devices, review audit logs on a schedule, update your risk analysis, and train staff. Each step produces an artifact you will need if you are ever assessed.

Does signing the Google BAA make my Gmail deployment compliant?

No. The Business Associate Agreement defines Google's obligations for the covered services. It does not configure your tenant, control your workforce, produce your risk analysis, or govern the third party tools your staff install. Under 45 CFR Part 164 Subpart C the covered entity or business associate remains responsible for administrative, physical, and technical safeguards. Signing is step one of roughly fifteen.

What is HIPAA compliant email, exactly?

HIPAA compliant email is a mail deployment where the vendor is under a Business Associate Agreement and the customer has implemented the Security Rule safeguards: unique user identification, automatic logoff, audit controls with actual review, integrity protection, authentication, and transmission security. It also requires the administrative layer: policies, workforce training, a current risk analysis, vendor governance, and an incident response path. No product is compliant on its own.

Do I have to encrypt every email that contains patient information?

Encryption is an addressable implementation specification, which means you must implement it or document why an equivalent alternative measure is reasonable and appropriate for your environment. In practice, for anything leaving your controlled network, encryption is the defensible choice, and "addressable" is not a synonym for optional. Where a patient requests unencrypted communication, capture the consent and record what risk was explained.

Can I email a patient at their personal Gmail address?

You can, with care. Patients have a right to receive communications in the manner they request, including unencrypted email, provided they have been warned of the risk and their choice is documented. Your obligation is to secure the message while it is under your control and to apply the minimum necessary standard to what you send. Their personal inbox is outside your control and outside any agreement you hold.

Is Microsoft 365 a better choice than Google Workspace for HIPAA?

Neither platform is inherently better for HIPAA. Both offer a Business Associate Agreement for their enterprise services and both provide the control surfaces the Security Rule expects: data loss prevention, message encryption, retention and legal hold, conditional access, endpoint management, and audit logging. Choose based on where your identity, clinical applications, and existing licensing already live, then configure whichever one you pick with the same discipline.

What happens if we send protected health information from a non-compliant mailbox?

Treat it as a potential breach. Contain it, determine what was disclosed and to whom, and run the breach risk assessment factors to decide whether notification is required. Document the analysis whether or not you notify, because the documentation is what demonstrates you evaluated the incident rather than ignored it. Then fix the control that allowed it, which is usually forwarding, a shared mailbox, or a training gap.

How often should we re-check our email configuration?

Review the control set at least annually and after any material change: a platform migration, a merger, a new clinical application, a new vendor in the mail path, or an administrator turnover. Tenants drift because administrators grant exceptions and vendors change defaults. Re-verification is cheaper than a breach analysis, and the review record itself is evidence of a functioning program.

What does a HIPAA email risk assessment from your team include?

We inventory every mailbox and mail path, verify BAA coverage for every vendor in that path, review tenant configuration against the Security Rule safeguards, test the controls by attempting what they prohibit, and deliver a findings register with severity, owner, and remediation sequence. The assessment is free and typically starts with one call. Scope and cost for remediation depend on seat count and your existing mail stack, so we quote after we look.

Should routine patient messaging move off email entirely?

Often, yes. Short two-way conversations belong in secure messaging, and documents belong in a patient portal where access is authenticated and logged. Email is best reserved for administrative traffic and provider-to-provider communication under enforced encryption. Splitting the channels deliberately, and writing down the rule, reduces exposure more than any single technical control.


Sources

Sources And Further Reading

Every regulatory statement on this page traces to one of the following primary sources. We encourage you to read them directly.

  1. U.S. Department of Health and Human Services, Office for Civil Rights. HIPAA Security Rule, 45 CFR Part 164 Subpart C, covering administrative, physical, and technical safeguards for electronic protected health information.
  2. U.S. Department of Health and Human Services. Guidance on business associates and business associate contracts under the HIPAA Privacy and Security Rules.
  3. U.S. Department of Health and Human Services. Breach Notification Rule guidance, including the risk assessment factors used to determine whether an impermissible use or disclosure requires notification.
  4. Google. HIPAA Implementation Guide for Google Workspace and Cloud Identity, which describes the Business Associate Agreement, the covered services, and administrator responsibilities.
  5. Google Workspace Admin Help. Documentation for the Business Associate Agreement acceptance process, data loss prevention for Gmail, hosted S/MIME, secure transport enforcement, Google Vault retention, and admin and login audit log events.
  6. Microsoft. HIPAA Business Associate Agreement and compliance offering documentation for Microsoft 365 enterprise services.

Related Services

Build The Rest Of The Program

Compliant email is one control set inside a wider HIPAA program. These are the pieces that surround it.


Find Out Where Your Email Actually Stands

Petronella Technology Group, Inc. will inventory your mail paths, verify BAA coverage, and review your tenant configuration against the HIPAA Security Rule. The assessment is free and it usually starts with one call. You get a findings register you can act on whether or not you hire us.