Is Google Drive HIPAA Compliant in 2020? (2024)

Yes, you can use Google Drive in a HIPAA compliant environment, but only if you’re careful! That’s the quick answer. Read on to learn more!

Every day we hear from practitioners who want to use Google Workspace in their medical practice. Google Workspace is easy-to-use, affordable, and can be HIPAA compliant. Most people want Google Workspace for Gmail, but having access to Google Drive and Docs really makes the subscription cost worthwhile.

In this article you will learn:

  • What is Google Workspace?
  • Is Google Workspace HIPAA compliant?
  • How to sign a BAA with Google
  • What is Google Drive?
  • Is using Google Docs HIPAA compliant?
  • What’s the difference between Google Drive and Dropbox?
  • How do I make Google Drive HIPAA compliant?

Contents hide

What is Google Workspace and is it HIPAA Compliant?

Google’s Business Associate Agreement (BAA)

BAA does not mean HIPAA compliance

Is using Google Docs HIPAA Compliant?

Is Google Drive and Docs safe for confidential information or medical records?

Can I use Google Drive on my Smartphone or Tablet?

Google Drive vs. Dropbox

How to make Google Drive HIPAA compliant

Talk to us!

What is Google Workspace and is it HIPAA Compliant?

Google Workspace is a collection of collaboration and productivity tools. You’re probably using some of these tools already: Gmail, Docs, Drive, Calendar, Meet and more.

Is Google Drive HIPAA Compliant in 2020? (1)

Google Workspace is a paid subscription service. If your email address ends with @gmail.com you are using Google’s free Gmail and apps, not Google Workspace.

What’s the difference between Google Workspace and free Gmail? Basically, the difference is having @gmail.com or @yourcompany.com at the end of your email address. You also get more cloud storage, phone/email support, additional security options and administrative controls with Google Workspace,.

You can use Google Workspace in a HIPAA compliant manner, but it is not HIPAA compliant right out of the box. Free Gmail/Google Apps cannot be HIPAA compliant since Google will not provide a BAA for free Gmail accounts. We have a bunch of articles about making Google Workspace HIPAA compliant:

  • HIPAA Compliant Gmail (17 Step How-To Guide for 2024)
  • Is Google Workspace HIPAA Compliant?
  • 5 Ways to Make Google Workspace HIPAA Compliant
  • Is Gmail Encryption HIPAA Compliant?

Google’s Business Associate Agreement (BAA)

Google will provide a BAA for Google Workspace account holders. Need help finding it? Check out this help article: https://support.google.com/a/answer/3407074?hl=en

Google’s BAA does not cover every service in Google Workspace. Protected Health Information (PHI) can be used in the following Google Workspace Apps: Gmail, Calendar, Drive (including Docs, Sheets, Slides, and Forms), Google Hangouts (chat messaging feature only), Hangouts Chat, Hangouts Meet, Keep, Google Cloud Search, Google Voice (managed users only), Sites, Google Groups, Jamboard, Cloud Identity Management, Tasks, and Vault.

Google Drive is included in that list! If you configure file sharing properly in Google Drive, it’s a great choice for HIPAA compliant cloud storage.

Is Google Drive HIPAA Compliant in 2020? (2)

BAA does not mean HIPAA compliance

But here’s a disclaimer that many private practice “influencers” miss: signing a BAA with Google does not make your Google Workspace/Google Drive HIPAA compliant.

Seriously – Google CLEARLY says

“Customers are responsible for … ensuring that they use Google services in compliance with HIPAA.”

“PHI is allowed only in a subset of Google services.”

“These Google covered services … must be configured by IT administrators to help ensure that PHI is properly protected."

So yes, Google Workspace CAN be HIPAA compliant, but it’s not compliant right out of the box.

You need to make sure your account is secure.

What is Google Drive?

Google Drive is a secure, easy-to-use cloud storage solution. It’s very easy to create and share files and folders. This is great from a collaboration standpoint, but not great from a HIPAA-standpoint. This is why it’s imperative that you set up Google Drive correctly to avoid sharing documents with the wrong recipients!

Google Drive is kind of like a cross between Dropbox (where you can back up your files to the cloud) and Microsoft Office (for creating and editing documents). It’s all in your web browser, and is really easy to learn and use.

You can upload any type of file to Drive and convert files to a Google document format: Docs (like Microsoft Word), Sheets (like Microsoft Excel) or Slides (like Microsoft PowerPoint).

How much cloud storage do you get? There are three levels of Google Workspace, and each has a different price/user and amounts of Drive cloud storage:

  • Basic $6/user/month, 30 GB cloud storage per user
  • Business $12/user/month, 2 TB cloud storage per user
  • Business Plus $18/user/month, 5 TB cloud storage per user
  • Enterprise contact Google for pricing, unlimited cloud storage

12/31/2020: here's a link to their pricing page: https://workspace.google.com/pricing.html

Is using Google Docs HIPAA Compliant?

Google Docs are intuitive collaboration and documentation tools. They are web-based and very similar to Microsoft Word, Excel and PowerPoint. You can convert many types of files into Google Docs formats:

  • Docs (word processing similar to Microsoft Word)
  • Sheets (spreadsheets similar to Microsoft Excel)
  • Slides (presentations similar to Microsoft PowerPoint)

And the answer is YES! Google Docs (with a paid Google Workspace subscription, signed BAA and appropriately configured settings) can be HIPAA compliant. They clearly state this in Google’s HIPAA Implementation Guide (linked at the end of this article).

Is Google Drive HIPAA Compliant in 2020? (3)

Is Google Drive and Docs safe for confidential information or medical records?

Google’s BAA covers Google Drive and Docs, so these services are appropriate for storing PHI. Google’s HIPAA Implementation Guide recommends the following:

  • Avoid putting PHI in titles of files, folders or team drives
  • Set appropriate file sharing permissions
  • Review file sharing reports, especially to see which files are shared with external users
  • Consider disabling third-party applications

Yes, Google Drive and Docs is safe for storing medical records or confidential information, but only if it’s configured correctly. Files in Google Drive and all file metadata (titles and comments) are encrypted. Learn more about Google’s Security focus here: https://support.google.com/googlecloud/answer/6056693?hl=en&visit_id=637275245913296513-3573186912&rd=1

Can I use Google Drive on my Smartphone or Tablet?

Yes! Google Drive and the rest of Google Workspace is very mobile friendly. You can use Google Drive in a HIPAA compliant manner if you use the Google Drive app on your smartphone or tablet AND you have Google Workspace configured properly.

Google Workspace subscriptions include a Mobile Device Management system which allows you to require screenlocks or passwords in addition to removing confidential data from devices as needed.

Google Drive vs. Dropbox

Google Workspace is perfect for smaller medical practices that need HIPAA compliant email, cloud storage, telehealth and more - but what if you already have a solution for email and telehealth and you just need cloud storage? You might want to look at other options, just to see other offerings.

We have an article that quickly reviews 11 HIPAA compliant cloud storage options: https://adeliarisk.com/hipaa-compliant-cloud-storage/

One of the most popular cloud storage solutions is Dropbox. Here’s a quick comparison between Google Drive (as a part of Google Workspace, not the free version) and Dropbox:

Google DriveDropbox
Sign BAA?YesYes
Cost- $6/user/month Basic- $12/user/month Business- $18/user/month Business Plus- $19.99/month for 1 user- $15.00/user/month for 3 users
Storage30 GB - 5 TB/user depending on plan3-5 TB depending on plan
Two-step verificationYesYes
Encryption at restYesYes
Encryption in transitYesYes
Remote wipe*YesYes

*in case a device is lost or stolen, it’s important to be able to remove files containing PHI

If you’re considering Google Drive, Dropbox or any other cloud storage solution, it’s important to review the actual features that you intend to use. We didn’t look at every feature of these solutions in our comparison, so be sure to check their websites for more information.

How to make Google Drive HIPAA compliant

Most practitioners who want to use Google Drive in their practice want to use the entire Google Workspace service. You need to set up your Google Workspace account properly. Google strives to make services easy to use, collaborate and share — which is great, but HIPAA requires you to limit sharing. You only want to share things with intended recipients!

Talk to us!

Have questions or feedback? Please share them in the comments below.

Like this article? Share it!

Is Google Drive HIPAA Compliant in 2020? (2024)
Top Articles
4 Reasons Your Deposit Isn't Showing Up As Planned
Are investment fund managers happy?
2018 Jeep Wrangler Unlimited All New for sale - Portland, OR - craigslist
Po Box 7250 Sioux Falls Sd
Winston Salem Nc Craigslist
Grange Display Calculator
Linkvertise Bypass 2023
2022 Apple Trade P36
Routing Number 041203824
Space Engineers Projector Orientation
Select Truck Greensboro
Craigslist Dog Kennels For Sale
Winterset Rants And Raves
Regal Stone Pokemon Gaia
David Turner Evangelist Net Worth
Procore Championship 2024 - PGA TOUR Golf Leaderboard | ESPN
Chastity Brainwash
Sonic Fan Games Hq
Khiara Keating: Manchester City and England goalkeeper convinced WSL silverware is on the horizon
Craigslist In Visalia California
Rugged Gentleman Barber Shop Martinsburg Wv
Macu Heloc Rate
Weather Underground Durham
Evil Dead Rise Showtimes Near Regal Sawgrass & Imax
My Dog Ate A 5Mg Flexeril
Eero Optimize For Conferencing And Gaming
Bee And Willow Bar Cart
Joplin Pets Craigslist
Powerball lottery winning numbers for Saturday, September 7. $112 million jackpot
67-72 Chevy Truck Parts Craigslist
The Best Carry-On Suitcases 2024, Tested and Reviewed by Travel Editors | SmarterTravel
Staar English 1 April 2022 Answer Key
Oxford Alabama Craigslist
What Does Code 898 Mean On Irs Transcript
Wlds Obits
Paperless Employee/Kiewit Pay Statements
Nsav Investorshub
התחבר/י או הירשם/הירשמי כדי לראות.
Gasoline Prices At Sam's Club
Devon Lannigan Obituary
Blackwolf Run Pro Shop
Pike County Buy Sale And Trade
Dobratz Hantge Funeral Chapel Obituaries
2000 Ford F-150 for sale - Scottsdale, AZ - craigslist
Lightfoot 247
Latina Webcam Lesbian
Dolce Luna Italian Restaurant & Pizzeria
Dcuo Wiki
Ark Silica Pearls Gfi
Who We Are at Curt Landry Ministries
Latest Posts
Article information

Author: Aron Pacocha

Last Updated:

Views: 5973

Rating: 4.8 / 5 (68 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Aron Pacocha

Birthday: 1999-08-12

Address: 3808 Moen Corner, Gorczanyport, FL 67364-2074

Phone: +393457723392

Job: Retail Consultant

Hobby: Jewelry making, Cooking, Gaming, Reading, Juggling, Cabaret, Origami

Introduction: My name is Aron Pacocha, I am a happy, tasty, innocent, proud, talented, courageous, magnificent person who loves writing and wants to share my knowledge and understanding with you.