Google Docs is an online document editor from Google Workspace that allows users to create, edit, share, and collaborate on documents in real time.
With Google Docs, organizations can draft documents, manage comments and suggestions, review version history, and control who can view, edit, comment on, download, or share files.
Is Google Docs HIPAA compliant? Yes, Google Docs can be HIPAA compliant.
What changed this year?
As of June 2026, our review did not identify any publicly disclosed changes removing Google Docs from Google Workspace HIPAA coverage or changing Google’s BAA terms in a way that affects Google Docs.
Google’s current HIPAA Included Functionality page, dated May 14, 2026, still lists “Google Drive (including Google Docs, Google Forms, Google Sheets, Google Slides, and Google Vids)” as Included Functionality under the applicable Google Workspace HIPAA Business Associate Addendum.
Will Google Docs sign a business associate agreement (BAA)?
Yes, Google will sign a business associate agreement for eligible Google Workspace and Cloud Identity customers, which can be reviewed here: Google Workspace HIPAA Business Associate Amendment.
However, this agreement does not mean that every use of Google Docs is automatically HIPAA compliant. Google says Workspace and Cloud Identity customers who are subject to HIPAA and want to use PHI in listed Google services “must enter a Business Associate Amendment (BAA) with Google.” Google also states that customers who have not signed a BAA “must not use PHI in Google Workspace or Cloud Identity services.”
What does the Google Docs BAA cover?
Google Docs is covered through Google Drive under Google’s HIPAA Included Functionality list. The current list includes “Google Drive (including Google Docs, Google Forms, Google Sheets, Google Slides, and Google Vids).”
Google’s BAA states, “This BAA applies to the extent Customer is acting as a Covered Entity or a Business Associate to create, receive, maintain, or transmit PHI via a Covered Service and to the extent Google, as a result, is deemed under HIPAA to be acting as a Business Associate or Subcontractor of Customer.”
Their BAA covers:
- Use of PHI in covered Google Workspace services
- Google Docs through Google Drive
- Security incident obligations
- Accounting of disclosures
- Access by HHS requests
- Return or destruction of PHI after termination
- Customer use of Google’s HIPAA Implementation Guide
Google also says administrators must review and accept the BAA before using PHI in Google services.
What does the Google Docs BAA exclude?
Google’s BAA does not cover every Google product, service, feature, third-party application, add-on, or use case. It only applies to covered services listed by Google.
The BAA states, “Customer acknowledges that this BAA does not apply to (a) any other Google product, service, or feature that is not a Covered Service; or (b) any PHI that Customer creates, receives, maintains, or transmits outside of the Covered Services (including Customer’s use of its offline or on-premise storage tools or third-party applications).”
Google’s HIPAA help page also states that third-party applications, including add-ons, are not included in the Included Functionality covered by the BAA.
It means Google Docs may be HIPAA compliant only when used inside a properly configured Google Workspace or Cloud Identity environment with an accepted BAA. A personal Google account, consumer Google Docs use, unmanaged sharing, public links, unsupported add-ons, or third-party tools connected to Google Docs may fall outside Google’s BAA coverage.
Conclusion
Google Docs can be HIPAA compliant, but only when used through Google Workspace or Cloud Identity with Google’s BAA in place and with proper HIPAA configuration.
See also: HIPAA Compliant Email: The Definitive Guide
FAQS
What is a business associate agreement?
A BAA is a legally binding contract establishing a relationship between a covered entity under HIPAA and its business associates. The purpose of this agreement is to ensure the proper protection of PHI as required by HIPAA regulations.
What is HIPAA?
HIPAA sets national standards for protecting the privacy and security of certain health information.
HIPAA is designed to protect the privacy and security of individuals’ health information and to ensure that healthcare providers and insurers can securely exchange electronic health information. Violations of HIPAA can result in significant fines and penalties for covered entities.
Who does HIPAA apply to?
HIPAA applies to covered entities, which include healthcare providers, health plans, and healthcare clearinghouses. It also applies to business associates of these covered entities. These are entities that perform certain functions or activities on behalf of the covered entity.
