As it relates to providing HIPAA compliant email service, we originally compared Google Workspace to Paubox in 2018.
In our initial review, we found the Google Workspace business associate agreement did not include the actual transmission of email across the internet as being in scope.
Now that it’s 2024, perhaps Google Workspace has changed its stance or scope on providing HIPAA compliant email service.
As such, we’ll revisit the question: What's the difference between Google Workspace and Paubox for HIPAA compliant email?
See related: Is Microsoft 365 HIPAA compliant? (2023 update)
Google Workspace (formerly known as G Suite) is a suite of cloud-based productivity and collaboration tools offered by Google. It includes services such as Gmail, Google Drive, Google Docs, Google Sheets, Google Slides, Google Calendar, Google Meet, Google Keep, and others.
These tools can be used by individuals, teams, and businesses to communicate, store, and manage data and documents, and collaborate on projects.
Paubox Email Suite is for healthcare organizations seeking to remove friction from their HIPAA compliant communications. Paubox Email Suite is a cloud-based solution that provides a seamless user experience for both senders and recipients of secure email.
Unlike incumbent solutions that force recipients to login to a portal to read a secure message, the Paubox solution allows the recipient to read a secure email in their inbox, just like a normal message.
Paubox launched in 2015 and currently has over four thousand customers in all 50 states.
There’s a primary item to consider when it comes to Google Workspace and its ability to provide a HIPAA compliant service.
First, let’s start with a quick recap of terms. The Health Insurance Portability and Accountability Act (HIPAA) is a federal law that protects the privacy of individuals’ personal health information, otherwise known as protected health information (PHI).
As we’ve previously discussed, HIPAA applies to covered entities, which includes healthcare providers, health plans, and healthcare clearinghouses. It also applies to business associates of these covered entities. These are entities that perform certain functions or activities on behalf of the covered entity.
A business associate agreement (BAA) is a written contract between a covered entity and a business associate. It is required by law for HIPAA compliance and is considered the primary item to consider when it comes to Google Workspace and its ability to be HIPAA compliant.
In the case of Google Workspace, the service would certainly fall into the category of business associate if it’s servicing customers that would store, process, or transmit PHI on its platform.
We googled Google's site and found their BAA: G Suite HIPAA Business Associate Amendment. From there, we eventually found the Google HIPAA Implementation Guide, which is an informational guide that Google makes available describing how customers can configure and use Google services to support HIPAA compliance.
Within Google's HIPAA Implementation Guide, the first section to pay attention to is called HIPAA Included Functionality.
This page states:
"As of July 21, 2020, The following functionality is Included Functionality under the applicable HIPAA Business Associate Addendum:
Gmail, Calendar, Drive (including Docs, Sheets, Slides, and Forms), Apps Script, Keep, Sites, Jamboard, Google Chat, Google Meet, Google Voice (managed users only), Google Cloud Search, Cloud Identity Management, Google Groups, Google Tasks and Vault (if applicable)."
As we can see, Gmail is included in the Google Workspace BAA.
The next section within the Google HIPAA Implementation Guide to pay attention is called:
Scrolling down a bit, we find the sub heading called Gmail. The HIPAA guidance here is vague, as Google only makes two claims about Gmail and HIPAA compliance:
It should be noted there is a complete absence of two basic tenets of HIPAA compliant email:
In an effort to gain clarity about the ability of Google Workspace to provide encrypted, HIPAA compliant email while it transits the internet, we eventually found a Google Support page called Best practices and data privacy.
From there, we found a page called Security checklist for medium and large businesses. Scrolling down a bit, we found an expandable section called Gmail (Google Workspace only). Once expanded, we found a checkbox labeled Enforce TLS with your partner domains. Bingo. We found the setting we're looking for:
To learn more about this checkbox, we clicked Require mail to be transmitted via a secure (TLS) connection.
From there, we found several nuggets of useful info:
See related: Paubox eliminates obsolete TLS protocols, follows NSA guidance
Paubox was built around the Paubox Foundations, three big ideas, and a mission to become the market leader for HIPAA compliant communication.
Paubox provides a BAA for all paid and freemium customers.
In addition, the following solutions are HITRUST CSF certified:
While an official HIPAA compliance certification does not exist, it’s widely acknowledged HITRUST CSF is the closest thing to it. Not only is Paubox HIPAA compliant, but its solutions are also HITRUST CSF certified.
Paubox was built using patented technology whereby if a secure connection cannot be established to the receiving mail server, Paubox automatically detects this and then converts the message (plus any attachments) to the Paubox Secure Message Center. The recipient then needs only a single extra click to secure access the message.
In other words, the email is not bounced, rejected, or sent unencrypted, as is the case with Google Workspace's built-in encryption settings.
In addition, Paubox supports only secure versions of TLS. Following the aforementioned NSA guidance, here’s a list of security protocols supported by Paubox:
Both Google Workspace and Paubox offer HIPAA compliant email services for organizations.
While Google Workspace provides a wide array of services that fall in scope of its BAA, its encrypted email component falls short in the following areas:
Paubox Email Suite can be quickly configured to integrate and complement Google Workspace.
The extra layer of security (HITRUST certified), ease of use, and peace of mind are the reasons why thousands of customers choose to Paubox to supplement Google Workspace.