Google Calendar is a scheduling and calendar management tool from Google that allows users to create events, schedule meetings, share calendars, manage appointments, and coordinate availability across Google Workspace.
With Google Calendar, organizations can manage schedules, invite attendees, create shared calendars, and coordinate meetings across teams.
Is Google Calendar HIPAA compliant? Yes, Google Calendar can be HIPAA compliant when used within the correct parameters.
What changed this year?
As of June 2026, our review did not identify any publicly disclosed changes removing Google Calendar from Google’s HIPAA coverage or ending Google’s BAA availability for eligible Google Workspace customers.
Google’s HIPAA Included Functionality page states that, as of May 14, 2026, the applicable HIPAA Business Associate Addendum includes Google Calendar. It means Google Calendar remains part of the Google Workspace services that may be used in connection with protected health information (PHI) when the customer has accepted Google’s BAA and uses the service appropriately.
Will Google Calendar sign a business associate agreement (BAA)?
Yes, Google will sign a BAA or eligible Google Workspace and Cloud Identity customers, which can be reviewed here: Google Workspace HIPAA Business Associate Addendum.
Google’s HIPAA guidance explains that Google Workspace and Cloud Identity customers who are subject to HIPAA and want to use PHI in covered Google services must enter into a BAA with Google before doing so.
What does the Google Calendar BAA cover?
The Google Workspace BAA covers Google Calendar when Calendar is used as part of Google Workspace’s HIPAA Included Functionality. Google’s included functionality page lists ‘Google Calendar’ among the services covered by the applicable HIPAA Business Associate Addendum.
Google’s BAA also states that Google and the customer will each use appropriate safeguards to help prevent unauthorized use or disclosure of PHI.
Their BAA covers:
- Use of PHI in covered Google Workspace services, including Google Calendar
- Appropriate safeguards for PHI
- Security incident and breach notification obligations
- Subcontractor protection requirements
- Access and amendment support through the covered services
- Accounting of disclosures
- Access by HHS, where required by law
- Return or destruction of PHI after termination, where applicable
What does the Google Calendar BAA exclude?
The Google Workspace BAA does not automatically cover every Google product, every type of Google account, or every third-party integration connected to Google Calendar.
Google’s BAA says it does not apply to “any other Google product, service, or feature” that is not a covered service. It also excludes PHI created, received, maintained, or transmitted outside the covered services, including offline tools, on-premise storage tools, and third-party applications.
It is a major limitation for healthcare organizations. A personal Google Calendar account should not be treated as HIPAA compliant. Likewise, Google’s BAA does not automatically cover third-party calendar add-ons, external booking tools, Chrome extensions, or connected applications. Healthcare organizations must review each integration separately to determine whether a separate BAA is required.
Google Calendar can support HIPAA compliant scheduling, but the organization remains responsible for how PHI is entered, shared, stored, and accessed. Calendar event titles, descriptions, guest lists, locations, attachments, reminders, and integrations should be configured carefully to avoid unnecessary PHI exposure.
Conclusion
Google Calendar is HIPAA compliant when used through an eligible Google Workspace or Cloud Identity account, with Google’s BAA accepted, and with appropriate HIPAA safeguards in place.
Google Calendar is not HIPAA compliant by default for personal accounts, uncovered services, or third-party integrations not included under Google’s BAA.
Learn more: HIPAA Compliant Email: The Definitive Guide
FAQs
What is a business associate agreement?
A BAA is a legally binding contract establishing a relationship between a covered entity under HIPAA and its business associates. The purpose of this agreement is to ensure the proper protection of PHI as required by HIPAA regulations.
What is HIPAA?
HIPAA sets national standards for protecting the privacy and security of certain health information.
HIPAA is designed to protect the privacy and security of individuals’ health information and to ensure that healthcare providers and insurers can securely exchange electronic health information. Violations of HIPAA can result in fines and penalties for covered entities.
Who does HIPAA apply to?
HIPAA applies to covered entities, which include healthcare providers, health plans, and healthcare clearinghouses. It also applies to business associates of these covered entities. These are entities that perform certain functions or activities on behalf of the covered entity.
