Google Cloud Identity is an identity and access management (IAM) platform that provides tools for managing user accounts, authentication, and device security.
With Google Cloud Identity, organizations can control access to apps and resources, enforce multi-factor authentication, and manage devices from a single console. This helps businesses enhance security, streamline user management, and ensure compliance across their cloud environment.
Is Google Cloud Identity HIPAA compliant? Yes, based on our research, Google Cloud Identity can be HIPAA compliant.
What changed this year?
Google's HIPAA compliance documentation for Workspace and Cloud Identity was last updated on June 18, 2026, with no changes identified to Cloud Identity Management's covered status. Google notes it continues to assess the scope of Included Functionality and may add further products in the future.
Will Google Cloud Identity sign a business associate agreement (BAA)?
Yes, Google Cloud Identity will sign a business associate agreement, which can be reviewed and accepted here. Google Workspace and Cloud Identity customers who are subject to HIPAA and wish to use certain services listed on the HIPAA Included Functionality list must enter into a Business Associate Amendment with Google, and customers who have not signed a BAA must not use PHI in Google Workspace or Cloud Identity services.
What does the Google Cloud Identity BAA cover?
The Google BAA covers the use and disclosure of protected health information (PHI). Their HIPAA Implementation Guide states that all users can access covered Core Services for use with PHI under the BAA, as long as the healthcare organization configures those services to be HIPAA compliant. Google Cloud Identity Management is included in this list.
What does the Google Cloud Identity BAA exclude?
Google has no obligations under the BAA with respect to any PHI that a customer creates, receives, maintains, or transmits outside of the Covered Services, including offline or on-premise storage tools or third-party applications.
Neither the Cloud Data Processing Addendum nor the Google Workspace BAA terms extend to Additional Google Services, though Google continues to evaluate methods to provide additional controls related to these services and may introduce them at any time.
Organizations should also be careful not to confuse Cloud Identity Management, which falls under the Workspace and Cloud Identity BAA, with Google Cloud's separate Identity Platform product used for building custom authentication into applications. Google Cloud's Identity Platform can support HIPAA compliance if properly used, but customers must sign the separate Google Cloud Business Associate Agreement to use it with PHI.
Conclusion
Google Cloud Identity signs a BAA and is therefore HIPAA compliant.
Learn more: HIPAA Compliant Email: The Definitive Guide
FAQs
What is a business associate agreement?
A business associate agreement (BAA) is a legally binding contract establishing a relationship between a covered entity under the Health Insurance Portability and Accountability Act (HIPAA) and its business associates. The purpose of this agreement is to ensure the proper protection of personal health information (PHI) as required by HIPAA regulations.
What is HIPAA?
The Health Insurance Portability and Accountability Act (HIPAA) sets national standards for protecting the privacy and security of certain health information, known as protected health information (PHI).
HIPAA is designed to protect the privacy and security of individuals' health information and to ensure that healthcare providers and insurers can securely exchange electronic health information. Violations of HIPAA can result in fines and penalties for covered entities.
Who does HIPAA apply to?
HIPAA applies to covered entities, which include healthcare providers, health plans, and healthcare clearinghouses. It also applies to business associates of these covered entities. These are entities that perform certain functions or activities on behalf of the covered entity.
