Google Keep is a digital note-taking app within Google Workspace that lets users create, share, and organize notes, lists, photos, drawings, and audio files. Google describes Keep as a tool for creating and sharing notes, lists, photos, drawings and audio that can be accessed across devices.
With Google Keep, users can capture quick notes, organize information with labels and reminders, collaborate on notes, and access saved content across Workspace-connected devices.
Is Google Keep HIPAA compliant? Yes, Google Keep is HIPAA compliant, but under certain conditions.
What changed this year?
As of July 2026, our review did not identify any publicly disclosed changes removing Google Keep from Google’s HIPAA related policies or BAA coverage. Google’s HIPAA Included Functionality list, dated May 14, 2026, continues to list Google Keep as Included Functionality under the applicable HIPAA Business Associate Addendum.
Google also continues to state that Workspace and Cloud Identity customers subject to HIPAA who want to use Google services that handle PHI must enter into a business associate amendment with Google before doing so.
Will Google Keep sign a BAA?
Yes, Google will sign a BAA, which can be reviewed here: Google Workspace HIPAA Business Associate Addendum. Google states that customers with HIPAA compliance needs may review and accept the BAA from the Google Admin console, but the user must be an administrator for the organization’s Google Workspace or Cloud Identity account.
What does the Google Keep BAA cover?
The Google Workspace BAA covers Google products and services listed as Covered Services or Included Functionality. Google’s HIPAA Included Functionality list states that, as of May 14, 2026, Google Keep is included under the applicable HIPAA Business Associate Addendum.
Google’s BAA states, “This BAA applies to the extent Customer is acting as a Covered Entity or a Business Associate to create, receive, maintain, or transmit PHI via a Covered Service.”
Their BAA covers:
- Protection of PHI
- Permitted uses and disclosures of PHI
- Security incident and breach notification obligations
- Subcontractor protections
- Access and amendment support
- Accounting of disclosures
- Access by HHS requests
- Return or destruction of PHI after termination
What does the Google Keep BAA exclude?
Google’s BAA does not cover every Google product, every Google account type, or every way a user might store information. The BAA only applies to Covered Services, and Google’s terms state that it does not apply to “any other Google product, service, or feature that is not a Covered Service” or to PHI created, received, maintained, or transmitted outside the Covered Services, including third-party applications.
It means Google Keep’s HIPAA coverage depends on using Keep within an eligible Google Workspace or Cloud Identity environment, accepting Google’s BAA, limiting PHI to covered services, and configuring the account appropriately. Google also states that customers who have not signed a BAA “must not use PHI in Google Workspace or Cloud Identity services.”
Conclusion
Google Keep is HIPAA compliant, but only when used under an eligible Google Workspace or Cloud Identity account with Google’s BAA in place and appropriate administrative controls configured.
See also: HIPAA Compliant Email: The Definitive Guide
FAQs
What is a business associate agreement?
A BAA is a legally binding contract establishing a relationship between a covered entity under HIPAA and its business associates. The purpose of this agreement is to ensure the proper protection of PHI as required by HIPAA regulations.
What is HIPAA?
HIPAA sets national standards for protecting the privacy and security of certain health information, known as PHI.
HIPAA is designed to protect the privacy and security of individuals’ health information and to ensure that healthcare providers and insurers can securely exchange electronic health information. Violations of HIPAA can result in significant fines and penalties for covered entities.
Who does HIPAA apply to?
HIPAA applies to covered entities, which include healthcare providers, health plans, and healthcare clearinghouses. It also applies to business associates of these covered entities. These are entities that perform certain functions or activities on behalf of the covered entity.
