Google Vault is an information governance and eDiscovery tool that provides tools for archiving, retaining, and managing data across Google Workspace apps.

With Google Vault, organizations can retain emails, files, and chat messages, search through archived data, and manage legal holds. This helps businesses ensure compliance, protect critical data, and efficiently handle eDiscovery and audit requests.

Is Google Vault HIPAA compliant? Yes, based on our research, Google Vault can be HIPAA compliant.

 

What changed this year?

In June 2026, Google Vault expanded its retention rules and litigation holds to cover the Gemini app, allowing organizations to include Gemini conversations in their regulatory and eDiscovery management from within Vault. This update applies specifically to the Gemini app on web and mobile and does not extend to Gemini in Workspace features embedded in other apps, such as "Help me write" in Gmail or Docs.

 

Will Google Vault sign a business associate agreement (BAA)?

Yes, Google Vault will sign a business associate agreement, which can be reviewed and accepted here. Google Vault is included as part of the same HIPAA Business Associate Addendum that covers other Google Workspace Core Services.

 

What does the Google Vault BAA cover?

The Google BAA covers the use and disclosure of protected health information (PHI). Their HIPAA Implementation Guide states that all users can access covered Core Services for use with PHI under the BAA, as long as the healthcare organization configures those services to be HIPAA compliant. Google Vault is included in this list.

 

What does the Google Vault BAA exclude?

Not all Workspace plans include access to Vault by default. Legal and compliance teams typically rely on the Business Plus or Enterprise tiers, which offer Vault functionality for retention, search, and holds lower-tier plans like Business Starter and Standard do not include Vault.

Google Vault is a tool meant only for retention and eDiscovery, and is not a backup and restore service. Data retained and protected in Vault is difficult to access by design, so organizations should choose a dedicated backup and restore solution as a separate disaster prevention measure. Vault does not retain data until retention rules are set up, until then, users can delete data, and services can purge it according to that service's own protocol.

Healthcare organizations relying on Vault for HIPAA audit and retention requirements should confirm their Workspace plan includes the tier of Vault functionality needed, and should not treat Vault as a substitute for a documented backup strategy.

 

Conclusion

Google Vault signs a BAA and is therefore HIPAA compliant.

Learn more: HIPAA Compliant Email: The Definitive Guide

 

FAQs

What is a business associate agreement?

A business associate agreement (BAA) is a legally binding contract establishing a relationship between a covered entity under the Health Insurance Portability and Accountability Act (HIPAA) and its business associates. The purpose of this agreement is to ensure the proper protection of personal health information (PHI) as required by HIPAA regulations.

 

What is HIPAA?

The Health Insurance Portability and Accountability Act (HIPAA) sets national standards for protecting the privacy and security of certain health information, known as protected health information (PHI).

HIPAA is designed to protect the privacy and security of individuals' health information and to ensure that healthcare providers and insurers can securely exchange electronic health information. Violations of HIPAA can result in fines and penalties for covered entities.

 

Who does HIPAA apply to?

HIPAA applies to covered entities, which include healthcare providers, health plans, and healthcare clearinghouses. It also applies to business associates of these covered entities. These are entities that perform certain functions or activities on behalf of the covered entity.