Skip to sign in Skip to content

Practice management

Is Gmail HIPAA compliant? Potentially…

Want to use Gmail in your private practice? Follow our 4-step guide to see how to make Gmail HIPAA compliant, and why an alternative may be better for you...
Is Gmail HIPAA compliant?

Estimated reading time: 8 minutes

Summarize this article with ChatGPT

TL;DR: To use Gmail in a HIPAA-compliant way, you need an eligible Google Workspace account, a Business Associate Agreement (BAA) with Google, appropriate security settings, and policies based on your risk analysis. Google Workspace can be configured to require TLS for outgoing email, but this takes administrative setup and does not protect messages after they arrive in the recipient's inbox.

If you prefer a simpler option, you can keep using Gmail for everyday communication and use Hushmail to send secure messages and forms.

If you already use Gmail for your practice, you might be wondering: Is it HIPAA compliant?

You like using Gmail because:

  • You're familiar with it
  • It's useful to have Google's other apps tightly integrated
  • It feels simple and easy to manage

The short answer: you can make Gmail HIPAA compliant, and this article will show you how.

But be warned, just because it's possible doesn't mean it's ideal.

  • You'll need to pay for Google's business plan, known as Google Workspace
  • You'll need to configure how messages containing PHI are protected, which may include requiring TLS or using an additional encryption service.
  • Setup won't be easy, and Google's support options are limited in case you get stuck

The good news is, if you like using Gmail, you don't need to replace it.

Many healthcare professionals keep Gmail for everyday communication and use Hushmail for secure messages or forms.

This gives you a simpler way to protect sensitive information, without changing the tools you already rely on.

But if you still want to learn how to make Gmail HIPAA-compliant, let's dive in!

How to make Gmail HIPAA compliant – A step-by-step guide

These are the 4 steps you'll need to follow. While the process isn't easy, we'll guide you using screenshots and simple explanations.

Steps to make Gmail HIPAA compliant

Step 1: Sign up for Google Workspace

You're probably used to Gmail – Google's free version of email for personal use.

However, regular Gmail isn't HIPAA compliant.

Instead, you'll need to sign up and pay for Google's business planGoogle Workspace (formerly G Suite).

Here's how:

1. Click here to go to Google Workspace and click "Get started" in the top corner

Google Workspace - Get started

2. Fill in your business name and number of employees (if any)

Google Workspace business details

3. Enter your name and current email address

Google Workspace Personal Details

4. Now you'll need to choose whether you own a "domain"

Google Workspace Domain Choice

What is a domain? The domain is the part of your email address after the @ symbol.

Domain explanation

Imagine you're a social worker using the website: watsonsocialwork.com. If you own the domain, you can create a professional-looking email address and increase trust with clients.

So instead of matthew.watson.lcsw@gmail.com, you could be matthew@watsonsocialwork.com.

The downside of having a custom domain is that you need to pay a few dollars extra each year. 

4a. If you do have a domain name…

Then click "Yes, I have one I can use". Google will ask you to enter it and verify you own it later. Google provides instructions for linking your domain to Google Workspace; you can follow them here.

4b. If you don't have a domain…

Then click "No, I need one" and Google will help you to search for and buy one. Most domain names will cost you between $12 and $60/year.

Google Workspace Domain Search

5. Create a username and password

Put your username as the email address you want to use. Then create a password for it.

To strengthen your password, we advise using a random set of memorable words. You might consider a phrase with a specific meaning to you, or about a family member, hobby, or personal belief.

For example: "chess is very hard" or "anna goes to nursery".

Google Workspace Account

After you're done, you'll be redirected to the login screen. Sign in using the username and password you just created, and get ready to choose a plan!

Which Google Workspace plan is HIPAA compliant?

Unlike personal Gmail accounts, any of Google's Workspace plans have the potential to be HIPAA compliant. Most of the features on the higher-priced plans are aimed at large enterprises. So if you're a small or medium-sized private practice, you can choose the Business Starter plan.

Google Workspace Plans

Step 2: Sign a BAA with Google for Gmail

As you will send and receive Protected Health Information (PHI), you need to sign a legal document known as a Business Associate Agreement (BAA). This agreement asks your email provider to comply with HIPAA and ensure your client information is held securely. The good news is:

  • These agreements can usually be signed electronically in a few clicks
  • The email provider should draft the agreement for you, so there are no lawyer fees

Important to know: Most healthcare professionals must have a BAA. But strictly speaking, it depends on whether HIPAA applies to you based on your profession and whether you bill insurance. If you're unsure, read our article to find out if you need a BAA.

This being said, getting a BAA is useful – even if you don't fall under HIPAA. A BAA will set responsibilities on your email provider and help to satisfy your own professional responsibility to your clients.

Here's how you sign a BAA for Google Workspace:

1. Click here and log in to Google’s Admin Panel

12_Google Admin Console

2. On the menu bar, go to Account > Account settings

13_Google Admin Settings

3. Scroll to the bottom of the page. Then click on the “Legal and compliance” box.

14_Google Workspace HIPAA Compliance

4. Click on "Not accepted" under "Google Workspace/Cloud Identity HIPAA Business Associate Amendment"

14b_Google BAA not accepted_update

5. Then click on "Review and accept."

14c_Google BAA review and accept_update

6. A pop-up should appear with 3 questions. Provide a yes/no answer to each of them.

15_Google HIPAA questionnaire

Note: If you're unsure what a "Covered Entity" is, or if you are one, then check our BAA guide first.

5. Review and accept the BAA agreement

Google HIPAA BAA

After clicking "I Accept", you've signed the BAA!

Step 3: Configure Gmail to protect emails containing PHI

After you've signed a Business Associate Agreement (BAA) with Google and set up Google Workspace, the next step is deciding how you'll protect emails that contain protected health information (PHI).

By default, Gmail tries to send emails over a secure, encrypted connection called Transport Layer Security (TLS).

What is encryption?

Encryption scrambles your information so only the intended recipient can read it. If someone intercepts the message while it's being sent, they'll see unreadable text instead of your information.

In most cases, Gmail can send messages using TLS.

But if the recipient's email provider can't use TLS, Gmail may still send the message without that protection.

You can change this behavior by requiring TLS for outgoing messages.

When you do, Gmail sends the email only if it can use a secure, encrypted connection. If it can't, the email isn't sent, and you'll receive a message letting you know it couldn't be delivered.

This helps protect your email while it's on its way to the recipient.

Once it arrives, though, it's just a regular email sitting in the recipient's inbox.

Is requiring TLS enough for your practice?

Requiring TLS is a good step because it helps protect your email while it's traveling across the internet.

But once the email reaches the recipient, TLS has done its job.

The message is delivered to the recipient's regular inbox, where it's stored just like any other email. At that point, you have much less control over who can access it or what happens next.

Whether requiring TLS is enough depends on your practice, the type of information you send, and the risks you've identified as part of your HIPAA risk analysis. HIPAA doesn't require you to buy a third-party email encryption service. Instead, it requires you to assess the risks and choose reasonable safeguards for your practice.

Want to learn more about how email is protected while it's being sent and after it's delivered? Read our Is sending email securely enough? blog post.

For some providers, requiring TLS may be enough.

Others decide they want additional protection because:

  • An email won't be delivered if the recipient's mail server can't establish a TLS connection.

  • Sensitive information ends up in the recipient's regular inbox after delivery.

  • You can't control whether the recipient forwards the email or leaves it in a shared inbox.

  • If someone else has access to the recipient's email account, they may also have access to the message.

For these reasons, some healthcare practices use a secure messaging or email encryption service alongside Gmail.

If you Google "Gmail encryption provider", you'll find a few companies that offer encryption for Gmail. One of the biggest is called Virtru.

Virtru pricing

But as you may notice:

  • Most encryption providers aim their services at large companies, not small to medium-sized practices
  • Their websites are technical and full of acronyms (HSM, DLP, SIEM, CJIS, ITAR)
  • Even if you're familiar with Gmail, you still have to learn how to use encryption software with it
  • Virtru's Starter plan costs $119/month for five users when billed annually
  • Their default support is online assistance only

For most healthcare practitioners, this means dealing with a more complex and expensive setup for using Gmail in a HIPAA-compliant way.

If that feels like more than you want to take on, there are simpler, more affordable ways to handle secure communication. We'll come back to that shortly. First, let's look at the final step.

Step 4: Follow Google's HIPAA implementation guide

Once you’ve decided how you’ll protect messages containing PHI, you'll need to adjust a few settings within Gmail. Handily, Google has created a guide with all the details, which you can access below:

Google HIPAA Implementation Guide

You'll also want to:

  • Set strong passwords: Remember when we said it's important to create a strong password? Well, you can check if your colleagues in your practice are using strong passwords from within the password management section of Google's admin panel. If Google thinks their passwords are weak, then ask them to change them.
  • Use two-step verification: Gmail and most email providers can send you a code by text or email to verify it's you every time you log in. Learn why you should turn on two-step verification.

🚨 Important to know: Do you use any external add-ons with Gmail, such as a grammar checker or file backup service? If you do, be aware that signing a BAA with Google Workspace does not cover them.

You'll either need to disable them or check if they can be made HIPAA-compliant.

What are the advantages and disadvantages of using Gmail as a HIPAA-compliant email service?

Now you know how to make Gmail HIPAA compliant. Is it worth it? Or is there a better alternative for you? Let's take a look.

Advantages and Disadvantages of Gmail

Advantages of using Gmail as a HIPAA-compliant email service

You're familiar with it

Gmail has a simple interface that makes it easy to use. Better yet, most people have had a Gmail account for years, which makes it less intimidating.

But remember that:

Other Google Workspace apps are nearby

Google has some great apps like Docs, Sheets, and Meet, which are a bonus when using Gmail. Just be aware that Google Contacts is not HIPAA-compliant and integrates closely with Gmail.

Google Workspace Apps

Disadvantages of using Gmail as a HIPAA-compliant email service

It's difficult to set up

If you're tech-savvy or run a large practice with a tech team, you should be OK. But for everyone else, it might be difficult, time-consuming, and expensive to set up.

Lack of personalized support

Google provides free standard support with its Business Starter plan. But as a large tech company, their support may struggle to understand the needs of a small healthcare practice.

Here at Hushmail, we have conversations with our healthcare customers about supporting HIPAA compliance every day. Our plans include full support at no extra cost. You can get help from a real person when you need it. We'll guide you through setup and answer your questions along the way.

Not built for healthcare users

Gmail was built as an email service for all companies, not just healthcare practices. While this makes it versatile, it does mean that any updates aren't prioritized with healthcare users in mind.

What if there's a new regulation about HIPAA-compliant email? How long might it take them to respond?

No forms with healthcare templates

As a healthcare professional, you need to be able to email forms to your clients.

Google does have an app for creating forms. But unlike Hushmail, it:

  • Doesn't include pre-made healthcare templates such as client intake forms, diagnosis forms, health screenings, etc.
  • Doesn't include specialist features like body charts (used by patients to indicate points of pain)
  • Doesn't give you the ability to electronically sign forms

Need to set up a professional email address

To use Gmail in a HIPAA-compliant way, you'll need to sign up for Google Workspace. This means setting up a custom email address for your practice, which may involve buying and managing a domain. This adds extra steps and cost before you can start sending secure messages.

Need additional protection for sensitive emails

If your practice needs more protection than required TLS provides, secure messaging is another option. Instead of delivering sensitive information directly to the recipient's inbox, secure messaging keeps it on a secure web page that the recipient accesses through a secure link.

How secure messages are delivered

When you send a secure message with Hushmail, the recipient receives a notification and clicks a secure link to view the message. They can read, reply, and complete forms on a secure page. They don't need a paid Hushmail account to access it.

Learn more about how secure messages work.

Seamless client experience

How to send HIPAA-compliant messages without configuring Gmail

For secure communication, many healthcare professionals use Hushmail alongside Gmail.

  Hushmail Gmail
Healthcare form templates ✅ Included ❌ No
Electronic form signatures ✅ Included ❌ No
Message delivery ✅ Through a secure link ❌ Regular email¹
HIPAA setup ✅ Designed for healthcare and HIPAA-ready 🟠 Requires Workspace administration and practice-specific configuration
Best use Secure messages and forms Everyday email
Get started Sign up Find out more about Google Workspace
Table updated Aug, 2026

¹ Google has a "confidential mode" feature, but it doesn't support secure replies from recipients unless they also have Gmail.

You can keep using Gmail for everyday communication, and use Hushmail when you need to send sensitive information.

Does using a HIPAA-compliant email service mean that you're fully HIPAA compliant?

No! It's still up to you to ensure you handle your emails in a compliant way. That's why we put together 6 quick tips to ensure your emails are truly HIPAA compliant. Enter your name and email, and we'll send them to you right away.

FAQ about using Gmail for HIPAA-compliant email

We'll answer common questions about using Gmail as a HIPAA-compliant email provider.

Is Gmail's confidential mode HIPAA compliant?

Gmail's confidential mode has some useful security features. It allows you to set a message expiration date, require a code for recipients to open messages, and remove message access.

However, it has the same downsides as Gmail. You would still need to follow our guide to sign a BAA with Google (which can only be done after paying for Google Workspace). Plus, you should still follow Google's HIPAA implementation guide.

Conclusion: Is Gmail HIPAA-compliant in 2026?

Gmail isn't HIPAA-compliant out of the box. But with a lot of effort, it is possible to make it HIPAA-compliant.

Considering the costs, difficult setup, lack of healthcare forms, and other downsides, it becomes hard to justify.

For most healthcare professionals, it's much easier to use a service like Hushmail for secure messages and forms, while continuing to use Gmail for everyday communication.

Reviewed by: Steven O. Youngman, VP of Legal and Compliance, Hushmail

Similar posts