Billing

Ask most practice administrators whether their cloud environment is HIPAA compliant and you will get a confident yes. Ask what that confidence rests on and the answer is usually the same: we signed the agreement. That agreement matters. It is also the smallest part of the job. The gap between a signed contract and a genuinely protected environment is where nearly all of the everyday risk sits. Not in sophisticated attacks, but in a receptionist saving a patient's phone number to the wrong app.

This article covers operational configuration and risk reduction, drawing on a detailed breakdown of what makes Google Workspace HIPAA compliant. It is not legal advice and does not constitute a compliance audit or a determination of legal standing. According to the HHS Office for Civil Rights, covered entities and business associates bear full responsibility for ensuring that any cloud service they use for PHI is configured according to the HIPAA Security Rule, regardless of what a vendor's agreement covers.