25 Aug Signing the BAA Is Step One. Here Is Where Patient Data Actually Leaks
Ask most practice administrators whether their cloud environment is HIPAA compliant and you will get a confident yes. Ask what that confidence rests on and the answer is usually the same: we signed the agreement. That agreement matters. It is also the smallest part of the job. The gap between a signed contract and a genuinely protected environment is where nearly all of the everyday risk sits. Not in sophisticated attacks, but in a receptionist saving a patient’s phone number to the wrong app.
This article covers operational configuration and risk reduction, drawing on a detailed breakdown of what makes Google Workspace HIPAA compliant. It is not legal advice and does not constitute a compliance audit or a determination of legal standing. According to the HHS Office for Civil Rights, covered entities and business associates bear full responsibility for ensuring that any cloud service they use for PHI is configured according to the HIPAA Security Rule, regardless of what a vendor’s agreement covers.
Key Takeaways
- Major cloud platforms are best described as HIPAA-ready rather than HIPAA compliant. The infrastructure is capable, but the configuration is entirely your responsibility.
- A Business Associate Agreement covers a specific, published list of services. Anything outside that list gets no protection, even when it sits in the same interface.
- Google Contacts is a core service where PHI is explicitly not permitted, which surprises almost everyone who reads the list for the first time.
- Your subscription tier determines whether you have retention and data loss prevention tools at all, and the cheapest tiers do not include them.
- Written policy is not evidence of control. Only testing the configuration tells you whether it works.
Ready Is Not the Same as Compliant
The distinction sounds like semantics until an auditor asks for evidence. A cloud vendor can offer encrypted storage, secure data centers and a signed agreement, and your environment can still be wide open. The platform is HIPAA-ready out of the box, and turning that into a compliant environment takes deliberate administrative setup, access controls and ongoing governance.
This is the shared responsibility model that underpins nearly every cloud service in healthcare. The vendor secures the infrastructure. You own how it is configured, who can reach what and how staff actually behave inside it. That second column is where audits are lost. It is also the column no software purchase can fill on your behalf.
What the Agreement Actually Covers
Google publishes an explicit list of core services in which PHI is permitted. It includes Gmail on paid accounts, Drive with Docs, Sheets, Slides and Forms, Calendar, Chat, Meet, Keep, Groups, Tasks, Sites, Cloud Search and Vault. Everything else sits outside that boundary. YouTube, Blogger, Google Photos, Maps and most additional services in the Admin Console carry no coverage, and Google’s implementation guide says they should be disabled for anyone handling PHI.
Third-party add-ons are also excluded, even when installed through the official marketplace. If a vendor’s tool touches patient data, that vendor needs its own separate agreement with your organization. Then there is the one that catches experienced administrators off guard. Google Contacts is a core service in which PHI is not permitted. That is a direct quote from Google’s own implementation guide, not an interpretation. It sits right there in the interface next to Gmail, which is exactly why clinical staff use it.
Where PHI Quietly Escapes
Healthcare breaches rarely begin with a sophisticated intrusion. They begin with convenience.
- Contacts as an informal patient directory. Front desk staff save patient names, numbers and a note about why they are coming in. That is PHI in a service that carries no coverage.
- Link sharing set to anyone with the link. A therapist builds a handout containing patient details and shares it the fastest way possible. Authentication is now bypassed for anyone who obtains the URL.
- Calendar titles. An appointment labeled with a full patient name and the reason for the visit is PHI sitting in event metadata, exposed by whatever the domain’s default calendar visibility happens to be.
- Browser AI assistants. The Gemini assistant built into Chrome is not covered by the Workspace agreement, and Google’s guide states directly that PHI should not be uploaded into it. Staff pasting a chart note into a browser sidebar is a real and growing exposure.
- Shared logins on a reception inbox. When four people use one password, you cannot prove who accessed a record. That destroys the audit trail HIPAA depends on.
- Abandoned app permissions. A PDF tool installed two years ago to convert intake forms still holds read access to Drive. Nobody has reviewed it since.
The Edition Question Nobody Asks Early Enough
Every paid tier lets you sign the agreement. That is the trap. Signing on a tier without the right tools leaves you exposed while feeling protected. The entry tiers include no Vault, which means no legal hold, no eDiscovery and no retention controls. HIPAA requires documentation to be retained for six years under 45 CFR 164.316, and state medical record retention rules apply separately on top of that.
Business Plus is the realistic minimum for any organization where clinical staff touch patient data, because it adds Vault along with basic endpoint management for lost or stolen devices. Enterprise tiers add automated data loss prevention that scans for PHI patterns and blocks improper sharing, plus context-aware access rules that can refuse a login from an unmanaged personal laptop.
Testing Beats Documenting
A binder of policies proves intent. It does not prove the settings work. Four checks tell you more than any written procedure.
- Sweep Drive for external sharing. Scan the whole domain for files set to public or external link access. Most organizations running this for the first time find something they did not expect.
- Run a live offboarding. Pick a test account and revoke it. Confirm that Gmail, Drive, mobile access and third-party app tokens all die at once, then confirm that any files the account owned have a new owner rather than becoming orphaned.
- Audit connected applications. Review every third-party tool with access to your domain and remove anything without its own agreement in place.
- Test retention. Run a sample eDiscovery query in Vault and confirm the records you are legally required to hold are actually being held.
The Practical Conclusion
Compliance in a cloud environment is not a purchase or a signature. It is an administrative discipline that decays quietly the moment nobody is watching it. Tools like gPanel by Promevo exist to close the visibility gap, offering centralized reporting, bulk offboarding and domain-wide sharing sweeps. It is worth stating clearly that no administrative platform confers compliance on its own, since that is determined by your organization’s full technical and administrative framework. What such tools do is make the gaps visible before an auditor finds them. For most practices, that is the difference between knowing your configuration works and merely hoping it does. Organizations seeking formal validation should engage certified healthcare compliance auditors. Internal testing is good practice, not certification.
Frequently Asked Questions
Is a signed Business Associate Agreement enough to make a cloud platform HIPAA compliant?
No. The agreement defines which services may lawfully handle PHI, but the platform is best described as HIPAA-ready. Access controls, sharing defaults, retention rules and staff training all remain your organization’s responsibility.
Why is Google Contacts excluded when Gmail is covered?
Google’s HIPAA Implementation Guide lists Contacts as a core service in which PHI is not permitted, while Gmail on a paid account is permitted. The practical implication is that patient contact details tied to care should live in an EHR or another covered system rather than in Contacts.
Which subscription tier does a small practice actually need?
Business Plus is generally the practical minimum, because it is the first tier to include Vault for retention and legal hold. Larger organizations typically need Enterprise tiers for automated data loss prevention and context-aware access controls.
Are third-party apps installed from an official marketplace covered?
No. Marketplace add-ons and browser extensions fall outside the platform vendor’s agreement. Any third-party tool that touches patient data requires a separate Business Associate Agreement executed directly with that vendor.
For a broader overview of how cybersecurity, data governance, and HIPAA compliance are shaping healthcare technology procurement decisions in 2026, see this MedicalResearch.com overview of healthcare technology priorities for clinical companies.
Disclaimer: The information on MedicalResearch.com is provided for educational purposes only, and is in no way intended to diagnose, cure, or treat any medical or other condition. Some links are sponsored. Products, services and providers are not warranted or endorsed by MedicalResearch.com or Eminent Domains Inc. Always seek the advice of your physician or other qualified health provider and ask your doctor any questions you may have regarding a medical condition. In addition to all other limitations and disclaimers in this agreement, service provider and its third party providers disclaim any liability or loss in connection with the content provided on this website.
Last Updated on August 25, 2026 by Marie Benz MD FAAD
