Disclaimer: Total HIPAA provides HIPAA compliance software, training, and documentation services. We do not provide IT services, email encryption software, or Google Workspace/Gmail technical setup. For assistance with configuring your email client or implementing third-party encryption, please consult with a qualified Managed Service Provider (MSP) or IT professional.
Can I email PHI?
The Health Insurance Portability and Accountability Act (HIPAA) mandates that Covered Entities and Business Associates protect electronic Protected Health Information (ePHI) in transit, in storage, and at rest. It’s a common misconception that standard email is inherently secure.
On its own, email is not a secure platform to transmit PHI.
In fact, using Google’s free email service to send unencrypted PHI is a direct violation of Google’s Terms of Service and a major data breach risk.
Emailing PHI without encryption is a HIPAA violation, as this could easily lead to a breach if the email ends up in the wrong hands.
If an email containing PHI lands in the wrong hands or is intercepted over an unsecured network, your organization faces severe federal penalties.
Is Gmail or Google Workspace HIPAA Compliant?
Gmail is not automatically HIPAA compliant out of the box, and free Gmail accounts can never meet HIPAA standards as no BAA has been provided.
It is critical to understand the distinction between free accounts and paid corporate accounts:
- Free Gmail (@gmail.com): Google will not sign a Business Associate Agreement for free accounts. Sending PHI through a free Gmail account is an automatic HIPAA violation.
- Google Workspace: This is the paid, enterprise-grade ecosystem. Google Workspace allows you to execute a BAA, gives administrators robust control over user behaviors, and unlocks essential security architecture.
A Google Workspace Account or G Suite is the paid version of Gmail.
There are several security benefits to purchasing this program, such as administrator controls on users. For example, administrators can mandate the use of two-factor authentication for all employees.
Additionally, admins can limit employees’ email usage on mobile devices. For this to be effective, you must implement these security measures on all employee accounts.
You can implement administrative and technical security measures to ensure the safety of sensitive information sent via Google’s infrastructure using a paid corporate account. Even if encrypted with a third party, Google maintains and stores the data from free Gmail accounts on their servers.
Google Workspace tiers that will NOT sign a BAA, and as such cannot be HIPAA compliant are:
- Free Gmail
- Google Workspace Individual
- Legacy G Suite Free Edition
Simply signing a BAA and using a paid Google Workspace account is still not enough for external emails. By default, Google secures messages using Transport Layer Security (TLS). TLS only encrypts emails in transit, and it only works if the recipient’s email provider also supports TLS. If you send an email containing ePHI to someone whose email server lacks TLS support, the message travels across the internet in plain text. Furthermore, standard TLS provides no way to recall an email or revoke access if it is accidentally sent to the wrong person.
When it comes to protecting emailed data, G Suite’s native security only goes so far. Although your messages are encrypted in transit, this does not protect your ePHI if an email is sent to the wrong recipient. To actively recall, track, and log whether unauthorized individuals have accessed sensitive data, you must deploy a third-party encryption program. Implementing this type of third-party plug-in can be the difference between a simple mistake and a serious data breach.
Popular third-party tools that integrate seamlessly with Gmail to achieve end-to-end encryption include Virtru, RMail, LuxSci, Paubox, and Egress.
Do I Need a Business Associate Agreement (BAA) with Google?
Yes. To make Gmail HIPAA compliant, you must enter into a Business Associate Agreement with Google before any PHI touches the platform.
Thankfully, you do not need to print and mail a physical contract. Google allows account administrators to digitally sign the BAA within the Google Admin Console. Under the Legal and Compliance section of your account settings, you can review and accept the Google Workspace HIPAA Business Associate Addendum.

The BAA Is Just Step One: Modern Configuration Requirements
When you’ve made Gmail HIPAA compliant with email encryption and secure email practices, does this mean your company is now fully compliant with HIPAA law?
No. Sending HIPAA compliant emails does not automatically ensure HIPAA compliance.
Signing the BAA is a vital legal baseline, but it does not magically make your daily operations compliant. HIPAA compliance is a shared responsibility. Google secures the underlying cloud infrastructure, but you are responsible for how your staff configures and interacts with it.
To keep your organization off the HHS “Wall of Shame,” administrators must enforce the following technical safeguards:
- Enforce Multi-Factor Authentication (MFA) and Passkeys: Passwords fatigue quickly and are easily compromised. Administrators must mandate MFA (utilizing modern passkeys, Google Authenticator, or physical security keys) across all employee accounts to ensure stolen credentials cannot breach your database.
- Implement DMARC, SPF, and DKIM Records: Domain authentication is no longer optional. To prevent malicious actors from spoofing your medical domain and to guarantee email deliverability, your IT department must align these cryptographic records in your Domain Name Server (DNS).
- Disable Non-Covered Services and Third-Party Add-Ons: Google’s BAA only applies to specific “Included Functionality” (like Gmail, Google Drive, and Google Meet). Consumer applications like YouTube, Blogger, or unvetted third-party apps from the Workspace Marketplace are not covered under the BAA and must be turned off for any users handling PHI.
- Govern Google Gemini (AI) Tools: With AI deeply integrated into modern workspaces, remember that inputting patient data into unmanaged generative AI tools poses a massive compliance risk. Ensure your Workspace tier specifically wraps your AI interactions under your signed BAA protections.
- Acknowledge That “Confidential Mode” is Not Enough: Google Workspace features a “Confidential Mode” that allows you to set expiration dates and restrict forwarding. While great for Data Loss Prevention (DLP), Confidential Mode does not replace end-to-end encryption and will not satisfy an OCR audit on its own.
Does Safe Email Mean My Company Is Fully Compliant?
No. Secure email infrastructure is only one piece of the puzzle. HIPAA compliance demands a “living, breathing” defense-in-depth strategy.
Imagine an employee drafts an encrypted email containing an attached medical record, but leaves their workstation unlocked and walks away for lunch. The data is exposed to anyone walking past the desk. Security requires constant mindfulness, physical safeguards, and ongoing workforce education.
Organizations must document these technical procedures explicitly within their corporate HIPAA Policies and Procedures. Furthermore, regular, documented staff HIPAA training is required to ensure every team member understands how to operate these secure tools correctly.
HIPAA requires organizations to protect PHI as soon as they encounter it and for the entire time they have access to it. As with every HIPAA compliance security measure, organizations must train their employees on how to correctly and safely use programs like Gmail. Employers must include email practices for making Gmail HIPAA compliant in their policies and procedures.
Additionally, entities should assign an administrator who is knowledgeable and readily available to help with all matters concerning email security. Penalties for violating HIPAA via email are just as severe as any other punishments, with fines ranging from ~$145 – $73,011 per violation (with an annual cap at ~$2,190,294 per incident).
With a concentrated effort, structured configurations, and the right partner, your company can securely leverage Gmail while remaining completely HIPAA compliant.
Have you performed a comprehensive Risk Assessment this year? Are your HIPAA Policies and Procedures updated for modern cloud configurations? Our HIPAA Prime™ program creates customized compliance plans, simplifies documentation, and provides your team with easy online training. Schedule a call to protect your business today!



