1 link tagged with all of: compliance + cloud-identity + phi + google-workspace
Click any tag below to further narrow down your results
Links
This guide explains how to configure Google Workspace and Cloud Identity services to handle protected health information under a HIPAA Business Associate Addendum. It lists which core services support PHI, outlines customer responsibilities, and shows how to separate user access via organizational units to meet compliance requirements.
- Only specific Workspace services (Gmail, Calendar, Chat, Drive apps, Cloud Search, Groups, Keep, Meet, Sites, Tasks, Vault, managed Voice, Gemini app) are covered for PHI under the BAA—Contacts, YouTube, Photos, and Gemini in Chrome are excluded.
- Admins, not Google, are responsible for determining Business Associate status, securing agreements, and handling HIPAA access/amendment/accounting requests.
- Organizational units must be used to separate PHI users from non-PHI users and restrict which services each group can access.
- Recommended safeguards include auditing third-party integrations, monitoring account activity, and locking down sharing settings across Docs, Drive, Chat, and Meet.