Click any tag below to further narrow down your results
Links
Google Apps Script is now a core Google Workspace service with enterprise-grade data protection and technical support. Administrators who previously disabled Apps Script can re-enable it to deliver secure custom automations. No action is required for organizations that already had it enabled or for end users.
- Google Apps Script became a core Workspace service on June 23, 2026, now covered by the same enterprise-grade security and compliance policies as Gmail and Drive.
- Admins who previously disabled Apps Script over security/compliance concerns can now re-enable it without needing extra compliance reviews.
- No action is needed for orgs that already had it enabled or for end users—functionality and settings remain unchanged.
- It's now visible in every Workspace customer's admin console regardless of Rapid or Scheduled Release track.
This guide explains how to configure Google Workspace and Cloud Identity services to handle protected health information under a HIPAA Business Associate Addendum. It lists which core services support PHI, outlines customer responsibilities, and shows how to separate user access via organizational units to meet compliance requirements.
- Only specific Workspace services (Gmail, Calendar, Chat, Drive apps, Cloud Search, Groups, Keep, Meet, Sites, Tasks, Vault, managed Voice, Gemini app) are covered for PHI under the BAA—Contacts, YouTube, Photos, and Gemini in Chrome are excluded.
- Admins, not Google, are responsible for determining Business Associate status, securing agreements, and handling HIPAA access/amendment/accounting requests.
- Organizational units must be used to separate PHI users from non-PHI users and restrict which services each group can access.
- Recommended safeguards include auditing third-party integrations, monitoring account activity, and locking down sharing settings across Docs, Drive, Chat, and Meet.