Google Groups is a communication and collaboration service that allows users to distribute emails through a shared group address, participate in group discussions, organize events, and manage conversations through a Collaborative Inbox.

Organizations can use Google Groups to create mailing lists, discussion groups, support queues, and other shared communication channels.

Is Google Groups HIPAA compliant? Yes, Google Groups can be HIPAA compliant.

 

What changed this year?

As of July 2026, Google Groups remains included in Google’s HIPAA Included Functionality. Google updated the current functionality list on May 14, 2026, while the Google Workspace BAA was last modified on September 12, 2025.

 

Will Google Groups sign a BAA?

Yes, Google offers a Google Workspace BAA that covers Google Groups.

A Google Workspace super administrator must electronically accept the BAA through the Admin console before the organization uses covered Google services to create, receive, maintain, or transmit PHI. Google states that customers who have not accepted the BAA must not use PHI in Google Workspace services.

 

What does the Google Groups BAA cover?

Google’s Workspace BAA covers Google Groups because the current HIPAA Included Functionality list specifically names Google Groups as covered functionality.

The Google Workspace BAA states, “Google and Customer will each use appropriate safeguards” concerning PHI handled through covered services.

The BAA covers:

  • PHI created, received, maintained, or transmitted through the covered Google Groups service
  • Appropriate safeguards against unauthorized uses or disclosures of PHI
  • Notification of qualifying breaches and security incidents
  • Protections required of Google subcontractors with access to PHI
  • Documentation and accounting of certain PHI disclosures
  • Access by the US Department of Health and Human Services when legally required
  • Return or destruction of PHI following termination of the applicable services agreement

Google’s breach-notification terms require it to notify the customer promptly and without unreasonable delay, and no later than 60 calendar days after discovering a breach.

Google also states that customers remain responsible for configuring available controls and ensuring that their employees’ use of Google Groups complies with HIPAA and HITECH. Organizations should therefore restrict group membership, posting permissions, conversation visibility, external access, and administrative privileges according to their HIPAA policies.

 

What does the Google Groups BAA exclude?

The Google Workspace BAA “does not apply to…any other Google product, service, or feature that is not a Covered Service.”

The BAA also excludes PHI created, received, maintained, or transmitted outside Google’s covered services, including through offline storage, on-premises tools, or third-party applications.

Google specifically confirms that its Workspace BAA does not cover third-party applications and add-ons. Healthcare organizations must separately assess those applications and obtain another BAA where necessary.

The BAA applies to the covered Google Workspace version of Google Groups. Google also offers a free consumer version of Groups, but the Workspace BAA does not cover that version. Google Groups can therefore only support HIPAA regulated use when it is provided under an applicable Google Workspace services agreement, the BAA has been accepted, and the organization uses the covered functionality.

 

Conclusion

Google Groups is HIPAA compliant when it is used as a covered Google Workspace service under an accepted Google BAA and configured with appropriate privacy and security controls. The free consumer version, third-party add-ons, and Google services outside the covered-functionality list are not covered.

See also: HIPAA Compliant Email: The Definitive Guide

 

FAQs

What is a BAA?

A BAA is a legally binding contract establishing a relationship between a covered entity under HIPAA and its business associates. The purpose of the agreement is to ensure the proper protection of PHI as required by HIPAA regulations.

The agreement defines the permitted uses and disclosures of PHI and requires the business associate to appropriately safeguard the information.

 

What is HIPAA?

HIPAA sets national standards for protecting the privacy and security of certain health information.

HIPAA is designed to protect the privacy and security of individuals’ health information and to ensure that healthcare providers and insurers can securely exchange electronic health information. Violations of HIPAA can result in significant fines and penalties for covered entities and business associates.

 

Who does HIPAA apply to?

HIPAA applies to covered entities, which include healthcare providers that conduct certain electronic transactions, health plans, and healthcare clearinghouses. It also applies to business associates that perform certain functions or provide services involving PHI on behalf of covered entities.