HIPAA & compliance

Signing the Google BAA and hardening your Workspace

The Business Associate Agreement is where a compliant Google Workspace starts — not where it ends. Here's how to sign it, and the handful of settings that turn a signed contract into a practice you could actually defend.

Published August 2026 · Written by Perry Emerick, LPC · 7 min read

PE

Written by Perry Emerick, LPC — a licensed counselor and the Privacy & Security Officer for his own practice, sharing what he learned setting his own Workspace up.

Compliance is behavior, not a checkbox

The most expensive misunderstanding in private practice is that HIPAA is a product you buy or a box you tick. It isn't. HIPAA is a set of behaviors — how you configure your tools, who can reach your data, what you do when something goes wrong, and whether you can prove any of it after the fact. A signed agreement is a necessary part of that, but a signed agreement sitting on top of a wide-open account protects no one.

I went through this myself, and I want to be plain about my footing: I'm a licensed counselor who serves as my own practice's Privacy and Security Officer, not a security engineer or an attorney. What follows is the practical path a solo or small-practice clinician can actually walk, not legal advice. Where the stakes are high, a HIPAA consultant or healthcare attorney is worth every dollar.

Signing the Google Workspace BAA

Google will act as your Business Associate — but only on a paid Workspace plan, and only once you've accepted the agreement. Consumer Gmail accounts have no BAA and can never be made to hold protected health information. The acceptance lives in your admin console:

  1. Sign in to the Google Admin console at admin.google.com with your administrator account.
  2. Go to Account → Legal & Compliance (in some consoles, Account → Account settings → Legal & Compliance).
  3. Open the Business Associate Amendment (HIPAA) and review it.
  4. Accept it, and save the confirmation somewhere durable for your compliance file.

One nuance clinicians miss: the BAA only covers the specific Google services Google designates as "Included Functionality," and it's your job to keep protected health information inside those covered services. If a service isn't covered, it shouldn't hold client data. Read the list once so you know your own boundaries.

Hardening the account you just made a business associate

Signing the BAA hands you responsibilities as much as it grants you coverage. These are the settings that most change your real-world risk, roughly in order of return on effort.

Enforce 2-Step Verification

A password alone is the single weakest point in any practice. Turn on 2-Step Verification and, in the admin console, enforce it rather than leaving it optional — for yourself and anyone else on the account. An authenticator app or a hardware security key is meaningfully stronger than SMS codes. This one change blocks the overwhelming majority of account-takeover attempts, which are how most small-practice breaches actually happen.

Lock down sharing and access

Configure Drive sharing so files can't be made public or shared outside your organization by default. Practice least privilege: only the people who need a record should be able to open it, and "Shared with me" clutter is a liability, not a convenience. If you ever bring on an associate or a biller, give them access to exactly what they need and nothing more — and remove it the day they leave.

Consider Google Vault for retention and holds

On the Workspace tiers that include it, Google Vault lets you set retention rules and place legal holds across Gmail and Drive. For a clinician, the value is being able to retain records for your required period and demonstrate a deliberate retention and eDiscovery posture, rather than relying on nobody deleting the wrong thing. Vault isn't on every plan, so check whether yours includes it before you build a policy around it.

Mind the endpoints

Your Workspace is only as safe as the devices signed into it. A screen lock and disk encryption on every laptop and phone, prompt updates, and the ability to remotely sign a lost device out of your account are the unglamorous basics that a real security review will ask about. Compliance lives on the hardware as much as in the cloud.

Your downstream business associates count too

Once your Workspace is buttoned up, remember the chain doesn't stop at Google. Any tool that touches protected health information on your behalf is a business associate you should have an agreement with — and each one is another surface to reason about.

The narrowest surface is the safest one

This is the lens I built Practice Pad through. When you use it, you sign a BAA with Practice Pad Technologies as a downstream business associate — and by design, there is very little for that agreement to cover. Your notes live encrypted on your iPad and, if you sync, in your own Google Drive under your own Google BAA. Handwriting is converted to text with on-device OCR. Practice Pad's own servers don't hold your clinical records.

That's the whole philosophy: the less of your data a vendor holds, the less there is to breach, subpoena, or lose. A downstream associate you barely have to trust is better than one you have to trust completely.

You don't need Practice Pad to run a hardened Workspace — the steps above stand on their own. But when you evaluate any add-on that touches client data, ask how much of your information it actually holds. The narrowest answer is usually the right one.

A hardened Workspace deserves a minimal-surface note-taker

Practice Pad keeps your clinical records on your device and in your own Drive — not on our servers.

Start your 14-day free trial Read the full Workspace-as-EHR guide

Built by an LPC · On-device encryption · US & Canada

Related guides

Part of our series on running a HIPAA-aware practice on Google Workspace. Start with the pillar guide: Google Workspace as a Therapy EHR — and the missing piece.