Are Google Workspace and Microsoft 365 HIPAA Compliant? What to Know in 2026
Healthcare data contains some of the most sensitive information about a person, which is why it's protected by HIPAA (Health Insurance Portability and Accountability Act) in the U.S. HIPAA is a set of regulations that aim to protect the privacy and security of patients' protected health information (PHI).
Too often, professionals in the medical field assume that standard email and file-sharing platforms like Google Workspace and Microsoft 365 are safe enough to transmit PHI on their own. The answer is more nuanced. Both platforms can be part of a HIPAA compliant email and file sharing program, and both offer business associate agreement terms.
But neither one makes your organization compliant by default. The gap between "we have a BAA" and "PHI is actually protected everywhere it travels" is where most healthcare organizations get into trouble.
Here are the four things that most often leave a Google Workspace or Microsoft 365 environment short of HIPAA expectations:
- Encryption that stops at the edge of your tenant
- BAA coverage that doesn't extend to every service in use
- Limited control over data once it's shared
- Non-compliant third-party apps and integrations
Below is what each one means in practice in 2026, and what to do about it.
Is Email HIPAA Compliant? It Depends on What Happens After You Hit Send
Both Google Workspace and Microsoft 365 encrypt email in transit using TLS (Transport Layer Security). The critical detail is that both use opportunistic TLS by default.
Google's documentation is explicit: Gmail always tries to send over a secure TLS connection, but "if the receiving server doesn't use TLS, Gmail still sends messages, but the connection isn't secure." Microsoft says the same of Exchange Online. By default it "sends the message without encryption if the recipient's organization doesn't support TLS encryption."
You can force TLS through compliance settings and connectors. But then messages to non-TLS recipients bounce instead, which creates its own problem when a referring physician or a patient's insurer can't receive your message.
That leaves administrators choosing between two imperfect outcomes: PHI that may travel unencrypted, or care communication that fails to arrive. Both stem from the same root cause. The protection is applied to the connection, not to the data.
A second issue follows from the first. Once a message or attachment lands in a recipient's inbox, TLS has done its job and stopped. The PHI now sits in an environment you don't administer, can be forwarded to anyone, and stays readable indefinitely. Your obligation to protect that PHI doesn't end when the connection closes.
What Google and Microsoft BAAs Actually Cover
HIPAA requires covered entities and business associates to enter into a business associate agreement (BAA) before PHI is handled on a vendor's platform. Both providers offer one, and the mechanics differ in ways worth knowing.
Google Workspace offers a HIPAA Business Associate Amendment that a super administrator can review and accept directly in the Admin console under Legal and compliance. It is not gated behind a premium edition. One common misconception is that a BAA requires an Enterprise plan, and it doesn't.
What matters instead is which services the BAA covers. Google publishes an explicit list, and it does not include third-party applications and add-ons, or "Additional Google Services" like Blogger and Google Photos. Google's own implementation guide directs administrators to disable non-covered services for users who handle PHI.
Microsoft 365 takes a different approach. BAA terms are included by default through the Microsoft Products and Services Data Protection Addendum rather than a separately signed agreement, and Microsoft's documentation indicates it does not accept a customer's own BAA form. Coverage is defined by service rather than by plan, and the in-scope list spans Exchange Online, SharePoint Online, OneDrive for Business, Teams, and others. We weren't able to locate a consolidated list of excluded services, so confirming that a given tool is in scope takes more work than a simple lookup.
The practical takeaway is the same for both platforms. A signed BAA defines responsibility for PHI; it does not automatically extend to every app your staff has installed, and it does not encrypt anything. Two organizations can hold identical BAAs and have very different actual risk.
HIPAA Compliant Data Storage Should Emphasize Control
Beyond email, Google Workspace and Microsoft 365 hold documents, spreadsheets, imaging files, and scanned records across Google Drive, OneDrive, and SharePoint. Assessing HIPAA exposure means looking at that full footprint, not just the mail flow.
In both platforms, data is encrypted at rest — with keys the provider manages. That satisfies a great deal, but it also means the provider retains the technical ability to decrypt your content, and your PHI is exposed to any compromise of that key custody.
Both vendors offer stronger options, and this is where plan tiers start to matter. Google Workspace client-side encryption is available on Frontline Plus, Enterprise Plus, and Education Standard and Education Plus, among other editions. It also requires you to stand up an external key service and connect an identity provider. On the Microsoft side, Purview Message Encryption is included in E3 and E5 as well as Business Premium, while Double Key Encryption — the option that keeps a key outside Microsoft's control — requires E5.
The strongest native encryption tends to sit in the most expensive plans, and often carries significant setup work. For a community clinic or a specialty practice running Business Standard, upgrading the entire organization to the top tier may not be realistic.
You also need to consider the users of the software. You don't want to introduce hurdles for a provider who needs to share records with an insurer, or make it difficult for a patient to get their own health information. Some client-side encryption approaches, including S/MIME, require cumbersome key exchange before a recipient can read anything — poorly suited to the average patient. Ease of use is essential to adoption, and a control that staff route around protects nothing.
Only Use HIPAA-Compliant Apps, AI tools, and Integrations for PHI
Both platforms allow third-party apps and integrations, and many are not HIPAA compliant. Using a non-compliant app to process PHI can put you in violation even when the underlying platform is properly configured and covered by a BAA.
A transcription add-on, a scheduling connector, or an AI assistant that reads mailboxes may sit entirely outside your BAA while still interacting with PHI daily. The software supply chain is difficult to police, so a documented review of every app and integration that can reach PHI belongs in your compliance program — and it needs revisiting as staff install new tools.
What the Proposed HIPAA Security Rule Update Means for Encryption
If you've read that HIPAA now requires encryption, that isn't accurate yet, and the distinction matters for planning.
HHS's Office for Civil Rights published a proposed rule in January 2025 that would significantly modernize the HIPAA Security Rule. It would remove the long-standing distinction between "required" and "addressable" implementation specifications. Encryption of ePHI both at rest and in transit would become a requirement, alongside multi-factor authentication, an annually reviewed asset inventory and network map, and network segmentation.
That rule has not been finalized. It remains in the proposed stage, and the government's regulatory agenda has moved its target for final action to 2027. At the time of writing, encryption sits where it has since the Security Rule took effect: addressable under 45 CFR 164.312, meaning you must assess whether it's reasonable and appropriate and document your reasoning if you choose an alternative. "Addressable" has never meant optional, and a risk assessment that rejects encryption for email carrying PHI is difficult to defend.
Enforcement, meanwhile, has not waited for the rule. OCR's Risk Analysis Initiative — which targets organizations that failed to conduct thorough risk analyses — has produced a steady run of settlements, and encryption obligations are showing up directly in corrective action plans. In a July 2026 settlement, a health system agreed to a $552,250 penalty and to a corrective action plan that specifically requires encrypting ePHI in transit and at rest.
Encryption of PHI is already the defensible answer under the current rule. Building toward it now also means the proposed rule, if and when it lands, won't require a scramble.
How to Close the PHI Gap in Microsoft 365 and Google Workspace
Google Workspace and Microsoft 365 offer a great deal that healthcare organizations depend on. What neither provides by default is protection that stays with PHI after it leaves your tenant. Closing that gap is what separates a platform you can use for PHI from HIPAA compliant email and file sharing you can actually defend in an audit.
Virtru applies encryption to the data itself, before it leaves the sender's device, so protection travels with information regardless of storage location or sharing destination. These are self-protecting data objects that enforce their own access policies. Enforcement happens at the data layer, which means you keep control after delivery: set expiration, disable forwarding, watermark attachments, and revoke access to a message or file even after it's been read.
This is also integration rather than replacement. Staff keep working in Gmail or Outlook, and the security follows the data rather than asking anyone to change how they work.
For Google Gmail, Virtru for Gmail adds one-click protection inside the interface your staff already uses, with no encryption key setup required with third parties. Rules can be set for targeted groups and organizational units so protection applies automatically rather than depending on someone remembering. Patients and external recipients get secure web-based access, so there's no account to create and no software to install.
For Microsoft Outlook, Virtru for Microsoft Outlook takes a policy-first approach. It uses attribute-based access control to govern message content and attachments, enforces delivery based on recipient entitlements, supports classification tools like Microsoft Purview, and optionally protects messages and attachments with encryption. It deploys without changing your existing Microsoft 365 or Exchange configuration.
For files and records in any ecosystem, Virtru Secure Share handles encrypted files of nearly any size with anyone, inside or outside your organization, from the desktop or from cloud storage. Secure Share uses Virtru's FIPS 140-2 validated VirtruCrypto module (CMVP certificate #4440), and FIPS mode is available on request. Virtru Secure Share can be used in any browser.
For teams sharing sensitive files with external partners, Virtru Collaborate provides FedRAMP-authorized workspaces for storing, organizing, and sharing PHI files — ensuring those files retain persistent access control wherever they move.
Virtru for Google Drive protects non-Google-native files uploaded to Drive, including Word documents, Excel files, and PDFs, so Google cannot decrypt them. It works across Workspace subscription levels, which means you can raise your protection floor without moving the whole organization to a top-tier plan. For organizations that need to hold their own keys, Virtru Private Keystore keeps key custody with you rather than the cloud provider.
Virtru supports compliance with HIPAA through encryption, access control, and audit logging, and offers a BAA that defines clear responsibilities for protecting PHI. Section 5 of Virtru's SOC 2 Type II report maps HIPAA Security Rule requirements to the relevant controls, giving auditors evidence in a form they recognize. The report is available on request from your account manager. And because client-side encryption means Virtru cannot read your patients' protected content, PHI stays protected even from Virtru's own infrastructure.
No single tool can guarantee HIPAA compliance — compliance depends on your full program, from risk analysis to workforce training. But encryption and persistent access control are among the most defensible steps available, and they don't require re-platforming your organization.
We'd be glad to talk through your compliance needs and what it would take to protect PHI across your email and file sharing. Contact our team to schedule a demo and see Virtru in action.
Frequently Asked Questions
HIPAA compliance in your daily business applications
Gmail can be used in a HIPAA-compliant way when you accept Google's business associate amendment, restrict PHI to covered services, and configure the environment appropriately. Gmail is not HIPAA compliant on its own, and its default opportunistic TLS means messages can be delivered unencrypted if the receiving server doesn't support TLS.
Microsoft includes HIPAA business associate agreement terms by default through its Data Protection Addendum, covering services such as Exchange Online, SharePoint Online, OneDrive for Business, and Teams. As with Google, the platform supports HIPAA compliance but does not deliver it automatically — configuration, app governance, and encryption decisions remain your responsibility.
Not strictly, as of today. Encryption is an "addressable" implementation specification under 45 CFR 164.312, meaning you must assess whether it is reasonable and appropriate and document your rationale if you don't implement it. A proposed 2025 update to the Security Rule would make encryption a requirement, but it has not been finalized. Addressable does not mean optional, and encryption is increasingly appearing in OCR corrective action plans.
Yes. If PHI will be created, received, maintained, or transmitted on either platform, you need a business associate agreement in place first. Google's is accepted by an administrator in the Admin console; Microsoft's applies by default through its Data Protection Addendum. Confirm which services each agreement covers before putting PHI into a given tool.
TLS protects a message while it moves between mail servers, then stops, leaving the message readable in the recipient's mailbox. End-to-end encryption protects the message and its attachments themselves, so PHI stays encrypted at rest in the recipient's environment. Separately, Virtru's policy controls let the sender revoke access, set expiration, and disable forwarding after a message has been delivered.
SharePoint Online is included in Microsoft's list of services in scope for its BAA terms, so it can be part of a HIPAA-compliant environment when properly configured. The considerations that apply to email apply here too: provider-managed keys at rest, permissions that don't follow a file once downloaded, and third-party apps that may fall outside BAA coverage.
Editorial Team
The editorial team consists of Virtru brand experts, content editors, and vetted field authorities. We ensure quality, accuracy, and integrity through robust editorial oversight, review, and optimization of content from trusted sources, including use of generative AI tools.
View more posts by Editorial TeamSee Virtru In Action
Sign Up for the Virtru Newsletter
Dive Deeper
/BLOG%20-%20BLACK%20HAT%202026/black-hat-2026-learnings.webp)
Notes from Black Hat 2026: Data Sovereignty, the AI Harness, and a Billion-Dollar Signal

Google Client-Side Encryption for Workspace: A Guide to Your Options with Virtru

How to Encrypt Email in Outlook: Your Full Guide

AI Sovereignty isn't Something You Buy. It's Something You Build.
/blog%20-%20cyera%20oasis/cyera-oasis.webp)
The Coin Has Two Sides: What Cyera's Acquisition of Oasis Tells Us About the Future of Security

Virtru Collaborate vs. Box: Secure File Sharing for Businesses of Any Size
/blog%20-%20william%20mcborrough%20recap/cmmc-compass-will-mcborrough.webp)
The $600,000 Problem: What the CMMC Pause Actually Revealed About the Defense Industrial Base
/blog%20-%20three%20stories/three-stories.webp)
Last Week in Critical Infrastructure: Three Stories You Should Read as One
/blog%20-%20cmmc%20on%20hold/CMMC-Pause-CUI-Not.webp)
CMMC Phase II Is Officially on Hold. NIST and DFARS aren't.
/2026%20Newsletter%20Assets/jk-HIO.png)
We Asked Kindervag: Why Are So Many Organizations Still Getting Zero Trust Wrong?
Book a Demo
Become a Partner
Contact us to learn more about our partnership opportunities.
Become a Compliance Champion
Contact us to learn more about our partnership opportunities.