HIPAA-Compliant AI Tools
Is Gemini HIPAA compliant?
By Mat Steinlin, Head of Information Security
Last updated: July 2026
Google's AI products span several distinct surfaces with different compliance postures. Gemini Enterprise Agent Platform (which is the evolution of Vertex AI and now the home for all Google Cloud model and agent development) is HIPAA-eligible under Google's standard cloud BAA. The consumer Gemini product at gemini.google.com has no BAA coverage. Gemini for Google Workspace sits in between, with coverage that depends on your Workspace plan and configuration.
The Google AI product landscape
Product | BAA coverage | Notes |
|---|---|---|
Gemini.google.com (consumer) | No | Consumer product. Do not use with PHI. (Source) |
Google AI Studio | No | Developer prototyping tool. Not for production PHI workloads. (Source) |
Gemini Enterprise Agent Platform (formerly Vertex AI) | Yes | HIPAA-eligible service under Google Cloud BAA. (Source) |
Gemini for Google Workspace | Partial | Depends on Workspace plan and configuration. Specific features (Help me Write, smart replies, side panel) are covered; third-party add-ons are not. (Source) |
Google NotebookLM | No | Not on Google's HIPAA-covered products list. Teams with a Workspace BAA may assume it is covered; it is not. (Source) |
Firebase App Hosting | No | Not HIPAA-eligible. Firebase Auth must be replaced with Identity Platform for compliant deployments. (Source) |
Google Cloud Healthcare API | Yes | HIPAA-eligible service under Google Cloud BAA. (Source) |
Google AI Studio and Gemini Enterprise Agent Platform both provide access to Gemini models, but they are different products with different compliance postures. Google AI Studio is a prototype and exploration environment, not appropriate for production workloads involving PHI, and it has no BAA coverage. Gemini Enterprise Agent Platform is Google Cloud's production platform and the evolution of Vertex AI (which is covered).
Gemini Enterprise Agent Platform: the right path for production AI workloads
Gemini Enterprise Agent Platform, the evolution of Vertex AI and now the home for all Google Cloud model selection, model building, and agent development, is a HIPAA-eligible service under Google's Cloud BAA.
How to activate HIPAA coverage:
Google Cloud's BAA process is self-serve. Accept the Google Cloud HIPAA Business Associate Addendum directly in the Cloud Console under IAM & Admin; no separate sales negotiation required for most customers.
Once your Google Cloud BAA is in place, Gemini Enterprise Agent Platform is covered as an eligible service. Before enabling new models or features for PHI workloads, confirm they appear in Google's current HIPAA covered products list, as new features may not be covered automatically.
Data handling: Google Cloud's data processing terms govern how customer data is handled. For specific no-training commitments, review your service-specific terms and the Google Cloud Data Processing Addendum; data handling terms vary by service configuration.
Data residency: Gemini Enterprise Agent Platform supports regional deployment, which matters for healthcare organizations with specific data residency requirements. See Data residency in healthcare AI systems for the full framework.
Gemini for Google Workspace: the plan matters
Many healthcare organizations have Google Workspace with an existing Google BAA. The assumption that Gemini AI features within Workspace are automatically covered under that BAA is often wrong.
Gemini for Workspace is a separate add-on to Google Workspace. Coverage under HIPAA depends on:
Your Workspace plan. Gemini for Workspace with HIPAA-eligible configuration is available on Workspace Enterprise plans. Business plans have different coverage terms.
Whether you've signed a Google Workspace BAA. Administrators must accept the BAA via the Workspace Admin Console before handling PHI. Customers who have not signed a BAA must not use PHI in Workspace services.
Which Gemini features are in use. Specific Gemini features are confirmed covered: Help me Write, contextual smart replies, and the side panel. Third-party applications and add-ons are explicitly not covered under the Workspace BAA, regardless of plan.
Before allowing clinical staff to use Gemini features in Gmail, Docs, or Meet for any work involving patient data, verify your plan includes HIPAA coverage and that you've signed the Workspace BAA. Do not assume that a Workspace BAA covers third-party add-ons or extensions.
Consumer Gemini: not covered
Gemini.google.com and the Gemini mobile app are consumer products. There is no BAA path for consumer Gemini. Healthcare workers using these tools for clinical work (summarization, documentation, analysis) are using a product that is explicitly not covered, regardless of what other Google products your organization has contracted for.
This is the same pattern that appears with every major AI vendor: the consumer product and the enterprise product look similar to the end user. The compliance boundary is not visible from the interface.
What Google's BAA and HIPAA compliance guide require of you
Google's HIPAA compliance guide is published as part of the BAA process and describes both essential and recommended requirements. The Google Workspace BAA explicitly requires customers to "use controls available within the Services, including those detailed in the HIPAA Implementation Guide" and states customers are "solely responsible for ensuring that its and its End Users' use of the Covered Services complies with HIPAA.”
Use only covered products for PHI. You must not use Google Cloud products that are not explicitly on the HIPAA-eligible covered products list when working with PHI. The list is updated as Google adds new services; verify before enabling any new product for PHI workloads.
Pre-GA features are excluded. Do not use pre-GA features or products offered under the Google Cloud Pre-General Availability Program in connection with PHI, unless expressly permitted.
Audit log export. You are responsible for configuring audit log export destinations. Google strongly recommends exporting audit logs to Cloud Storage for long-term archival and to BigQuery for analytical and forensic needs. Configure appropriate access controls for log destinations.
Metadata hygiene. PHI must not appear in resource metadata, including: resource labels, VM labels/annotations, GKE resource annotations, Cloud Monitoring metric labels, dashboard titles or content, alerting configurations, Integration Parameter names, Connection Names or Connection Configurations, or Cloud Build config files. Metadata may be captured in logs and could be visible to anyone with IAM permissions to view your monitoring console.
Specific product restrictions. Cloud Speech-to-Text customers must not opt into the data logging program. Cloud CDN customers must not request caching of PHI. API Gateway headers must not contain PHI.
IAM best practices required. Service accounts can access resources; access to service accounts and service account keys must be tightly controlled.
What Google's BAA doesn't cover
Signing a Google Cloud BAA defines Google's obligations. It doesn't define yours. The logging, encryption, key management, and access controls that HIPAA requires of your application are outside the scope of what any vendor BAA covers.
See What an AI BAA actually covers for the full breakdown.
What you still need to build
The compliance infrastructure layer applies to Gemini Enterprise Agent Platform the same way it applies to every LLM vendor in this guide: audit logging of every model interaction involving PHI, encrypted storage of those logs, six-year retention, key management, and access controls.
FAQs
Is Gemini HIPAA compliant?
It depends on which product. Gemini Enterprise Agent Platform (Google Cloud's production AI platform, formerly Vertex AI) is HIPAA-eligible under Google's standard cloud BAA. Consumer Gemini at gemini.google.com has no BAA and is not appropriate for PHI. Gemini for Workspace coverage depends on your plan and whether you've signed the Workspace BAA.
Is Gemini Enterprise Agent Platform (formerly Vertex AI) covered under Google's HIPAA BAA?
Yes. Gemini Enterprise Agent Platform is listed as a HIPAA-eligible service under the Google Cloud BAA. Accept the BAA through the Cloud Console under IAM & Admin.
Does my Google Workspace BAA cover Gemini?
Specific Gemini features are covered: Help me Write, contextual smart replies, and the side panel. Third-party add-ons and extensions are explicitly not covered. Your Workspace BAA must be signed by an administrator via the Admin Console before handling PHI.
How do I enable HIPAA-compliant usage of Gemini Enterprise Agent Platform?
Accept the Google Cloud HIPAA Business Associate Addendum in the Cloud Console under IAM & Admin. No separate sales negotiation required for most customers. Then confirm Gemini Enterprise Agent Platform appears in the current covered products list before routing PHI through it.
Is Google AI Studio HIPAA compliant?
No. Google AI Studio is a developer prototyping environment with no BAA coverage. Use Gemini Enterprise Agent Platform for production workloads involving PHI.
Does Google train on my data when using Gemini Enterprise Agent Platform?
Review your service-specific terms and the Google Cloud Data Processing Addendum for the specific commitments that apply to your configuration. As with any vendor, your signed BAA is the legally binding document, not a policy page.
What's next
For teams choosing between Google Cloud and Azure for AI model access, see Azure OpenAI for the comparable Microsoft BAA path.
For data residency requirements that are particularly relevant for Gemini Enterprise Agent Platform deployments, see Data residency in healthcare AI systems.
For teams managing BAAs across multiple AI vendors, see Managing BAAs across multiple AI vendors.
__
Google's BAA covers Google's infrastructure. The audit logging, encrypted log retention, and access controls that HIPAA requires on top of it are still yours to implement. For teams on Google Cloud who want those handled as a managed service, Aptible LLM Gateway provides the compliance layer with one Aptible BAA covering all supported models. Talk to an engineer to see if it fits.