ModelCharter

Is Gemini Code Assist HIPAA compliant?

Unverified

Google · Coding

Not verified. Check directly with Google before using Gemini Code Assist with protected health information (PHI).

What we checked

This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.

Business Associate Agreement
Not verified
No public BAA was confirmed. Treat PHI use as blocked until Google provides written terms.
Enterprise route
Gemini Code Assist Standard or Enterprise (not the free Individual tier)
For regulated use, validate the BAA, configured service and users under the Gemini Code Assist Standard or Enterprise (not the free Individual tier) contract.
Default data training
Opt-out required
For individuals (free tier), prompts, code and output are collected to improve Google products, with human review, and disconnected copies stored up to 18 months.
Business-tier training
No by default
Standard and Enterprise: Google does not use your data to train its models without your permission, and prompts and responses are handled statelessly (not stored).
Practical risk: On Standard and Enterprise, Gemini Code Assist is not trained on without permission, is stateless, and carries SOC 1/2/3 and ISO 27001 with VPC Service Controls. The free Individual tier is different: code and prompts are collected to improve Google products with human review and up to 18-month retention.

How to make a decision

Check the precise account tier, written contract and intended data before approving Gemini Code Assist. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.

More on Gemini Code Assist

See the full Gemini Code Assist risk profile, with every data-handling fact and its source, or browse all rated AI tools.