Is Google Gemini HIPAA compliant?
YesGoogle · AI assistants
Yes. Google will sign a Business Associate Agreement (BAA) for Google Gemini, usually on an enterprise plan, which is the baseline requirement for handling PHI.
What we checked
This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.
- Business Associate Agreement
- Confirmed
- Google publishes a BAA option. Confirm the exact plan and service are covered before sending PHI.
- Enterprise route
- Google Workspace with Gemini (Business/Enterprise)
- For regulated use, validate the BAA, configured service and users under the Google Workspace with Gemini (Business/Enterprise) contract.
- Default data training
- Opt-out required
- On consumer Gemini Apps (personal Google accounts), activity is used to improve Google services and a subset is human-reviewed unless Gemini Apps Activity is turned off.
- Business-tier training
- No by default
- Google Workspace with Gemini does not use customer content to train models outside the customer's domain and content is not human-reviewed.
Practical risk: Personal Gemini accounts have human reviewers reading a sample of chats (kept up to 3 years even after you delete activity), so confidential work content typed into a personal account can be seen by reviewers.
How to make a decision
Check the precise account tier, written contract and intended data before approving Google Gemini. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.
More on Google Gemini
Is Google Gemini GDPR compliant?Is Google Gemini SOC 2 compliant?Is Google Gemini ISO 27001 certified?Does Google Gemini train on your data?
See the full Google Gemini risk profile, with every data-handling fact and its source, or browse all rated AI tools.