Phone/Fax BAA Guide

Is Google Voice HIPAA compliant?

Google Voice is a telephone service that provides call forwarding, voicemail, voice and text messaging services. It's a popular choice due to its integration with other Google services, affordable international calling rates, and the ability to ring multiple devices with one phone number. Users can access the service across devices, including computers and smartphones, making it a flexible solution for communication needs. Another notable feature is its voicemail transcription service which converts voice messages into text.

Google Voice in healthcare

In a healthcare context, Google Voice can support a range of communication workflows. For telehealth, it provides a convenient way for providers and patients to communicate via calls or text messages — appointment reminders, follow-ups, and brief consultations. Google Voice's voicemail transcription service can be helpful to healthcare providers, allowing them to review patient messages more efficiently. Google Voice can also be used for internal communication within the healthcare team, improving coordination and collaboration.

Google Voice and HIPAA compliance

Google Voice can be HIPAA compliant, but only under specific conditions. Google will sign a Business Associate Agreement (BAA) that covers Google Voice as part of Google Workspace — however, Google Voice is only included under the BAA when used with a Google Workspace for Healthcare plan or an eligible Workspace edition, and only the Google Voice for Google Workspace product (not the free consumer version of Google Voice) is covered.

Free Google Voice vs. Google Voice for Workspace

This distinction is critical and often misunderstood:

Free Google VoiceGoogle Voice for Workspace
BAA availableNoYes (via Workspace BAA)
HIPAA compliantNoYes (when configured)
Audit loggingNoYes
Admin controlsMinimalFull Workspace Admin

Using the free, consumer version of Google Voice for PHI is not HIPAA compliant — Google's BAA does not cover it.

Requirements for HIPAA-compliant Google Voice use

To use Google Voice in a HIPAA-compliant manner:

  1. Use Google Voice as part of a Google Workspace subscription (not the free consumer product)
  2. Execute the Google Workspace BAA with Google
  3. Configure Google Voice settings per your organization's security policies
  4. Ensure users are on managed, organization-controlled Google Workspace accounts — not personal Gmail or Google accounts

Google employs strong security measures including encryption in transit and at rest, two-factor authentication, and detailed audit logs across Workspace services. Further information on Google Voice's approach to HIPAA compliance can be found in Google's HIPAA Compliance Guide.

Frequently asked questions

Is Google Voice HIPAA compliant? Google Voice can be HIPAA compliant when used as part of Google Workspace with a signed Business Associate Agreement (BAA). The free consumer version of Google Voice is not covered by the Workspace BAA and is not HIPAA compliant.

Does Google sign a BAA for Google Voice? Yes, Google will sign a BAA for Google Voice as part of the Google Workspace BAA — but only for Google Voice for Workspace, not the free consumer product.

Can I use Google Voice for patient calls? You can use Google Voice for Workspace for patient calls involving PHI, provided you have the Workspace BAA in place and are using an eligible Workspace plan. Free Google Voice cannot be used for patient calls involving PHI.

What phone systems are HIPAA compliant? HIPAA-compliant phone and VoIP options include Google Voice for Workspace (with BAA), RingCentral (with BAA), Vonage Business (with BAA), and iplum (with BAA). Each requires a signed BAA and proper configuration before use with PHI.

Staying HIPAA Compliant

Take a look at our ultimate guide to HIPAA compliant software and services for help selecting compliant service providers. Though careful vendor evaluation and selection is only one piece of the puzzle for maintaining HIPAA compliance. At TeachMeHIPAA, we offer an affordable HIPAA training solution to ensure your staff are knowledgeable in how to comply, and to help you meet your legally mandated HIPAA training requirement with ease. Learn more about our tips and tricks for maintaining compliance with our HIPAA compliance blog.