Is Gemini HIPAA Compliant?
Three products share one name. One of them warns you not to enter confidential information at all. Route matters more than model.
The Verdict: Is Gemini HIPAA Compliant?
Is Gemini HIPAA compliant? Yes, with conditions. Gemini falls under the Workspace BAA on managed domains and under the Cloud BAA, never on personal accounts.
Three routes, three answers. Personal Gemini: no BAA, never for PHI. Managed Workspace: covered, minus Gemini in Chrome. Google Cloud: covered by named product.
Google's consumer privacy notice tells users not to enter confidential information, because reviewers may read conversations.
Verified against Google's Workspace HIPAA Included Functionality list and the Cloud BAA list, July 2026.
| Route | BAA | Trains on your data | Verdict for PHI |
|---|---|---|---|
| Gemini app, personal account (free or paid) | No | Consumer terms; human review possible | Never, by Google's own warning |
| Gemini under a managed Workspace account (domain with BAA) | Yes: Gemini app (excluding Gemini in Chrome), Gemini Mac App, and Gemini in Workspace are in Google's HIPAA Included Functionality list | No; Workspace enterprise protections apply | Possible; confirm your edition includes Gemini and note the Chrome exclusion |
| Google Cloud (covered generative AI products under the Cloud BAA) | Yes, self-serve Cloud BAA, product-enumerated | No (contractual training restriction) | Possible for built applications, per named covered product |
This is not legal advice, and your counsel makes the call for your organization.
The Naming Trap
The Cloud route inherits the same naming trap that runs through every HIPAA-and-AI question. The BAA covers named products, Google renames products often, and the live covered-products list is the only source that counts at contract time.
The Consumer App Risk Is Not Hypothetical
Four reasons the free Gemini app keeps showing up in places it should not
Google says it plainly
The consumer privacy notice tells users not to enter confidential information because reviewers may process conversations. For PHI, that is a disclosure to human third parties, not just a server.
The same icon, three postures
Staff see "Gemini" on their phone, in Gmail, and in a Cloud console, and reasonably assume one policy covers them. Your acceptable use policy has to name the routes separately.
Workspace coverage follows the domain, not the person
Gemini under your organization's Workspace BAA protects work accounts in covered editions. The same clinician in a personal Gmail tab is on route one.
Android makes the consumer route ambient
Gemini ships as the system assistant on modern Android phones, which puts route one a long-press away from every clinical hallway conversation. No install, no approval, no decision anyone would remember making, which is what makes route one the quietest one on this page. AI preinstalled on the phone does not show up in a software inventory, and naming the routes in policy is a different job from finding out which route people took.
Gemini and HIPAA: Common Questions
Does Google sign a BAA covering Gemini?
Yes, with conditions. The Workspace BAA's Included Functionality list names the Gemini app, Gemini Mac App, and Gemini in Workspace, excluding Gemini in Chrome. The Cloud BAA covers named generative AI products. No BAA covers personal Gemini accounts.
Is the free Gemini app HIPAA compliant?
No. No BAA, and Google's guidance is to not enter confidential information into it. That guidance is the answer.
Does Gemini train on our data?
Consumer app: activity can be used to improve services per consumer terms. Workspace and Cloud: Google states customer data is not used to train models without permission, backed by contract. Route decides the answer.
Is Gemini in Gmail and Docs safe for patient information?
Google's HIPAA guidance covers help me write, contextual smart replies, and side-panel features as part of Workspace with Gemini. Inside a covered domain on an eligible edition, yes, with controls. Outside that, treat it as the consumer app.
How does Gemini compare with ChatGPT and Copilot for healthcare?
All three follow the same law: consumer tiers never, enterprise tiers conditionally, and your controls decide the rest. See our comparison for Microsoft Copilot.
Is this legal advice?
No. This is not legal advice, and your counsel makes the call for your organization.
Related Reading
AI Tool HIPAA Compliance Directory
BAAs, training policies, and verdicts for the AI tools your staff actually use, in one place.
Read article →Is ChatGPT HIPAA Compliant?
Consumer, Plus, Team, and Enterprise tiers each answer differently.
Read article →Is Claude HIPAA Compliant?
What Anthropic's BAA covers, what it excludes, and where PHI still leaks.
Read article →Name the Routes Before Staff Pick One for You
Your policy has to distinguish the Gemini your organization licensed from the one on every phone. Generate a healthcare-ready draft in minutes.