Is Google Voice HIPAA Compliant?

The answer depends on which version of Google Voice you use — and most healthcare professionals use the one that isn't compliant.

Get started for free
Yes, with conditions

Consumer Google Voice is not HIPAA compliant — Google does not offer a BAA for free personal Google Voice accounts. Google Voice for Google Workspace is conditionally compliant: it is listed as HIPAA Included Functionality under the Workspace BAA, but only on eligible editions (Business Standard, Business Plus, or Enterprise) with a separately purchased Voice add-on, an admin-accepted BAA, and significant security configuration.

Why?

No BAA for consumer Google Voice

Google does not offer a Business Associate Agreement for free or personal Google Voice accounts. Without a BAA, any use of consumer Google Voice for protected health information violates HIPAA — regardless of how the service is configured.

Source: Google HIPAA Included Functionality

Workspace BAA available only on eligible editions

Google lists Google Voice (managed users only) as HIPAA Included Functionality under the Google Workspace BAA. However, the BAA is available only on Business Standard, Business Plus, and Enterprise editions — not Starter or free tiers. The Voice add-on itself costs $10–$30 per user per month on top of the Workspace subscription.

Source: Google HIPAA Included Functionality

SMS metadata transits carrier networks

Google Voice SMS messages traverse third-party carrier networks where Google has limited control over encryption and metadata logging. Message metadata — who texted whom and when — may be retained by carriers outside the scope of Google's BAA.

Source: Google Workspace HIPAA BAA

Voicemail transcriptions contain PHI

Google Voice automatically transcribes voicemails using AI. These transcriptions may contain protected health information and are covered under the Workspace BAA, but transcription accuracy is not guaranteed. Inaccurate transcripts that are retained as records could create compliance risk.

Source: Google Workspace HIPAA BAA

Default settings do not meet HIPAA requirements

Even with an eligible Workspace edition and a signed BAA, Google Voice does not ship HIPAA-ready. Administrators must configure two-factor authentication, mobile device management, Google Vault retention policies, data loss prevention rules, and sharing restrictions. Google's own implementation guide states that default settings do not satisfy HIPAA requirements.

Source: Google Workspace HIPAA compliance

What Google Voice says

Google's HIPAA Included Functionality page lists "Google Voice (managed users only)" as a Covered Service under the Workspace BAA. The BAA defines Covered Services as products listed on that page and requires Google to give 12 months' notice before removing any service.
Source: Google HIPAA Included Functionality

What you would need to configure

Required plan: Google Workspace Business Standard, Business Plus, or Enterprise — plus a Google Voice add-on license ($10–$30/user/month)

  1. Provision an eligible Google Workspace edition (Business Standard, Business Plus, or Enterprise)
  2. Purchase and assign Google Voice add-on licenses for users who will handle PHI
  3. Accept the HIPAA Business Associate Agreement in the Google Admin console (Admin Console → Account → Legal and compliance)
  4. Enforce two-factor authentication for all users
  5. Configure mobile device management policies to enable remote wipe of devices with ePHI
  6. Set up Google Vault retention policies for Voice text messages, voicemails, and call logs
  7. Configure Data Loss Prevention rules to prevent PHI from being shared outside approved channels
  8. Restrict external sharing and disable non-covered Google services for users handling PHI

Requires IT staff to configure and maintain Google Workspace security settings, Vault policies, and DLP rules. The combined cost of Workspace ($12–$25/user/month) plus Google Voice add-on ($10–$30/user/month) means $22–$55 per user per month before any configuration effort. Not a one-time setup — policies need ongoing review as Google updates features and defaults.

HIPAA-compliant alternatives

BloomText

Purpose-built HIPAA messaging with a signed BAA on every plan, including the free plan. Cross-organization messaging is free — no Workspace subscription or Voice add-on required.

Spruce Health

HIPAA-compliant communication platform for medical practices with secure messaging, phone, fax, and telehealth in one system.

OhMD

Patient texting platform with EHR integrations, call-to-text, and website chat for practices that need broader patient communication tools.

Frequently Asked Questions

Is Google Voice HIPAA compliant?

Not in its free or consumer form. Google Voice for Google Workspace is listed as HIPAA Included Functionality, but only on Business Standard, Business Plus, or Enterprise editions with a signed BAA and admin configuration. Most individual healthcare professionals using Google Voice are on the free consumer version, which has no path to HIPAA compliance.

Does Google sign a BAA for Google Voice?

Only for Google Voice within eligible Google Workspace editions. The BAA is accepted by a super administrator in the Google Admin console. Consumer Google Voice — the free version tied to a personal Google account — is not covered by any BAA.

Can I use free Google Voice for patient communication?

No. Free Google Voice is not HIPAA compliant and Google will not sign a BAA for it. Using free Google Voice to discuss patients, share lab results, or transmit any protected health information violates HIPAA.

How much does HIPAA-compliant Google Voice cost?

Google Workspace Business Standard starts at $12 per user per month, and the Google Voice add-on starts at $10 per user per month — totaling at least $22 per user per month before configuration effort. Compare this to BloomText, where cross-organization messaging is free with a signed BAA included.

Sources

Last verified May 29, 2026.

  1. BloomText pricing
  2. Google HIPAA Included Functionality
  3. Google Workspace HIPAA BAA
  4. Google Workspace HIPAA compliance
  5. HHS HIPAA Security Rule

Need HIPAA-compliant messaging?

Get started for free

Trusted by today's leading healthcare professionals

Streamlined appointment schedulingWith BloomText Broadcast SMS Messaging, I literally took the job of 20 employees and I can do it by myself in three and a half hours.Chief Administrative Officer, Radiology
Best HIPAA app on the marketBloomText has brought our clinic into the modern age, and our patients love being able to communicate with us via text or through our website.Office Administrator, Family Medicine
Excellent for acute careBloomText is the nervous system for my business. It helps us differentiate ourselves in terms of our communication and our quality of care.Clinical Director, Acute Care