Purpose
This article summarizes the Google HIPAA Business Associate Addendum (BAA) that AUSD has in effect for Google Workspace / Cloud Identity. It explains what the BAA covers, what Google is responsible for, and what the District is responsible for. Use it as a plain-language reference — it does not replace the signed agreement or legal counsel.
Record of acceptance: Accepted by
[email protected]on Jul 31, 2020, in the Google Admin console under Account → Account settings → Legal & compliance → Security and Privacy Additional Terms.
What a BAA is
A Business Associate Addendum is a HIPAA-required contract between a Covered Entity (or Business Associate) and a vendor that handles Protected Health Information (PHI) on its behalf. It supplements the existing Google Services Agreement and governs both parties' obligations for PHI. It is only valid while an active Services Agreement is in place.
Scope — what it covers
- Applies only to "Covered Services." These are the specific Google products listed as "Included Functionality" in Google's HIPAA functionality terms. PHI stored or transmitted outside those services (offline tools, on-prem storage, third-party apps) is not covered.
- Applies only to PHI within Customer Data that Google can access through the Covered Services.
- Applies when AUSD acts as a Covered Entity or Business Associate and Google, as a result, acts as a Business Associate or Subcontractor.
Google's obligations
- Use/disclosure limits. Google may use and disclose PHI only as permitted by the Services Agreement, this BAA, or as required by law. It may use PHI for its own proper management/administration only under strict conditions (legal requirement, or written assurances of confidentiality).
- Safeguards. Google will use appropriate safeguards to prevent unauthorized use or disclosure of PHI.
- Breach reporting. Google will promptly notify AUSD after discovering a Security Breach, sent to the notification email on file. Routine unsuccessful access attempts are covered by a blanket notice and are not individually reported.
- Breach mitigation. Google will use commercially reasonable efforts to mitigate harm from a breach it caused.
- Subcontractors. Any subcontractors with PHI access must be bound to the same material protections. Google stays responsible for their performance.
- Access & amendment. Google provides AUSD access to its PHI via the Covered Services so AUSD can meet HIPAA access/amendment obligations.
- Accounting of disclosures. Google documents its PHI disclosures and provides an accounting as required.
- Government access. Google will make relevant records available to the U.S. Department of Health and Human Services (HHS) Secretary to determine compliance.
- Return/destruction. On termination of the Services Agreements, Google returns or destroys PHI, or extends BAA protections if that is not feasible.
AUSD's obligations
- Use PHI only within Covered Services. AUSD is solely responsible for managing whether end users may share, create, or use PHI in the Covered Services.
- No impermissible requests. AUSD will not ask Google to use or disclose PHI in any way that would violate HIPAA.
- Configure correctly. AUSD must use available controls, including those in Google's HIPAA Implementation Guide, to keep PHI within the Covered Services. The Implementation Guide is informational — AUSD is solely responsible for ensuring its own and its end users' use complies with HIPAA.
- Minimum necessary. Limit PHI use to the minimum needed for authorized purposes.
- Consents & permissions. AUSD warrants it has obtained all consents/authorizations required to disclose PHI to Google, and will notify Google of changes or revocations.
Termination
- The BAA ends at the earlier of a permitted termination or the expiration/termination of all Services Agreements granting access to a Covered Service.
- Either party may terminate for a material breach on 10 days' written notice if the breach is not cured. If cure is not possible, the non-breaching party may terminate immediately or report the violation to the HHS Secretary.
- If the BAA ends before the Services Agreements, AUSD may keep using the Services but must delete any PHI it holds in the Covered Services and stop sending PHI to Google.
Quick reference
| Item | Detail |
|---|---|
| Agreement | Google Workspace / Cloud Identity HIPAA Business Associate Addendum |
| Accepted by | [email protected] |
| Acceptance date | Jul 31, 2020 |
| Location | Google Admin → Account → Account settings → Legal & compliance |
| Covers | PHI within Google "Covered Services" only |
| Excludes | PHI outside Covered Services (offline, on-prem, third-party apps) |
| Google's role | Business Associate / Subcontractor |
| AUSD's role | Covered Entity / Business Associate |
| Breach notice sent to | Notification email on file in Services Agreement |
| Config responsibility | AUSD (per HIPAA Implementation Guide) |
| Compliance oversight | HHS Secretary access to records |
| Termination for breach | 10 days' written notice / cure period |
Notes
- Configuration is on AUSD, not Google. Having the BAA in place does not by itself make any workflow HIPAA-compliant. AUSD must configure the Covered Services and limit PHI to them.
- The BAA is only valid while an active Google Services Agreement exists.
- This is a plain-language summary. For binding terms, refer to the executed BAA and Google's referenced HIPAA functionality terms and Implementation Guide. Consult counsel for legal questions.
- Reference links in the agreement: HIPAA Included Functionality (
gsuite.google.com/terms/2015/1/hipaa_functionality.html) and HIPAA Implementation Guide (Google-hosted PDF).

