Need IT help now? Call (321) 221-7117 — We respond within 2 hours.

Need IT help? Help Desk Request Assistance Get in Touch
Medical IT

Microsoft 365 vs Google Workspace for Medical Practices: The HIPAA Side

Oct 9, 2026·5 min read·By Ric Acevedo

Is Microsoft 365 or Google Workspace better for a medical practice?

In the Microsoft 365 vs Google Workspace decision, both can be used for patient information under HIPAA, and neither is “HIPAA compliant” out of the box. The practical difference is in the plan you buy: Microsoft 365 Business Premium bundles device management, endpoint protection, email encryption and archiving in one plan, while Google Workspace keeps several of those features in its Enterprise editions. Whichever you choose, the setup decides whether you are protected.

This comparison covers the HIPAA and security side only, for a practice of roughly 5 to 30 people, based on Microsoft’s, Google’s and HHS’s own documentation as of October 2026. It does not cover pricing.

Do Microsoft and Google sign a Business Associate Agreement?

Yes, both do, but differently. HHS is clear that a cloud provider storing patient information is a business associate, “even if the CSP processes or stores only encrypted ePHI and lacks an encryption key,” and that a BAA is required (HHS cloud computing guidance). HHS also does not certify any product, so no email platform is “HIPAA certified.”

  • Microsoft 365: the BAA is included by default in Microsoft’s Data Protection Addendum for customers who are covered entities or business associates (Microsoft HIPAA documentation). It covers the core services, including Exchange, OneDrive, SharePoint, Teams, Entra ID and Intune.
  • Google Workspace: an administrator has to review and accept the BAA in the Admin console before any patient information goes in. Google’s words: “Customers who have not signed a BAA with Google must not use PHI” (Google Workspace HIPAA guide). It covers the services on Google’s “Included Functionality” list, such as Gmail, Drive, Calendar, Chat and Meet. Add-ons, other Google services and pre-release features are not covered.

On AI: Microsoft’s BAA lists Microsoft Copilot and Copilot Chat as covered. Google’s covers Gemini in Workspace and the Gemini app, but not Gemini in Chrome (Google HIPAA services list). Check the list before staff use any AI feature with patient details.

How do Microsoft 365 and Google Workspace compare on security features?

Microsoft 365 (Business plans)Google Workspace
Getting the BAAIncluded by defaultAdmin accepts it in the console
Multi-factor authenticationSecurity defaults on all Business plans; Conditional Access only on Business Premium2-Step Verification on all editions; Context-Aware Access only on Enterprise
Device managementBasic on all plans; Intune on Business PremiumBasic on all editions; advanced and Windows management on Business Plus
Endpoint protectionDefender for Business on Business PremiumNot included
Email encryptionPurview Message Encryption on Business Premium (add-on for Basic and Standard)S/MIME and client-side encryption on Enterprise Plus
Data loss preventionEmail and file DLP on Business PremiumGmail and Drive DLP on Enterprise editions
Retention and legal holdArchiving and Litigation Hold on Business Premium (add-on for Basic and Standard)Vault on Business Plus and Enterprise
Audit logsAudit (Standard) on all Business plansAudit and investigation tool on all editions

Sources: Microsoft’s Business Premium security overview and Purview licensing guidance; Google’s Business and Enterprise edition comparisons.

The pattern for a small practice: on Microsoft, Business Premium is the plan that covers most of what a HIPAA risk assessment will ask about. On Google, Business Plus adds Vault and stronger device management, but encryption and DLP sit in the Enterprise editions. That does not make Google worse; it means you budget for the edition that matches your risks, or cover the gaps with other tools.

Which platform protects a practice’s email domain better?

Neither, by default, and this is where we see the biggest real-world gap. Neither platform publishes a DMARC record for your domain automatically, and both need DKIM signing switched on for a custom domain: Microsoft states that “no DKIM signing occurs for outbound mail from custom domains” until you enable it (Microsoft DKIM guide), and Google requires an admin to generate a key and publish it (Google DKIM guide).

When we checked 1,101 businesses for our Polk County email security report, 84% of those using Google Workspace and 48% of those using Microsoft 365 could be impersonated by email, and 61% of medical, dental and health businesses overall. The platform was not the cause; the setup was never finished. For a practice, a forged email from your domain can be a fake billing request to a patient or a fake referral to another office. Our free email spoofing check tells you in seconds where your own domain stands.

What should a practice set up first on either platform?

  1. Get the BAA in place: confirm Microsoft’s is in effect, or accept Google’s in the Admin console, before patient information goes in.
  2. Turn on multi-factor authentication for every account, including the owner’s and any shared front-desk mailbox. Microsoft already requires it for its admin portals; HHS has proposed making it mandatory under the Security Rule.
  3. Switch on DKIM and publish DMARC, then move DMARC to enforcement once reports show your legitimate senders pass.
  4. Lock down sharing: decide whether files can be shared outside the practice and with whom, and restrict “anyone with the link” sharing.
  5. Manage the devices that open patient email, including staff phones (see our guide to personal phones and HIPAA).
  6. Set retention and backups, because neither platform’s recycle bin is a backup.
  7. Write it into your risk assessment: the platform, the BAA, and which safeguards you turned on. Our HIPAA risk assessment guide includes a free worksheet.

Should a practice switch from one to the other?

Usually not for HIPAA reasons alone. Both can be configured properly, and a migration costs staff time and carries its own risk. Switching makes sense when the practice’s other software pushes you one way, for example an EHR or phone system that integrates with Outlook and Teams, or when the features you need are only affordable on the other platform’s plans. If you are setting up from scratch, Microsoft 365 Business Premium is the simpler single plan for most small practices because it bundles device management, endpoint protection, encryption and archiving; Google Workspace suits practices already built around Gmail and Drive that are willing to fill those gaps.

Not Sure Your Setup Would Pass?

Take our free three-minute HIPAA readiness check for a score and your top gaps. iTech Plus provides HIPAA-compliant IT services and Microsoft 365 management for medical and dental practices across Polk County, including Lakeland and Winter Haven. For a full review, we offer a free IT assessment with a written report. Call (321) 221-7117 or email info@itechplus.co.

General information based on vendor documentation as of October 2026, not legal advice. Plan features change; confirm against current vendor terms.

Recent Articles

What Does a HIPAA Risk Assessment Actually Involve for a Small Practice?
Medical IT
What Does a HIPAA Risk Assessment Actually Involve for a Small Practice?
Oct 2, 2026
eClinicalWorks Alternatives for Small Practices: The IT Side of Switching
Medical IT
eClinicalWorks Alternatives for Small Practices: The IT Side of Switching
Oct 2, 2026
Is VoIP HIPAA Compliant? What a Medical Practice's Phone System Actually Needs
Medical IT
Is VoIP HIPAA Compliant? What a Medical Practice's Phone System Actually Needs
Sep 29, 2026
Can Front Desk Staff Use AI to Write Patient Emails?
Medical IT
Can Front Desk Staff Use AI to Write Patient Emails?
Aug 26, 2026
Can a Law Firm Use ChatGPT Without Breaching Confidentiality?
Medical IT
Can a Law Firm Use ChatGPT Without Breaching Confidentiality?
Aug 26, 2026

Related posts

Digital Business Card