Compliance

Is Gmail HIPAA compliant? Email rules for NEMT offices that handle rider details

Updated 7 min read

Overview

Free Gmail is not. Google's HIPAA business associate agreement covers Gmail only inside a Google Workspace account, and a super administrator must accept it in the Admin console before any rider details go into Gmail. Even then, only the services on Google's covered list may hold that information. Microsoft works the same way: Exchange Online in Microsoft 365 business plans is covered, and free Outlook.com is not.

On this page

Free Gmail is not HIPAA compliant for rider details, and no setting can make it so. Google’s business associate agreement covers Gmail only for Google Workspace customers, who accept it in the Admin console. With that agreement accepted, Gmail inside Workspace can carry rider information, as long as the account is set up with care and staff keep rider details out of the services the agreement does not cover.

That matters to a NEMT office because so much of the job moves through email: trip requests from facilities, schedule changes from brokers, discharge paperwork, and the daily manifest someone wants to send to a driver. Whether your company falls under HIPAA at all is answered in our HIPAA guide for NEMT providers. Texts and email sent to riders themselves are covered in texting riders and drivers under HIPAA, so this page sticks to the office mailbox.

Why a free Gmail account cannot be fixed

A free @gmail.com account is a personal account, and the agreement HIPAA requires is not available for it. Google’s admin help says a person must be signed in to an administrator account for an organization’s Workspace or Cloud Identity account to accept the agreement. A personal Gmail address has no such account behind it, and users of the legacy free edition are excluded as well.

The consequence comes from HHS’s cloud computing guidance. A company that keeps health information with a cloud provider that creates, receives, maintains, or transmits it on the company’s behalf must have a business associate agreement with that provider, and doing without one is a violation in itself. HHS cites a resolution agreement with a covered entity that stored information on more than 3,000 people on a cloud server without one. A rider list sitting in a free Gmail inbox is the same problem at a smaller size.

Getting Google’s agreement on a Workspace account

The agreement comes from the Admin console, and only a super administrator can accept it. The path Google gives:

  1. Sign in to the Admin console as a super administrator.
  2. Open Menu, then Account, then Account settings, then Legal and compliance.
  3. Under Security and Privacy Additional Terms, open the Google Workspace/Cloud Identity HIPAA Business Associate Amendment.
  4. Select Review and Accept, answer the three questions about your HIPAA status, and select OK.

Google states that customers without a signed agreement must not use protected health information in Workspace, so do this before moving rider work into the account. Google’s help page says a screenshot of the acceptance in the Admin console serves as proof, and that the electronic agreement is as binding as a paper one. Save that screenshot with your HIPAA records, which the Security Rule says to hold for six years (45 CFR 164.316(b)(2)), counted from the later of the day a record was made or the day it stopped applying.

What the agreement covers, and what it leaves out

Google lists the services where rider information is allowed. As of August 31, 2026, that list includes Gmail, Calendar, Chat, Drive (with Docs, Sheets, Slides, and Forms), Meet, Groups, Keep, Sites, Tasks, AppSheet, Apps Script, Cloud Search, Vault where applicable, and Voice for managed users. Anything not on the list is off limits for rider details, even when it sits inside the same account.

Google’s HIPAA implementation guide names the gaps that catch small offices:

  • Contacts. Google Contacts is a core Workspace service where protected health information is not permitted. A saved contact named “Mrs. Diaz, dialysis MWF” breaks the rule even though Gmail itself is covered.
  • Consumer services. YouTube, Blogger, Google Photos, and other services outside the Workspace agreement must be turned off for staff who handle rider information.
  • Add-ons and outside apps. Google’s agreement does not reach third-party Marketplace apps and add-ons connected to Gmail or Drive. Google leaves it to you to put HIPAA terms in place with each one, an agreement included, before rider data reaches it.
  • Support tickets. Google’s technical support is not covered, so never paste rider details into a support request.
  • Preview features. Pre-release features are excluded unless Google says otherwise.

The guide’s suggested fix is organizational units: put the people who handle rider information in one unit with only covered services turned on, and everyone else in another.

Microsoft’s version is simpler to get. Its HIPAA business associate agreement is part of the Microsoft Online Services Data Protection Addendum and applies by default to customers who are covered entities or business associates. Exchange Online, Teams, OneDrive for Business, and SharePoint Online are among the in-scope commercial services. Outlook.com, the free consumer email service, is not on that list. The same agreement test applies to AI chat tools.

Encryption in transit: what Gmail does and does not do

HIPAA does not ban email. HHS’s answer in FAQ 2006 is that the Security Rule allows electronic health information to travel over an open network as long as it is adequately protected. The covered company has to assess its use of email, choose protections, and document the decision. Encryption is an addressable specification under 45 CFR 164.312(e), so you adopt it or write down why another measure is reasonable.

Gmail always tries to send messages over an encrypted TLS connection. If the receiving server does not support TLS, Gmail sends the message anyway, without that protection. Workspace administrators can close the gap for the domains that matter with the Secure transport (TLS) compliance setting, under Apps, Google Workspace, Gmail, Compliance. With it on, a message to a listed domain whose server will not use TLS bounces back with a non-delivery report instead of going out in the clear. Your brokers’ and main facilities’ domains belong on that list.

For a recipient whose mail system you cannot vouch for, send a link into a secured system or an encrypted message rather than an attachment. Microsoft Purview Message Encryption comes with Microsoft 365 Business Premium and the Enterprise E3 and E5 plans, and Business Basic and Business Standard get it through the Azure Information Protection Plan 1 add-on. Recipients outside Microsoft 365 open those messages in a web browser.

Some brokers set this rule for you. CareOregon’s provider manual requires email carrying member health information to use a secure email portal. Providers that lack one may ask the brokerage to encrypt what it sends them. Modivcare’s 2025 provider compliance training gives unencrypted email that discusses a member’s records or complaints as an example of an improper disclosure.

Emailing manifests to drivers

Do not send manifests or schedules to drivers’ personal email accounts. The message lands with a provider your company has no agreement with, can sync to other devices the driver shares, and stays in the account after the driver quits. Each of those copies is rider information you can no longer protect or delete.

The cleaner options are company accounts for drivers inside your covered Workspace or Microsoft 365 domain, or trips delivered in a driver app so nothing needs to be emailed at all. Our guide to company phones for NEMT drivers covers the device side of the same decision. When a driver leaves, close the company account the same day and check it for forwarding rules, a step the NEMT cybersecurity guide walks through.

Broker, facility, and online fax traffic

Rider details also arrive by email: discharge requests from hospitals, standing order updates from dialysis centers, and schedule changes from brokers. Once a message reaches your inbox, protecting it is your job. A few habits keep that traffic from spreading:

  • Reply without the history. Answer a facility’s trip request without quoting the full chain of earlier messages.
  • Share files, not attachments. Google’s guide notes that Drive files attached in Gmail start out restricted. Administrators can set link sharing to private by default so a file goes only to the people named.
  • Use Bcc for groups. When one message goes to several outside people, Google’s guide suggests the Bcc field so recipients cannot see each other and are left out of later replies.

Fax has not gone away. WellTrans’s in-network agreement for providers, revised October 16, 2025, makes providers keep a fax line WellTrans can reach and sends trip reservations by fax or a secure website. A fax line or machine that cannot receive for at least an hour of the business day triggers a $100 liquidated damages charge per occurrence.

Online fax services bring HIPAA back into it. HHS’s cloud guidance limits the conduit exception to services that only transmit information, with temporary storage along the way. A service that keeps incoming faxes in a web inbox, or turns them into email attachments, stores rider information for you and needs a signed agreement like any other vendor. Our HIPAA guide lists what that agreement should say.

Setting up email for a small office

  1. Move everyone to company accounts on your own domain in Google Workspace or Microsoft 365, and stop using personal addresses for anything that touches a trip.
  2. Get the agreement in place. Accept Google’s amendment in the Admin console, or download Microsoft’s from its Service Trust Portal, and save proof with your HIPAA records.
  3. Turn on two-step sign-in for every account, starting with the owner and the shared dispatch inbox.
  4. Separate staff by role in organizational units, with non-covered services switched off for people who handle rider information.
  5. Keep riders out of Contacts. Rider details belong in your dispatch system, not an address book.
  6. Require TLS for broker and facility domains, and use an encrypted message or a portal link for anyone else.
  7. Restrict sharing of Drive or OneDrive files to named people.
  8. Write it down and train on it. Add an email section to your privacy policies, and teach staff what may and may not go in a message.

Fewer emails carrying rider details

Most of the email in a NEMT office exists to move trip information between people. In HealthRide, drivers see their trips in the driver app instead of an emailed manifest, and dispatchers and drivers message each other in team chat. Each person sees only what their role allows, and HealthRide is HIPAA compliant and signs business associate agreements with its providers.

Frequently asked questions

Is a personal Gmail account OK for my NEMT business if I never send diagnoses?
Not for rider details. A pickup address next to a rider's name and a clinic destination is protected health information once your company holds it under HIPAA, diagnosis or not. A free @gmail.com account has no Admin console, so there is no way to accept Google's business associate agreement for it, and HHS says keeping health information with a cloud provider that has not signed one violates the HIPAA rules.
Does Google sign a BAA for every Workspace plan?
Google ties the agreement to the account rather than to a named plan. An administrator of a Google Workspace or Cloud Identity account can review and accept it, while users of the legacy free edition, sometimes called Google Apps Standard Edition, cannot. If your Admin console does not show the HIPAA amendment under Legal and compliance, ask Google before any rider information goes into the account.
Is email encrypted automatically in Google Workspace?
Only when the other side cooperates. Gmail always tries to deliver over an encrypted TLS connection, but if the receiving server does not support TLS, the message still goes out unencrypted. Administrators can require TLS for chosen domains, such as your brokers and main facilities, and messages to those domains then bounce instead of going out unprotected.
Can I email a trip schedule to a driver's personal email address?
Avoid it. The schedule then sits in an account your company does not control, under a provider that has no agreement with you, and it stays there after the driver leaves. Give drivers company accounts under your covered domain, or send trips through a driver app, and keep personal inboxes out of it entirely.
Do online fax services need a business associate agreement?
Usually yes. HHS treats a service that only transmits information, with temporary storage along the way, as a conduit that needs no agreement. An online fax service that keeps incoming faxes in a web inbox or emails them to you as attachments is storing rider information for you, so it needs a signed agreement first.
Is a signed BAA with Google enough to make our email HIPAA compliant?
No. Google says customers are responsible for deciding whether they need the agreement and for using its services in compliance with HIPAA, and Microsoft says its agreement alone does not achieve compliance. You still need settings, staff rules, and training: two-step sign-in, restricted sharing, no rider details in services the agreement does not cover, and a written email policy.

Official resources

HealthRide plans the whole day in one click and bills every ride.