← All posts
Filed in / hipaa · compliance · file-sharing

Is Google Drive HIPAA Compliant? Check Sharing Before Uploading PHI

In this piece
  1. 01 Start with a folder, not just a file
  2. 02 Use a repeatable sharing review
  3. 03 Test revocation at the source of access
  4. 04 Compare the same sharing exercise
  5. 05 Treat downloaded copies as another location
  6. 06 Plan for the next staff change
  7. 07 Evaluate the whole document exchange

Google Drive can support HIPAA workflows when the required agreement, service scope, and safeguards are in place. Drive appears on Google’s HIPAA Included Functionality list. Define who should see each patient document in your organization.

Before uploading protected health information (PHI), verify the organization’s BAA and approved service scope. The Google Workspace HIPAA guide covers that first review. This checklist focuses on what happens inside the sharing workflow.

Start with a folder, not just a file

Imagine a billing coordinator preparing documents for an outside billing partner. The coordinator checks the partner’s email address and shares a spreadsheet. But the spreadsheet sits in a general operations folder that other people already use.

The file’s audience can come from its location as well as direct invitations. Google documents how folder permissions are inherited by the files and subfolders inside. Review the parent folder, group membership, and any shared drive membership that contributes access.

A useful review question is: if a new staff member joins an existing group tomorrow, which patient documents will become visible to them?

Use a repeatable sharing review

For each proposed location, have the workflow owner and administrator complete a small review using synthetic files:

Check Question to answer
Location Is this the approved folder or shared drive for this work?
Audience Which people and groups can currently open it?
External access Is the recipient the intended person at the intended organization?
Permission level Does the recipient need to view, comment, or edit?
Future access Who can add members or broaden sharing later?
End of access Who removes access when the work or relationship ends?

Prefer an approved, defined recipient set for PHI workflows. Check the general access setting rather than assuming that copying a link preserves the intended restriction. A link is a way to reach a file; your review must establish who can actually open it.

Test revocation at the source of access

Removing a direct invitation may leave another route through a group or parent folder. Google’s sharing controls documentation explains the relationship between file and parent permissions, including options for limiting access.

Create a test file with the same sharing structure as the planned workflow. Sign in as an authorized test collaborator, open it, remove the relevant access, and try again. Repeat with an unrelated account and record the permission path you changed and the result.

If the folder structure makes the intended audience hard to explain, reorganize the test workflow before adding PHI.

Compare the same sharing exercise

Request a healthcare document-sharing pilot to evaluate IRONKEEP DRIVE with the same recipient and revocation exercise. It is part of IRONKEEP’s private beta healthcare workspace; review the intended exchange and BAA scope before introducing ePHI.

Treat downloaded copies as another location

Revoking access to the online file does not erase a copy already downloaded to another device. Google offers controls that limit downloading, printing, copying, and resharing, while also noting that content can still be shared in other ways. Review the available controls and their limits in its sharing documentation.

Decide whether the recipient actually needs a local copy. If downloads are part of the approved process, document the destination, device expectations, and handling when the engagement ends. Include that location in your ePHI inventory.

Plan for the next staff change

Before the coordinator leaves, establish who will own the workflow, receive access requests, and review external collaborators. Follow the employee offboarding checklist for sessions, integrations, and devices beyond Drive.

Keep evidence that the replacement owner can access the required records and the departing person cannot. Review retained content separately from account access so that closing an account does not become an accidental records-deletion decision.

Evaluate the whole document exchange

The outcome should be a workflow your team can explain: where the document belongs, who receives it, what copies exist, and how access ends. Our broader HIPAA file sharing guide applies the same questions across vendors.

Bring a synthetic file, its permission map, and a staff-change scenario to the evaluation. Include the email or chat that delivers the link: the recipient’s experience starts before they open the document.

Healthcare · Private beta

Scope your healthcare workspace.

Evaluate email, files and docs, and team access with IRONKEEP. Start with your workflow and BAA needs.

Request a healthcare pilot