


A BAA is required when working with any technology or vendor that will have access to your PHI. The first thing you must do to make Google Drive compliant is enter into a BAA with Google. Enter a business associate agreement (BAA).Google provides documentation of HIPAA compliance and implementation, but we’ll break it down here too. What if your security practices are solid? What do you have to do to use Google Drive in a HIPAA-compliant manner? Keeping PHI secure while using Google DriveĪpart from ensuring that your organization is practicing HIPAA-compliant procedures, follow a few steps to ensure you’re using Google Drive in a HIPAA-compliant way. You can read more about how to ensure your organization is HIPAA compliant here. Organizations that want to keep their data safe and avoid legal repercussions need to ensure both their technology and employee practices are HIPAA compliant. That example illustrates how a lack of training can put an organization at risk even when their technology is HIPAA compliant. Although the software is technically compliant, bad practices have put your organization at risk for a HIPAA violation. Imagine your team has just purchased new HIPAA-compliant form software, but after entering a new patient’s information, the administrator walks away from the computer without logging off. To securely collect medical data, files, and payments online and send them to Google Drive automatically, Jotform offers HIPAA-compliant online forms and a free Google Drive integration HIPAA-compliant software is only as good as your internal security practices
