A hand signing a paper contract with a pen at a wooden office desk, representing a Canadian therapist reviewing what a Google Workspace BAA actually covers

Google Workspace BAA: what it covers and does not

Gabriel Borges14 min read

Updated

You found the Business Associate Amendment in your Google Admin console, read enough of it to feel reassured, and clicked to accept. Maybe you saved the PDF somewhere sensible. For a lot of Canadian therapists, that’s the moment the email side of the practice feels handled.

Here’s the honest version. A Google Workspace BAA is a contract, not compliance. It’s a real document that does real things, and signing it is a reasonable move. But it’s a United States HIPAA instrument, and it answers a different question than the one you answer to under PHIPA in Ontario. Filing it under “done” is where the gap opens.

This piece takes the BAA apart: what it actually covers, what it quietly leaves to you, and where the real gaps sit for a Canadian therapist. It belongs to a series on running Google Workspace in a therapy practice, so if you haven’t set the tenant up yet, start with the Google Workspace PHIPA setup guide for Canadian therapists. This one assumes you’ve signed the BAA and want to know what it’s worth.

What a Google Workspace BAA actually is

A Business Associate Amendment (BAA) is a contract under United States HIPAA. In it, a vendor like Google agrees to act as a “business associate,” handling protected health information on behalf of a HIPAA covered entity under defined terms. Google offers it to Workspace administrators for electronic acceptance, which is why so many therapists have one on file.

Read that definition again, because the mismatch is right there in it. HIPAA is a US law. A covered entity is a US concept. A therapist in private practice in Canada isn’t a HIPAA covered entity, and PHIPA, not HIPAA, is the law you answer to. So the BAA is an instrument built for a legal world you don’t live in.

That doesn’t make it worthless. It does mean the document governing Google’s handling of your data, as a Canadian, is the one sitting alongside the BAA: the Cloud Data Processing Addendum. The Addendum is the general data processing agreement for your Workspace account. The BAA is a HIPAA-specific overlay bolted on top. When people say “I signed Google’s BAA, so my email is covered,” the more accurate sentence is “I accepted Google’s data processing terms, one layer of which is a US HIPAA amendment that doesn’t map onto PHIPA.”

And here’s the part no contract can change. The PHIPA compliance duty stays with you. Under PHIPA s.17(1), a health information custodian stays accountable for personal health information in its custody or control, including information handled by an agent such as a service provider. You can bind Google to good behaviour. You can’t hand Google your legal duty. There is no signature that transfers it, and no Ontario regulator issues a “PHIPA compliant” stamp for a configuration or a contract.

That accountability has teeth, too. Since January 1, 2024, the Information and Privacy Commissioner of Ontario has been able to impose administrative monetary penalties of up to $200,000 on an individual and up to $1,000,000 on an organization, on top of offence provisions that carry fines and imprisonment of up to 12 months. None of that is a reason to fear the BAA. It’s a reason to be clear about what the BAA does and doesn’t do, so the responsibility that stays with you isn’t one you’ve quietly assumed away.

What the BAA covers

Give the BAA its due. The therapists who sign it aren’t wrong to want it on file.

When you accept it, Google commits, as a business associate under US HIPAA, to handle the data covered by the agreement in defined ways. In broad terms, that means limits on how Google may use and disclose that data, a commitment to apply safeguards on its side of the wire, and an obligation to tell you about certain incidents involving the data. Reviewing those terms before you accept is the right instinct.

There’s a genuine PHIPA benefit buried in there, narrower than most people assume. Part of your accountability as a custodian is choosing service providers with appropriate protections and holding them to defined terms. A signed agreement in which your email provider commits to specific handling of your data is evidence you did that part. It speaks to how you selected and bound Google, which is a real slice of your s.17 responsibility.

What it doesn’t do is stretch to cover everything your Google account can reach. The BAA, and the Cloud Data Processing Addendum alongside it, apply to the Workspace core services. They don’t extend to the Additional Google Services a user can switch on outside that core. So the protections you signed for cover Gmail and the other core apps, not every Google product the account can touch.

Where the BAA stops: the gaps it leaves you

Four gaps, and they’re the four most therapists never notice, because the BAA feels like it should have closed them.

The BAA is an agreement between you and Google. Your client isn’t a party to it, and it says nothing about what they agreed to.

That matters because PHIPA puts a consent question in front of you that the BAA can’t answer. PHIPA permits personal health information to be handled outside the country, so this isn’t a claim that US servers are illegal. But where handling client email amounts to a disclosure of personal health information across the border, s.50(1)(a) requires the client’s consent, and s.18(3)(a) makes it express rather than implied where the recipient isn’t a health information custodian. Not implied. Not buried in a policy nobody opens. The Act never demands a written form, but a record is how you show you asked.

Google signing a contract about how it processes data does nothing to capture that consent. The vendor agreement and the client agreement are two different documents, and only one of them is yours to get. The same express consent standard reaches another situation you might not connect to email: processing personal health information with AI. If a Workspace feature like “smart features and personalization in other Google products” can route client email into other Google products, that’s an express consent question too, and the BAA doesn’t touch it. For where Workspace actually stores your email and why cross-border handling comes up at all, see Google Workspace data residency for Canadian therapists.

The encryption the BAA doesn’t provide

A contract is a promise about conduct. It isn’t a technical control.

The BAA commits Google to handle your data a certain way. It doesn’t encrypt the email your client opens, and it does nothing about the most ordinary breach in a solo practice: the message sent to the wrong person. You autocomplete the wrong Sarah, or reply all to a group, and a treatment detail lands in an inbox it was never meant for. TLS, which protects the connection between mail servers, doesn’t help there, because the message arrives perfectly readable. Neither does a signed BAA.

What changes that outcome is encryption tied to the message itself and a verified recipient, so a wrong-address email is one the wrong person can’t open. Whether plain Gmail clears that bar is its own question, and we work through it in whether Gmail is PHIPA compliant.

The record of the send

Picture the Information and Privacy Commissioner of Ontario asking you to show what protected one specific client email. What do you hand them?

The BAA is a contract, not a receipt. It doesn’t generate a per-send record showing that a given message went out encrypted, on a given date, to a given recipient. Google’s admin logs capture account activity, which helps, but an account log isn’t message-level proof that the safeguard was running when it mattered. The document you’d most want in that moment is the one the BAA never produces.

The Google services the BAA doesn’t reach

This one slips past almost everyone, because it sounds like a technicality. It isn’t.

The BAA and the Cloud Data Processing Addendum cover the Workspace core services. The Additional Google Services a user can enable outside that core sit outside those terms. So if client information finds its way into an Additional Service, the contractual protections you signed for don’t follow it there. Keeping personal health information inside the covered core services is a quiet but real part of holding up your end.

What to do about the gaps

None of this is a reason to tear out Google Workspace. It’s a reason to treat the BAA as step one of a few, not the finish line. Here’s the short list, in the order that makes sense.

  1. Read both instruments and confirm the scope. Signed in as a super administrator, open Account settings, then Legal and compliance, and look at what you actually accepted. The Business Associate Amendment is the US HIPAA overlay; the Cloud Data Processing Addendum is the data processing agreement that governs a Canadian therapist’s use of Workspace. Note the date you accepted them and which services are in scope, and keep client information out of the Additional Google Services those terms don’t cover.
  2. Capture your client’s express consent, and record it. Build the cross-border handling of their information into your intake paperwork, in plain language, and keep a record of what they agreed to. This is the piece the BAA structurally can’t do for you, and it’s the one an IPC review is most likely to ask about.
  3. Add encryption that travels with the message. Put a control in place that encrypts client email to a verified recipient, so a message sent to the wrong address stays unreadable. This protects the message itself, which is exactly what TLS and the BAA leave exposed.
  4. Keep a per-send record you could show. Maintain a send-level audit trail that records each client email was encrypted and when. If a question ever comes about one specific message, that record is the answer, not something you rebuild from memory two years later.

The first two are yours no matter what tools you run. The last two are where a product built for this earns its place.

Where Curio fits

That last line is the honest handoff to what we make, so here’s the precise version.

Curio encrypts every outbound email automatically and logs every send in a Canadian audit trail, working with the Gmail you already use. No migration, no new inbox, no extra step at the moment you hit send. It closes steps three and four: the message is encrypted to the recipient, and the send is on the record. When the wrong-address email happens, and across enough sends it does, the message wasn’t sitting in plain text, and the audit trail is the proof the safeguard was running.

One scope note, because precision is the whole point of this piece. Curio’s compliance infrastructure, its audit trail and its encrypted portal messages, is hosted in Canada, in Montreal. That’s Curio’s own data, not your Gmail’s storage location, and it doesn’t move where Google keeps your message content. What it adds is the encryption and the Canadian audit trail the BAA leaves out.

To be exact about the limits: encryption and an audit trail are safeguards under PHIPA s.12(1), not the whole of PHIPA. They don’t capture consent for you, that’s step two, and they don’t make your practice “PHIPA compliant” on their own. They close the two gaps this explainer keeps circling back to.

If you want your Gmail encrypted for Canadian mental health privacy law, with every send recorded in a Canadian audit trail, and without leaving the inbox your practice already runs on, join the Curio waitlist.

What this explainer doesn’t settle

A few honest limits, because a piece about the boundaries of a contract should mind its own.

This is informational content, not legal advice. Consent mechanics for cross-border handling get specific fast, and a close call is worth a conversation with a privacy lawyer or a knowledgeable compliance professional. One consultation costs less than mishandling a disclosure.

It’s also written from Ontario, where the statute is PHIPA. The shape of the BAA problem holds across the country, but the law underneath it shifts. In Alberta, private practice therapists fall under Alberta’s Personal Information Protection Act (PIPA), with College of Alberta Psychologists standards on top, not the Health Information Act. In British Columbia, PIPA sets a comparable duty to protect personal information with reasonable security. The consent and safeguard obligations rhyme; the details don’t. If you see clients across provincial lines, get advice for your situation.

And it’s a snapshot. Google revises its terms, its service list, and its admin surfaces on its own schedule. The instruments and scope described here were current when this was written. Before you rely on a specific term, open the console and confirm it still reads the way this describes.

Frequently asked questions

Does a Google Workspace BAA make me PHIPA compliant?

No. A BAA is a US HIPAA contract, not a PHIPA certificate, and no Ontario regulator certifies software or a configuration as compliant. It can show you chose a service provider with defined contractual protections, but under PHIPA you stay accountable for your consent process, safeguards, and breach response.

Do I need a Google Workspace BAA as a Canadian therapist?

Reviewing and accepting it is reasonable, but it’s a US HIPAA instrument, not a PHIPA requirement. For a Canadian therapist, the terms that actually govern Google’s handling of your data are the Cloud Data Processing Addendum. Signing the BAA does not discharge your PHIPA obligations.

What’s the difference between the BAA and the Cloud Data Processing Addendum?

The Business Associate Amendment is a HIPAA-specific overlay written for US covered entities. The Cloud Data Processing Addendum is the general data processing agreement that governs how Google handles your Workspace data. For a Canadian therapist under PHIPA, the Addendum is the document that actually applies to you.

No. The BAA is an agreement between you and Google, and it says nothing about your client. PHIPA requires the client’s consent where personal health information is disclosed outside Ontario (s.50(1)(a)), and s.18(3)(a) makes that consent express rather than implied where the recipient isn’t a health information custodian. It doesn’t require the consent in writing, but the consent is yours to obtain and to be able to evidence, and the BAA does not capture it.

Does signing the BAA mean my client email is encrypted?

No. The BAA is a contract about how Google handles data, not an encryption setting. It doesn’t encrypt the message your client opens, and it doesn’t stop a misdirected email from being readable. Encryption that travels with the message to a verified recipient is a separate control you add.

Does the Google Workspace BAA cover all Google services?

No. The BAA and the Cloud Data Processing Addendum apply to the Workspace core services, not the Additional Google Services outside that boundary. If you use an Additional Service with client information, it sits outside those terms, so keep personal health information within the covered core services.


This content is for informational purposes only and does not constitute legal advice. Privacy regulations vary by province and are subject to change. Verify current requirements with the Information and Privacy Commissioner of Ontario, your provincial regulatory body, and a qualified privacy professional for your specific situation.

Curio is designed to encrypt outbound email and maintain a Canadian audit trail. It is not a substitute for professional legal or compliance advice.

Sources

Coming soon

Gmail encryption, built for Canadian therapists.

Join the waitlist →

Share this article

Related posts

Community

Join the community

Connect with Canadian therapists navigating Google Workspace compliance.

Join on Facebook