A laptop and external monitor on a tidy office desk, representing a Canadian therapist setting up Google Workspace for PHIPA

Google Workspace PHIPA setup for Canadian therapists

Gabriel Borges21 min read

Updated

You pay for Google Workspace, sign Google’s business agreement, switch on two factor login, and tell yourself the email side of your practice is handled. It’s a reasonable assumption. It’s also the gap most Canadian therapists never see, because the settings that look like compliance and the obligations PHIPA actually puts on you are not the same list.

So here’s the honest version, up front. No combination of Google Workspace settings makes your Gmail “PHIPA compliant.” No Ontario regulator certifies a configuration, and no checkbox transfers your responsibility to Google. What the right settings do is still worth the half hour: they shrink the distance between a default Workspace tenant and what the law expects of a health information custodian. They don’t erase it.

This is the setup, ordered the way you’d actually do it. The admin settings to change. The AI features to turn off. Where Workspace keeps your client email, and whether you can choose Canada. And the places a well configured Workspace still leaves you exposed, which is the part most setup guides quietly skip.

If you’re earlier than configuration and still asking whether Gmail belongs in a therapy practice at all, start with our guide on whether Gmail is PHIPA compliant. This piece assumes you’ve made that call and want the tenant set up properly.

Key takeaways

  • No Google Workspace configuration makes Gmail “PHIPA compliant.” Compliance is a duty on you as a custodian, not a certificate you switch on. The right settings reduce the gap; they do not close it.
  • The settings that matter most for client email are enforced 2-step verification, required TLS for client domains, the AI and smart features that route content into other Google products turned off, and a documented record of what you configured.
  • Google Workspace data regions does not offer a Canadian location. Your choices are the United States, the European Union, or no preference. PHIPA does not require Canadian storage, so this is a “know where your data sits” issue, not a legal breach.
  • A Google Workspace BAA is a US HIPAA instrument and a contract, not PHIPA compliance. For a Canadian therapist the relevant terms are the Cloud Data Processing Addendum, and neither covers Additional Google Services.
  • Implied consent doesn’t stretch to an outside AI tool. Where the vendor isn’t your agent, PHIPA s.18(3)(a) requires express consent before you disclose personal health information to it. That applies to AI note-takers and assistants wired into your inbox.
  • What a hardened Workspace still doesn’t give you: message-level encryption that protects the email when it reaches the wrong recipient, and a Canadian audit trail showing each send was encrypted. That’s the remaining gap.

Can you make Google Workspace PHIPA compliant?

Quick answer

No. There is no setting, no edition, and no signed agreement that makes Google Workspace or Gmail “PHIPA compliant.” PHIPA governs your conduct as a health information custodian, not Google’s product. Under PHIPA s.12(1) you must take steps reasonable in the circumstances to protect personal health information, and under s.17(1) you stay accountable for what your service providers do as your agents. Configuring Workspace well is part of taking those reasonable steps. It is not a transfer of responsibility, and no Ontario regulator issues a “compliant” stamp for a configuration.

This trips up careful people, so it’s worth being exact about why.

“PHIPA compliant” describes a custodian who is meeting their obligations across the board: consent, safeguards, retention, breach response, access requests. A piece of software can support some of those obligations. It can’t satisfy all of them on your behalf, and it can’t hold the legal duty that sits with you. When a vendor calls its product “PHIPA compliant,” what they can honestly mean is that the product is built to help you meet specific requirements, not that installing it discharges the law.

That distinction changes how you should read this guide. You’re not hunting for the setting that flips Workspace to compliant. You’re building a defensible setup: a tenant where, if the Information and Privacy Commissioner of Ontario ever asked what safeguards you had in place, you’d have a real answer. The rest of this article is that setup, plus an honest account of where it stops.

What does PHIPA actually require of your email setup?

Before changing settings, it helps to know what you’re configuring toward. Otherwise you’re flipping switches without knowing which ones the law cares about.

Under PHIPA s.12(1), a health information custodian must take steps that are reasonable in the circumstances to protect personal health information against theft, loss, and unauthorized use or disclosure. PHIPA does not list specific technologies. It sets a standard (“reasonable in the circumstances”) that scales with the sensitivity of the information, and mental health records sit at the sensitive end. The Information and Privacy Commissioner of Ontario enforces PHIPA, and since January 1, 2024 it has been able to impose administrative monetary penalties of up to $200,000 for an individual and up to $1,000,000 for an organization, alongside offence provisions that carry fines and imprisonment of up to 12 months.

The phrase doing the work is “reasonable in the circumstances.” It’s deliberately flexible, and that flexibility runs against you, not for you. A configuration that lets client email travel in plain text, or flow into systems you never chose, is hard to defend as reasonable even if nothing ever goes wrong.

Two more points before the steps, because they decide how you read everything that follows.

First, this is a Canada-wide question with province-specific law underneath it. In Ontario, the statute is PHIPA. In Alberta, private practice therapists fall under Alberta’s Personal Information Protection Act (PIPA), with College of Alberta Psychologists standards on top; they are not health information custodians under the Health Information Act. In British Columbia, PIPA s.34 sets a comparable duty to protect personal information with reasonable security. The Google Workspace steps below are the same in every province. The law you’re answering to shifts with where your client sits.

Second, your obligation is broader than encryption. Encryption is the safeguard people fixate on, and it matters, but PHIPA’s “reasonable steps” also reach access control, retention, who can see shared files, and your ability to show what you did. The setup below covers the email-adjacent parts of that. It is not your whole compliance program. For the underlying email requirements in depth, see our guide to PHIPA email requirements for therapists.

How do you configure Google Workspace for PHIPA, step by step?

Here’s the order that makes sense. Account-level decisions first, then the controls that protect access, then transport, then the AI and data questions, then the paperwork. If you run a one-person practice, you’re the super administrator, so all of this is yours to set.

A quick note before you start. Google moves its menus and renames its settings more often than anyone would like. The paths below were current when this was written. If a label doesn’t match what’s on your screen, search Google’s admin help for the setting name rather than assuming the feature disappeared.

Step 1: Confirm your edition and review Google’s data terms

Start with the account, because two things here trip up a lot of careful people.

The first is the edition. A free, consumer Gmail account is not eligible for Google’s business data terms, and it has no place handling client email. You want a paid Google Workspace subscription. Any of the paid tiers will do for the terms themselves; the data region question in Step 5 is where the edition starts to matter.

The second is the agreement. Signed in as a super administrator, open Account settings, then Legal and compliance. Google offers a HIPAA Business Associate Amendment for electronic acceptance here, and a lot of therapists sign it and feel covered. Be precise about what it is. The BAA is a United States HIPAA construct. It does not make you “PHIPA compliant,” and for a Canadian therapist the terms that actually govern Google’s processing of your data are the Cloud Data Processing Addendum. We pull that apart in what the Google Workspace BAA covers and what it does not. For now: review the terms, note the date you accepted them, and record which services are in scope.

Step 2: Enforce 2-step verification

This is the highest-value setting in the whole guide, and it’s free.

In the Admin console, open Menu, then Security, then Authentication, then 2-step verification. Set it to enforce, not merely allow. “Allow” leaves it to each user to opt in, which means it protects the people who least need protecting and skips the ones who don’t bother. Enforcement closes that gap.

When you choose a method, lean toward security keys or an authenticator app over text messages. SMS codes can be intercepted, and Google itself flags them as the weaker option. Most client email exposure doesn’t start with a sophisticated attack. It starts with a reused password showing up in a breach dump. 2-step verification is what stops that password from being enough.

Step 3: Require TLS for email with client domains

By default, Gmail tries to send over an encrypted TLS connection. The word doing quiet damage there is “tries.” If the receiving server doesn’t support TLS, an ordinary message can fall back to plain text, and you’d never know.

To remove the fallback for the domains you care about, open Menu, then Apps, then Google Workspace, then Gmail, then Compliance, and configure the Secure transport (TLS) compliance setting. You can require TLS for mail exchanged with specific domains and addresses, which is useful if you correspond regularly with a clinic, an EAP provider, or a referral partner.

Now the honest limit, because this is where a lot of “encrypted email” claims overreach. TLS protects the connection between two mail servers. It does not encrypt the message so that only your intended recipient can open it, and it offers nothing at all when you autocomplete the wrong Sarah and send a treatment summary to a stranger. TLS is a floor worth setting. It is not message-level encryption.

Step 4: Turn off the AI and smart features that route content outside the core service

Workspace ships its AI and smart features switched on for users in Canada. Google turns them off by default in the European Economic Area, the UK, Switzerland, and Japan, which tells you something about how the company reads the privacy stakes. In Canada, the off switch is yours to find.

The one to prioritize is the setting that lets your Gmail content feed personalization across other Google products, the path that carries content outside the boundary your Workspace agreement governs. Turn it off at the organization level so no individual user can re-enable it, then confirm it on your own account. The full walkthrough, with every menu path and the difference between the three smart features settings, is in the Google Workspace AI features therapists need to turn off.

There’s a legal layer here that settings alone don’t resolve. Consent must be knowledgeable (s.18(1)), and the implied consent you rely on inside the circle of care doesn’t reach an outside AI tool: where the vendor isn’t your agent, s.18(3)(a) requires the consent to be express and not implied. PHIPA never requires it in writing, but you should be able to show you asked. So if you’re running an AI note-taker, an AI scheduling assistant, or any tool that reads client content to generate output, the question isn’t only “is the toggle off.” It’s “did my client agree to this specific processing, and can I show that they did.” A switched-off setting and a missing consent are two different exposures.

Step 5: Set your data region, and know what it cannot do

If your Workspace edition includes data regions, open Menu, then Data, then Compliance, then Data regions, and assign a location. You can scope it to your whole organization or to a unit.

Then brace for the catch, because it’s the honest centre of this whole topic. The data region choices are the United States, the European Union, or no preference. There is no Canada. A Canadian therapist cannot pin Workspace’s covered data to Canadian soil, full stop.

That sounds alarming until you line it up against the actual law, and then it mostly deflates. PHIPA imposes no Canadian data-residency requirement. None. Cross-border handling of client information is permitted with the right consent, and it does not trigger a mandatory privacy impact assessment. So the fact that you can’t choose Canada in Workspace is not a legal violation. It’s a transparency problem: you should know your client email content sits on US or EU infrastructure, and you should be able to tell a client that if they ask. We document the whole residency question, including what the Workspace terms say and where the real limit is, in Google Workspace data residency for Canadian therapists.

Step 6: Restrict external sharing and set basic mobile rules

Email isn’t the only way client information leaves your control, so two adjacent settings earn their place here.

In your Admin console, review the Drive and Docs sharing controls and tighten them so files holding client information can’t be shared outside your domain by default. Intake forms, assessments, and session notes have a way of living in Drive, and a too-open default sharing rule is a quiet disclosure waiting to happen. (Google rearranges this area periodically, so if the exact menu path differs from what you expected, search the admin help for “sharing settings” rather than guessing.)

Then set basic mobile device management, so that if a phone with cached client email is lost, you can require a screen lock and wipe the account remotely. Neither setting is dramatic. Both are the kind of reasonable safeguard PHIPA s.12(1) expects a custodian to have at least considered.

Step 7: Write down what you configured and when

Make a short record of every setting you changed and the date you changed it. A note in whatever you use for practice records is plenty.

This isn’t busywork, and it isn’t paranoia. PHIPA s.12(1) asks for reasonable steps, and a custodian who can show the safeguards they applied, and when, stands on far firmer ground than one relying on memory two years later. Workspace keeps admin logs of account activity, which help. But an admin log is not a per-send record proving a given client email went out encrypted, and that distinction matters more than it first appears. We’ll come back to it.

Google Workspace PHIPA setup at a glance

Step 7: Write down what you configured and when
SettingWhere it lives in Google WorkspaceWhat it does for client email
Review Google’s data termsAccount settings, then Legal and compliance (super admin)Confirms the contractual terms (Cloud Data Processing Addendum; HIPAA BAA is a US instrument). Not PHIPA compliance.
Enforce 2-step verificationMenu, then Security, then Authentication, then 2-step verificationStops a phished or reused password from unlocking client email. Highest-value control.
Require TLSMenu, then Apps, then Google Workspace, then Gmail, then Compliance, then Secure transport (TLS) complianceForces encrypted server-to-server transport for chosen domains. Not message-level encryption.
Turn off cross-product AI personalizationOrganization-level smart features control, plus the Gmail settings (see the AI features guide)Keeps content inside the core-service boundary. Express consent is still required under s.18(3)(a) before PHI is disclosed to an AI vendor that isn’t your agent, and the IPC’s guidance on AI and health data sets out what else Ontario expects you to be able to answer.
Set data regionMenu, then Data, then Compliance, then Data regionsAssigns covered data to the US, the EU, or no preference. No Canada option. PHIPA requires no Canadian residency.
Restrict external sharingDrive and Docs sharing controls (Admin console)Limits client files leaving your domain.
Document the configurationYour practice recordsEvidence of “reasonable steps” under PHIPA s.12(1).

Does signing Google’s BAA cover you under PHIPA?

Short answer: no, and the gap between what the BAA does and what therapists assume it does is one of the most common misreadings in this whole area.

A Google Workspace Business Associate Amendment (BAA) is a contractual instrument under United States HIPAA. It commits Google, as a business associate, to handle protected health information in defined ways. It is not a PHIPA instrument, it is not a certificate of compliance, and it does not move a Canadian therapist’s legal responsibility onto Google. For a Canadian custodian under PHIPA, the terms that actually govern Google’s processing are the Cloud Data Processing Addendum, and neither the BAA nor the Addendum extends to Additional Google Services outside the Workspace core.

So signing it is reasonable, and you should review the terms. Just don’t let the act of signing stand in for the work. The BAA can support your case that you chose a service provider with appropriate contractual protections. It can’t answer for your consent process, your safeguards, or your breach response, which remain yours.

We take the BAA apart in detail, including what it covers, what it leaves to you, and where the real gaps sit, in what the Google Workspace BAA covers and what it does not.

Where does a configured Google Workspace still fall short?

You’ve done the work. Verification enforced, TLS required, AI personalization off, data region set as far as it goes, sharing tightened, the whole thing written down. That puts you ahead of most practices, and it was worth doing.

It also leaves two gaps no Workspace setting closes. They happen to be the two that bite hardest in a therapy practice.

The first is the message itself. Everything in Step 3 protects the connection between servers. None of it protects the email once it lands in the wrong inbox, and the most common breach in a solo practice isn’t a hacker. It’s a misdirected message: the autocompleted wrong name, the reply-all that exposes one client to another. TLS does nothing there, because the email arrives perfectly readable to whoever received it. What changes that outcome is encryption tied to the message and a verified recipient, so a misdirected email is one the wrong person can’t open.

The second is proof. Admin logs tell you about account activity. They don’t give you a per-send record showing each client email went out encrypted. If the IPC ever asks you to show the safeguards applied to one specific message, “TLS was configured” is a weaker answer than a log that shows that message was encrypted when it left. The evidence you’d most want is the evidence Workspace doesn’t generate.

There are softer edges too, and you’ve met them already. Your client email content lives on US or EU servers because Workspace gives you no Canadian option, which is lawful but worth disclosing. The BAA is a contract, not compliance. The AI consent obligation sits with you, not in a toggle. None of these is a reason to leave Workspace. They’re the reasons a configured Workspace is a strong floor rather than a finished story.

What a configured Google Workspace still does not do

  • It does not encrypt the message itself to a verified recipient, so a misdirected email stays fully readable to whoever receives it. TLS protects the server-to-server connection, not the message.
  • It does not produce a per-send audit trail showing each client email was encrypted. Admin logs record account activity, not message-level proof.
  • It does not store your Gmail content in Canada. Data regions offers the United States, the European Union, or no preference, and PHIPA does not require Canadian storage anyway.

Where Curio fits

This is the gap Curio was built to close, and only this gap. Curio encrypts every outbound email automatically and logs every send in a Canadian audit trail, working with the Gmail you already use. No migration, no change to how you send mail, no extra steps at the moment of sending. When the wrong-address email happens, and across enough sends it does, the message wasn’t sitting in plain text. And if a question ever comes about what safeguards were in place, the audit trail is the record, not a memory you reconstruct after the fact.

One scope note, because precision is the point. Curio’s compliance infrastructure, its audit trail and its encrypted portal messages, is hosted in Canada, in Montreal. That’s Curio’s own data, not your Gmail’s storage location, and it doesn’t move where Google keeps your message content. What it adds is the encryption and the Canadian audit trail a hardened Workspace leaves out.

To be exact about what that does and doesn’t do: encryption and an audit trail are safeguards under PHIPA s.12(1). They don’t make your practice “PHIPA compliant” on their own, and they don’t stand in for consent, retention, or breach response. They close the specific gap this guide keeps circling back to, the email that goes to the wrong person and the proof that you protected it.

If you want your Gmail encrypted for Canadian mental health privacy law, with every send recorded in a Canadian audit trail, and without leaving the inbox your practice already runs on, join the Curio waitlist.

Frequently asked questions

Is Google Workspace PHIPA compliant?

No software is “PHIPA compliant” on its own. PHIPA governs you as a health information custodian, not Google’s product. A paid Workspace tenant configured with enforced 2-step verification, required TLS, AI personalization off, and documented settings supports your obligations under PHIPA s.12(1). It does not satisfy them for you.

Does PHIPA require my client email to be stored in Canada?

No. PHIPA imposes no Canadian data-residency requirement. Cross-border handling of client information is permitted with appropriate consent and does not trigger a mandatory privacy impact assessment. This matters because Google Workspace data regions offers only the United States, the European Union, or no preference, with no Canada option.

Do I need a Google Workspace BAA as a Canadian therapist?

A Google Workspace BAA is a United States HIPAA instrument, not a PHIPA requirement or a compliance certificate. Reviewing and accepting it is reasonable, but for a Canadian custodian the terms that govern Google’s processing are the Cloud Data Processing Addendum. Signing the BAA does not discharge your PHIPA obligations.

Which Google Workspace AI settings should a therapist turn off?

Prioritize the setting that lets your Gmail content feed personalization across other Google products, which moves content outside the core-service boundary. Turn it off at the organization level and confirm it on your account. Implied consent also doesn’t reach an outside AI tool: where the vendor isn’t your agent, PHIPA s.18(3)(a) requires express consent before client health information is disclosed to it.

What is the single most important Google Workspace security setting for therapists?

Enforced 2-step verification, found under Menu, then Security, then Authentication, then 2-step verification. Most client email exposure starts with a phished or reused password, not a sophisticated attack. Enforcing 2-step verification for every user stops a stolen password from being enough to open a mailbox of client correspondence.

Does turning on TLS make my Gmail encrypted enough for PHIPA?

Not by itself. TLS encrypts the connection between mail servers, and it can fall back to plain text if the receiving server does not support it. It does nothing when an email is sent to the wrong person, because the message arrives readable. TLS is a floor, not message-level encryption.

I see clients in more than one province. Does the setup change?

The Google Workspace steps are identical everywhere. The law underneath them shifts: Ontario clients engage PHIPA, Alberta clients engage Alberta’s PIPA and College of Alberta Psychologists standards, and BC clients engage BC’s PIPA. Email crossing provincial lines can also engage PIPEDA. The safeguard direction stays the same.


This content is for informational purposes only and does not constitute legal advice. Privacy regulations vary by province and are subject to change. Verify current requirements with the Information and Privacy Commissioner of Ontario, your provincial regulatory body, and a qualified privacy professional for your specific situation.

Curio is designed to encrypt outbound email and maintain a Canadian audit trail. It is not a substitute for professional legal or compliance advice.

Sources

Coming soon

Gmail encryption, built for Canadian therapists.

Join the waitlist →

Share this article

Related posts

Community

Join the community

Connect with Canadian therapists navigating Google Workspace compliance.

Join on Facebook