To set google drive sharing settings for plan ephi, place only authorized plan-administration staff in a dedicated Google Workspace organizational unit, disable external sharing and public-link access for that unit, and store plan records in tightly managed Shared drives. Google Workspace can provide the technical safeguards supporting HIPAA 45 CFR §164.314(b)(1), but the group health plan’s documents must also require the plan sponsor, its workforce, and its vendors to follow those safeguards and report security incidents.
What does HIPAA require for group health plan ePHI in Google Drive?
HIPAA’s group health plan plan-sponsor provision at §164.314(b)(1) requires the plan documents to require the sponsor to reasonably and appropriately safeguard electronic protected health information it creates, receives, maintains, or transmits for the plan. The related implementation specifications in §164.314(b)(2) require safeguards for confidentiality, integrity, and availability; support for the required separation between plan functions and sponsor functions; appropriate safeguards by agents and subcontractors; and incident reporting to the plan.
For a COO or finance leader, the practical point is that a general corporate Google Drive configuration is usually not enough. Payroll, benefits, HR, and finance employees may have legitimate business access to corporate files but no permitted reason to access plan ePHI. A dedicated Workspace organizational unit and a restricted Shared drive create a defensible technical boundary around the limited staff who administer the group health plan.
How do you configure google drive sharing settings for plan ephi in Google Workspace?
Use a dedicated organizational unit called Plan EPHI and apply more restrictive Drive settings to that unit than to the general employee population. Perform these steps with a Super Admin account or a delegated administrator with the necessary Drive and organizational-unit privileges. Menu labels can vary slightly by Google Workspace edition, but the administrative paths below reflect the Google Admin console.
-
Create the restricted organizational unit. In the Google Admin console, go to
Directory > Organizational units, select the appropriate parent organization, and chooseCreate new organizational unit. Name itPlan EPHI. Move only workforce members who perform plan administration into this unit, such as the benefits manager and specifically authorized HR or payroll personnel. Do not place all HR, finance, or executive users in this unit merely because they may occasionally request reports. -
Create an access group for the Shared drive. Go to
Directory > Groups > Create group. Create a restricted group such asplan-ephi-drive-access@company.com, setWho can join the grouptoInvited users only, and limit member viewing and conversation access to group members where your operating model permits. Require an owner approval process for membership changes. This group becomes the repeatable, auditable method for granting access. -
Turn off sharing outside the organization for the Plan EPHI unit. Go to
Apps > Google Workspace > Drive and Docs > Sharing settings. In the left panel, select thePlan EPHIorganizational unit. UnderSharing options, selectSharing outside of your organizationand set it toOff. Save the change. This prevents users in the unit from sharing Drive files with personal Gmail accounts, brokers, consultants, or other external recipients through ordinary Drive sharing. -
Disable public and link-based publishing. In the same
Sharing settingspage and with thePlan EPHIunit selected, locatePublishing options. Turn offAllow users to publish files on the web or make them visible to the world as public or unlisted files. Also set the organization’s link-sharing default so files areRestricted, rather thanAnyone in your organization with the link. Restricted sharing requires a named, authenticated user to receive access. -
Prevent inbound external content where the business process does not need it. Still under
Apps > Google Workspace > Drive and Docs > Sharing settings, selectSharing optionsand disableAllow users in your organization to receive files from users outside of your organizationfor the Plan EPHI unit if plan staff do not need outside parties to share files into Drive. If the plan must receive material from a broker, TPA, or legal adviser, use a documented approved channel and a contractual arrangement rather than opening inbound sharing broadly. -
Limit Shared drive creation. Go to
Apps > Google Workspace > Drive and Docs > Manage shared drives. For thePlan EPHIunit, setAllow users to create shared drivestoOff. This avoids unmanaged plan repositories. Have an administrator create one approved Shared drive, such asGroup Health Plan - Restricted. -
Configure the approved Shared drive. Open Google Drive as the administrator, select
Shared drives, openGroup Health Plan - Restricted, and select the drive name followed byManage members. Addplan-ephi-drive-access@company.comasContent managerorContributoraccording to job duties. ReserveManagerfor one or two accountable administrators. In the Shared drive settings, turn offAllow people who aren’t members of this shared drive to access filesand turn offAllow managers to share foldersif individual folder sharing is not needed. -
Require strong authentication for plan administrators. Go to
Security > Authentication > 2-Step Verification, select thePlan EPHIorganizational unit, and set enforcement toOn. Set an appropriate enforcement date and use phishing-resistant methods, such as security keys or passkeys, for Shared drive managers when available. This is not a Drive-sharing control, but it materially reduces the risk that a compromised account exposes plan ePHI. -
Turn on audit visibility and retention. Go to
Reporting > Audit and investigation > Drive log eventsto confirm Drive audit logging is available. If your edition includes Google Vault, go toApps > Google Workspace > Google Vaultand establish a retention rule for the plan’s Drive data that aligns with the plan’s record-retention schedule and legal advice. Retention is not a substitute for backups or access controls, but it supports availability and investigation.
Which settings should the Plan EPHI unit have?
| Google Workspace setting | Required Plan EPHI value | Risk addressed |
|---|---|---|
| Sharing outside of your organization | Off | Prevents uncontrolled external disclosure of plan ePHI. |
| Publishing options | Public and unlisted publishing off | Prevents internet-accessible files and anonymous links. |
| Default link access | Restricted | Requires authenticated, named recipients. |
| Allow users to create shared drives | Off | Prevents unapproved plan-data repositories. |
| Shared drive membership | Restricted access group only | Supports required plan/sponsor separation. |
| 2-Step Verification | Enforced | Reduces account-takeover exposure. |
How do you verify that the Google Drive restrictions actually took effect?
Verification should include both an administrator review and a user-level test. In Apps > Google Workspace > Drive and Docs > Sharing settings, select the Plan EPHI organizational unit and confirm that each setting displays as locally configured rather than inherited from the parent unit. If a setting is inherited, select Override before saving the restrictive value.
Next, sign in as a test user who belongs to the Plan EPHI unit. Create a test document in the approved Shared drive, select Share, and attempt to add an external Gmail address. Google Drive should prevent the share. Also confirm that the General access area displays Restricted and does not offer public or external-link options. Finally, sign in as a typical employee outside the approved access group and verify that the Shared drive is not visible and that a direct file URL returns an access-denied message.
Review membership monthly by opening the access group in Directory > Groups and comparing members to the plan administrator authorization list. The most important test is not whether the configuration looks correct; it is whether an unauthorized sponsor employee is actually unable to open the file.
What evidence should you capture for a HIPAA assessor?
An assessor will want evidence that the controls were configured, are operating, and are connected to the group health plan’s documented requirements. Capture dated evidence at implementation and at least annually thereafter.
- A screenshot of
Directory > Organizational unitsshowing thePlan EPHIunit and its authorized users. - Screenshots or a PDF export of the Drive and Docs sharing settings for that unit, showing external sharing off, restricted link access, and public publishing disabled.
- A screenshot of
Apps > Google Workspace > Drive and Docs > Manage shared drivesshowing that Shared drive creation is disabled for the unit. - A membership export or screenshot for
plan-ephi-drive-access@company.com, including group owners and members. - A screenshot of the approved Shared drive’s member list and settings, including the prohibition on access by non-members.
- A Drive audit-log export from
Reporting > Audit and investigation > Drive log eventsshowing sharing and access events for a selected review period. - The relevant plan-document amendment, workforce authorization procedure, vendor agreements, and security-incident reporting procedure required by §164.314(b)(2).
Where do Google Workspace sharing controls fall short?
Google Workspace settings alone do not satisfy §164.314(b)(1). They cannot amend the plan document, determine whether an employee has a legitimate plan-administration role, ensure a third-party administrator contract contains appropriate HIPAA terms, or guarantee that the plan sponsor reports incidents to the group health plan. Those gaps require governance: plan-document language, a formal authorization matrix, access-review records, vendor due diligence and agreements, workforce training, and an incident-response process with clear notice obligations.
There are also technical limitations. Disabling external sharing does not prevent an authorized user from viewing information and copying it into another system, taking a screenshot, or mishandling downloaded data. Consider Google Workspace Enterprise features such as Drive data loss prevention rules, context-aware access, endpoint management, and investigation tools where the risk assessment supports the investment. For particularly sensitive plan files, combine the restricted Drive design with managed devices, encryption, endpoint controls, and a documented process for revoking access immediately when a plan-administration role ends.
Next step: Ask your Workspace administrator and privacy counsel to review this restricted-unit design against your plan document, then fund a quarterly access-review process for the approved Plan EPHI Shared drive.