How to Set Google Drive Sharing Settings for Plan ePHI

How to Set Google Drive Sharing Settings for Plan ePHI

Configure google drive sharing settings for plan ephi with a restricted Workspace unit, no external sharing, audit evidence, and access controls.

LakeRidge Team
July 18, 2026
8 min read

Share:

Schedule Your Free Compliance Consultation

Feeling overwhelmed by compliance requirements? Not sure where to start? Get expert guidance tailored to your specific needs in just 15 minutes.

Personalized Compliance Roadmap
Expert Answers to Your Questions
No Obligation, 100% Free

CMMC Phase 2 begins November 10, 2026.

To set google drive sharing settings for plan ephi, place only authorized plan-administration staff in a dedicated Google Workspace organizational unit, disable external sharing and public-link access for that unit, and store plan records in tightly managed Shared drives. Google Workspace can provide the technical safeguards supporting HIPAA 45 CFR §164.314(b)(1), but the group health plan’s documents must also require the plan sponsor, its workforce, and its vendors to follow those safeguards and report security incidents.

What does HIPAA require for group health plan ePHI in Google Drive?

HIPAA’s group health plan plan-sponsor provision at §164.314(b)(1) requires the plan documents to require the sponsor to reasonably and appropriately safeguard electronic protected health information it creates, receives, maintains, or transmits for the plan. The related implementation specifications in §164.314(b)(2) require safeguards for confidentiality, integrity, and availability; support for the required separation between plan functions and sponsor functions; appropriate safeguards by agents and subcontractors; and incident reporting to the plan.

For a COO or finance leader, the practical point is that a general corporate Google Drive configuration is usually not enough. Payroll, benefits, HR, and finance employees may have legitimate business access to corporate files but no permitted reason to access plan ePHI. A dedicated Workspace organizational unit and a restricted Shared drive create a defensible technical boundary around the limited staff who administer the group health plan.

How do you configure google drive sharing settings for plan ephi in Google Workspace?

Use a dedicated organizational unit called Plan EPHI and apply more restrictive Drive settings to that unit than to the general employee population. Perform these steps with a Super Admin account or a delegated administrator with the necessary Drive and organizational-unit privileges. Menu labels can vary slightly by Google Workspace edition, but the administrative paths below reflect the Google Admin console.

  1. Create the restricted organizational unit. In the Google Admin console, go to Directory > Organizational units, select the appropriate parent organization, and choose Create new organizational unit. Name it Plan EPHI. Move only workforce members who perform plan administration into this unit, such as the benefits manager and specifically authorized HR or payroll personnel. Do not place all HR, finance, or executive users in this unit merely because they may occasionally request reports.

  2. Create an access group for the Shared drive. Go to Directory > Groups > Create group. Create a restricted group such as plan-ephi-drive-access@company.com, set Who can join the group to Invited users only, and limit member viewing and conversation access to group members where your operating model permits. Require an owner approval process for membership changes. This group becomes the repeatable, auditable method for granting access.

  3. Turn off sharing outside the organization for the Plan EPHI unit. Go to Apps > Google Workspace > Drive and Docs > Sharing settings. In the left panel, select the Plan EPHI organizational unit. Under Sharing options, select Sharing outside of your organization and set it to Off. Save the change. This prevents users in the unit from sharing Drive files with personal Gmail accounts, brokers, consultants, or other external recipients through ordinary Drive sharing.

  4. Disable public and link-based publishing. In the same Sharing settings page and with the Plan EPHI unit selected, locate Publishing options. Turn off Allow users to publish files on the web or make them visible to the world as public or unlisted files. Also set the organization’s link-sharing default so files are Restricted, rather than Anyone in your organization with the link. Restricted sharing requires a named, authenticated user to receive access.

  5. Prevent inbound external content where the business process does not need it. Still under Apps > Google Workspace > Drive and Docs > Sharing settings, select Sharing options and disable Allow users in your organization to receive files from users outside of your organization for the Plan EPHI unit if plan staff do not need outside parties to share files into Drive. If the plan must receive material from a broker, TPA, or legal adviser, use a documented approved channel and a contractual arrangement rather than opening inbound sharing broadly.

  6. Limit Shared drive creation. Go to Apps > Google Workspace > Drive and Docs > Manage shared drives. For the Plan EPHI unit, set Allow users to create shared drives to Off. This avoids unmanaged plan repositories. Have an administrator create one approved Shared drive, such as Group Health Plan - Restricted.

  7. Configure the approved Shared drive. Open Google Drive as the administrator, select Shared drives, open Group Health Plan - Restricted, and select the drive name followed by Manage members. Add plan-ephi-drive-access@company.com as Content manager or Contributor according to job duties. Reserve Manager for one or two accountable administrators. In the Shared drive settings, turn off Allow people who aren’t members of this shared drive to access files and turn off Allow managers to share folders if individual folder sharing is not needed.

  8. Require strong authentication for plan administrators. Go to Security > Authentication > 2-Step Verification, select the Plan EPHI organizational unit, and set enforcement to On. Set an appropriate enforcement date and use phishing-resistant methods, such as security keys or passkeys, for Shared drive managers when available. This is not a Drive-sharing control, but it materially reduces the risk that a compromised account exposes plan ePHI.

  9. Turn on audit visibility and retention. Go to Reporting > Audit and investigation > Drive log events to confirm Drive audit logging is available. If your edition includes Google Vault, go to Apps > Google Workspace > Google Vault and establish a retention rule for the plan’s Drive data that aligns with the plan’s record-retention schedule and legal advice. Retention is not a substitute for backups or access controls, but it supports availability and investigation.

Which settings should the Plan EPHI unit have?

Google Workspace setting Required Plan EPHI value Risk addressed
Sharing outside of your organization Off Prevents uncontrolled external disclosure of plan ePHI.
Publishing options Public and unlisted publishing off Prevents internet-accessible files and anonymous links.
Default link access Restricted Requires authenticated, named recipients.
Allow users to create shared drives Off Prevents unapproved plan-data repositories.
Shared drive membership Restricted access group only Supports required plan/sponsor separation.
2-Step Verification Enforced Reduces account-takeover exposure.

How do you verify that the Google Drive restrictions actually took effect?

Verification should include both an administrator review and a user-level test. In Apps > Google Workspace > Drive and Docs > Sharing settings, select the Plan EPHI organizational unit and confirm that each setting displays as locally configured rather than inherited from the parent unit. If a setting is inherited, select Override before saving the restrictive value.

Next, sign in as a test user who belongs to the Plan EPHI unit. Create a test document in the approved Shared drive, select Share, and attempt to add an external Gmail address. Google Drive should prevent the share. Also confirm that the General access area displays Restricted and does not offer public or external-link options. Finally, sign in as a typical employee outside the approved access group and verify that the Shared drive is not visible and that a direct file URL returns an access-denied message.

Review membership monthly by opening the access group in Directory > Groups and comparing members to the plan administrator authorization list. The most important test is not whether the configuration looks correct; it is whether an unauthorized sponsor employee is actually unable to open the file.

What evidence should you capture for a HIPAA assessor?

An assessor will want evidence that the controls were configured, are operating, and are connected to the group health plan’s documented requirements. Capture dated evidence at implementation and at least annually thereafter.

  • A screenshot of Directory > Organizational units showing the Plan EPHI unit and its authorized users.
  • Screenshots or a PDF export of the Drive and Docs sharing settings for that unit, showing external sharing off, restricted link access, and public publishing disabled.
  • A screenshot of Apps > Google Workspace > Drive and Docs > Manage shared drives showing that Shared drive creation is disabled for the unit.
  • A membership export or screenshot for plan-ephi-drive-access@company.com, including group owners and members.
  • A screenshot of the approved Shared drive’s member list and settings, including the prohibition on access by non-members.
  • A Drive audit-log export from Reporting > Audit and investigation > Drive log events showing sharing and access events for a selected review period.
  • The relevant plan-document amendment, workforce authorization procedure, vendor agreements, and security-incident reporting procedure required by §164.314(b)(2).

Where do Google Workspace sharing controls fall short?

Google Workspace settings alone do not satisfy §164.314(b)(1). They cannot amend the plan document, determine whether an employee has a legitimate plan-administration role, ensure a third-party administrator contract contains appropriate HIPAA terms, or guarantee that the plan sponsor reports incidents to the group health plan. Those gaps require governance: plan-document language, a formal authorization matrix, access-review records, vendor due diligence and agreements, workforce training, and an incident-response process with clear notice obligations.

There are also technical limitations. Disabling external sharing does not prevent an authorized user from viewing information and copying it into another system, taking a screenshot, or mishandling downloaded data. Consider Google Workspace Enterprise features such as Drive data loss prevention rules, context-aware access, endpoint management, and investigation tools where the risk assessment supports the investment. For particularly sensitive plan files, combine the restricted Drive design with managed devices, encryption, endpoint controls, and a documented process for revoking access immediately when a plan-administration role ends.

Next step: Ask your Workspace administrator and privacy counsel to review this restricted-unit design against your plan document, then fund a quarterly access-review process for the approved Plan EPHI Shared drive.

 

Quick & Simple

Discover Our Cybersecurity Compliance Solutions:

Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you

 CMMC Level 1 Compliance App

CMMC Level 1 Compliance

Become compliant, provide compliance services, or verify partner compliance with CMMC Level 1 Basic Safeguarding of Covered Contractor Information Systems requirements.
 NIST SP 800-171 & CMMC Level 2 Compliance App

NIST SP 800-171 & CMMC Level 2 Compliance

Become compliant, provide compliance services, or verify partner compliance with NIST SP 800-171 and CMMC Level 2 requirements.
 HIPAA Compliance App

HIPAA Compliance

Become compliant, provide compliance services, or verify partner compliance with HIPAA security rule requirements.
 ISO 27001 Compliance App

ISO 27001 Compliance

Become compliant, provide compliance services, or verify partner compliance with ISO 27001 requirements.
 FAR 52.204-21 Compliance App

FAR 52.204-21 Compliance

Become compliant, provide compliance services, or verify partner compliance with FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems requirements.
 ECC Compliance App

ECC Compliance

Become compliant, provide compliance services, or verify partner compliance with Essential Cybersecurity Controls (ECC – 2 : 2024) requirements.