This comes up constantly with small medical and dental practices: someone on staff is already comfortable with Google Calendar, so patient appointments end up booked there — sometimes on a free personal account, sometimes on a paid Workspace account nobody's checked the compliance details on. Calendly gets used the same way, often for a public booking link.
Google will sign a Business Associate Agreement covering Google Workspace's core services, Calendar included — but only for paid Workspace accounts, not the free, personal Gmail accounts a lot of solo and small practices default to. If your practice is on a personal Gmail account, or a Workspace plan without a signed BAA on file, using that Calendar for patient appointments is a compliance gap, full stop.
Even with a Workspace BAA in place, the BAA covers the underlying infrastructure — it doesn't add the things a healthcare-specific compliance review usually looks for: a record of who created, viewed, or changed an appointment; separate staff logins with different access levels; or a session that locks itself after the front desk walks away from an idle screen. Google Calendar wasn't built for any of that, because it isn't scheduling software for healthcare — it's a general-purpose calendar.
Calendly's BAA is available on its Enterprise plan only, which is priced and sold toward larger organizations, not a two-to-five-provider practice. On Calendly's Free, Standard, and Teams tiers, there's no BAA offered at all — which means patient scheduling on those tiers isn't covered.
| Google Calendar | Calendly | Kenko | |
|---|---|---|---|
| BAA available | Paid Workspace plans only | Enterprise plan only | Yes, on the one plan |
| Free/personal tier covered | No | No | N/A — no free tier holds patient data |
| Audit trail of record changes | No | No | Yes |
| Automatic session timeout | No | No | Yes, 15 minutes |
| Built for multi-provider practices | Not specifically | Partially | Yes |
A BAA is the starting point, not the finish line. See the full checklist — audit trail, access roles, session timeout, and what to ask any vendor before signing up.
Read the full checklistOnly under specific conditions. Google will sign a BAA for Google Workspace core services, including Calendar, but only on paid Workspace plans — not personal Gmail accounts. Even with a signed BAA, it doesn't give you an audit trail, per-record access controls, or an automatic session timeout, which most healthcare compliance programs also expect.
Calendly offers a BAA, but only on its Enterprise plan, priced for larger organizations. On Calendly's lower tiers, there's no BAA available, which means it shouldn't be used to schedule patients.
No. Free, personal Gmail accounts aren't covered by a Google BAA, so using a personal Google Calendar to store or schedule patient appointments is a HIPAA compliance gap for any US medical or dental practice.
A signed BAA available before any patient data is entered, an audit trail of record changes, role-based access for staff, and an automatic session timeout on idle devices. See the full HIPAA-compliant scheduling checklist.
Signed BAA on every plan, audit trail included, 14-day free trial.
Start your free trial