Is Gemini in Google Analytics HIPAA Compliant?
Gemini in GA4 is not HIPAA compliant because Google Analytics has no BAA. What the AI layer changes, what it does not, and how clinics get those answers safely.
No. Gemini in Google Analytics is not HIPAA compliant, because Google Analytics 4 is not HIPAA compliant, and an AI feature cannot be covered by a Business Associate Agreement that does not exist. Google does not sign a BAA for GA4, so every AI feature inside it (Gemini-powered insights, the question box, Analytics Intelligence) inherits the same status as the reports it reads. The part worth your time is what the AI layer changes about the risk you already had, which is less than most people assume, and what a clinic should use instead. Curve built its own analytics assistant on data collected under a BAA, so we will use it as the reference point for what "compliant" has to mean here.
TL;DR
- Google does not sign a BAA for Google Analytics 4. Gemini in GA4, Analytics Intelligence, and any future AI feature inside the product inherit that.
- The problem is upstream of the AI. GA4 collects in the visitor's browser and processes on Google's servers with no BAA in place. The AI only reads what is already there.
- The AI layer adds little new exposure. It makes the existing exposure easier to see, and easier to paste into an email that later turns up in a compliance review.
- Google's healthcare BAA terms cover Google Cloud and Workspace. GA4 is a different product under different terms, and a Cloud BAA does not reach across.
- A compliant equivalent collects analytics on the server under a BAA and runs the AI inside that same boundary. That is how Curve Analyst works.
- Most of what clinics wanted from GA4's AI (trend against last period, best converting sources, worst bouncing pages) is answerable without Google touching the data.
Why is Google Analytics 4 the problem, and not Gemini?
Start with the pipe, not the chatbot. GA4 works by placing a Google tag on every page of your site. When a visitor loads a page, their browser sends a hit directly to Google: the URL, the page title, an identifier stored in a cookie, their IP address, device and browser details, and whatever parameters were on the URL. Google receives that on its own servers, processes it, and stores it in your property.
On a clinic website, the URL alone is often enough. A path like /services/ketamine-therapy/book says something about the person who loaded it. Pair it with a persistent identifier and an IP address and you are describing an identifiable person and the care they are looking for. Under HIPAA, a vendor that handles that kind of information on your behalf is a business associate, and a business associate needs a BAA. Google does not offer one for Google Analytics. That is the whole case, and it was settled long before Gemini showed up in the interface.
None of this depends on what Google does with the data afterwards. The disclosure happens at collection. Whether the data then sits in a standard report or gets summarised by a language model is downstream of a transfer that should not have happened. If you want the longer version of the GA4 argument, with the alternatives laid out, it is in Is Google Analytics 4 HIPAA compliant, and what healthcare alternatives exist.
Does adding Gemini make GA4 more risky?
A little, and not in the way people assume. The data Gemini reads is the property data you were already sending. Asking "which landing pages had the most conversions last month" does not transmit anything new to Google; the pageviews and conversion events were already there. If your objection to GA4 is the missing BAA, the AI does not change the underlying exposure much. What it changes is visibility, in two directions.
It makes the exposure legible
A raw GA4 exploration is opaque to most practice owners. A sentence from an AI is not. "Your ketamine therapy booking page had the highest conversion rate from paid search" is a plain restatement of what the tag has been collecting all along, sitting in a Google product with no agreement governing it. An auditor understands it faster than a table of dimensions and metrics. Nothing new leaked when that sentence was generated. It did become harder to argue that nothing had.
It invites questions you should not be asking there
The question box lowers the effort of a query to nearly zero, and the queries people reach for first are the ones with the most health context in them. "How many visitors from the fertility campaign reached the consultation form?" "Which cities do our addiction treatment inquiries come from?" Each of those is a legitimate marketing question. Each is also a question you are typing into a Google product about people seeking care, with no BAA covering the question or the answer. A clinic that already should not be on GA4 should not be asking Gemini about GA4 data. The second mistake is the first mistake with a better interface.
Doesn't Google sign a BAA? Cloud and Workspace versus Analytics
Yes, for some products, and this is where most of the confusion lives. Google will sign a BAA for eligible Google Cloud services and for Google Workspace. So a practice manager hears "Google signs a BAA" and assumes the analytics dashboard is covered as well.
It is not. The Cloud BAA covers Cloud services. The Workspace BAA covers Workspace. Google Analytics is a separate product under separate terms, and Google does not offer a BAA for it. Gemini in Analytics is a feature of Analytics, so it sits on the uncovered side of that line regardless of what the same company signs for its Cloud customers.
Two things follow. First, "we have a Google BAA" is not an answer to "is your GA4 compliant". Ask which agreement, and which product list is attached to it. Second, if a vendor or agency tells you the Gemini features make GA4 safer because Google's AI is available under healthcare terms elsewhere, they are mixing up two product lines. Confirm current terms with Google directly. Product lists change, and you should read the contract rather than trust a blog post, including this one.
What does a compliant equivalent look like?
Same questions, different pipe. For an AI analytics feature to be usable by a covered entity, the collection, the storage, and the model all have to sit inside a BAA boundary, and the data cannot leave that boundary to be answered.
Collection happens on your side of a BAA
The visitor's browser should talk to a server run by a vendor that has signed a BAA with you, and that server decides what leaves. Curve's tag sends events to Curve's US-hosted infrastructure first, server-side. Curve strips what should not leave, then forwards conversion signals to Google Ads, Meta, TikTok, Microsoft, LinkedIn, and the other ad platforms. Google Analytics is not in the path unless you put it there. Curve signs a BAA with every customer on every plan, which is the point of the arrangement rather than an upgrade.
The analytics live in that same environment
Visitors, sessions, pageviews, bounce rate, top pages, sources, channels, UTM breakdowns, devices, goals, funnels, ad spend, and attributed conversions are all computed from data that never went to a party without a BAA. That is the part GA4 cannot offer at any price, because the collection step is the product.
The AI reads the data in place
This is where most "chat with your data" tools fall down for healthcare. They generally want your data loaded into their platform first, which means a second vendor, a second BAA question, and a second copy of the data. Whether any given vendor signs a BAA varies by product and plan, and you have to verify each one yourself.
Curve Analyst takes the other approach. It is an AI chat inside the Curve dashboard. You type a question, it runs a query against your own account's data, and it answers with text plus a rendered chart: a line for trends, a table for ranked lists, a stat card for totals, a step chart for funnels. The model is Claude, running through Amazon Bedrock inside infrastructure covered by Curve's BAA with AWS. Bedrock is a HIPAA-eligible AWS service. Your data is not exported to a separate AI product and is not used to train models.
We built it read-only. It cannot change tracking, edit destinations, or take actions, and it does not look up individuals or answer questions about a specific person. It also refuses to estimate. Every number is a query result; empty metrics are reported as empty; if data is stale, partial, sample, or still syncing, it says so before the number. Unknown and zero are treated as different things, which sounds like a small detail until you have presented a "zero conversions" chart to a practice owner and found out afterwards that the connector was down for a week.
It does not do everything. Analyst does not open session recordings or heatmaps, does not write SQL, and does not yet answer questions about tracking configuration or connector health. A fuller walkthrough is at What is Curve Analyst.
What did clinics actually want from GA4's AI?
We have watched a lot of healthcare marketers poke at the GA4 question box, and the questions are boring in the best way. Nobody wants to interrogate an individual patient journey. They want to survive the Monday meeting.
Is traffic up or down, and compared to what?
The most common question, and the one GA4 makes oddly laborious: a date comparison, a channel filter, and enough patience to build the comparison yourself. Curve keeps the date range and filters of the screen you opened Analyst from, so "how does this compare to the previous period" is answered against the window you were already looking at, with both periods on one line chart.
Which sources actually converted?
Not which sources sent traffic. Which sent people who booked. GA4 answers this with its own attribution model, which you cannot line up against what your ad accounts claimed. Curve reports its own attributed conversions, credited by Curve's attribution engine under the model you chose, with spend, clicks, and impressions pulled from the platforms directly. Analyst tells you which number it is quoting, and its reconciliation view puts what Curve sent to Google or Meta next to what the platform credited. When those differ, it is usually the platform's attribution window still being open rather than under-reporting, and you can say that in the meeting without flinching.
Which pages are people leaving from?
Bounce rate by page, sorted worst first. This is a single question in Analyst and comes back as a ranked table. The follow-up, "and which of those pages get paid traffic", is another single question. Neither needed to pass through a vendor without a BAA.
Referrals from AI assistants such as ChatGPT and Perplexity also appear as their own rows in the Curve sources report, so whether being cited in an AI answer sends anyone to the site has a direct answer. More on the questions clinics start with is in Ask your analytics: the questions clinics start with.
What should a clinic on GA4 do now?
Stop asking Gemini questions about the property. That costs nothing and takes effect today. Then deal with the property itself.
- Inventory where the GA4 tag fires. Marketing site, booking flow, any page a patient reaches after they identify themselves. The booking flow is where the URLs get specific.
- Decide whether you can remove it outright. Many clinics can, because the reporting they actually use is traffic, sources, goals, and ad performance, and all of that is available from a vendor that signs a BAA.
- Check the downstream tools. If GA4 feeds a Looker Studio dashboard, the dashboard inherits the same problem, and putting a compliant vendor upstream does not fix a report still wired to the old property. The details are in Is Looker Studio HIPAA compliant.
- Move the AI question to a place that can answer it under a BAA. If the analytics are collected compliantly, asking an AI about them is fine. If they are not, no AI feature fixes that.
What to ask Curve Analyst
Open Analyst from the report you are already on, so it inherits that date range, and type these as written. Each comes back with a chart you can drop straight into the Monday deck.
- How did traffic trend this period compared to the previous period?
- Which sources converted best this period?
- Which pages have the highest bounce rate this period?
The launch post, Introducing Curve Analyst, has more examples, including funnel drop-off and campaign spend questions.
Frequently asked questions
Is Analytics Intelligence in GA4 HIPAA compliant?
No. Analytics Intelligence is a feature of Google Analytics, and Google does not sign a BAA for Google Analytics. The feature reads the same property data as every other report, so it has the same status as the property.
If I turn off the Gemini and AI features, is GA4 compliant?
No. The AI features are not what creates the exposure. The exposure is the tag sending visitor data to Google without a BAA. Disabling the question box leaves that collection untouched.
My organization has a Google Cloud BAA. Does it cover Google Analytics?
No. Google's healthcare BAA terms apply to eligible Google Cloud services and to Google Workspace. Google Analytics is a separate product and is not covered by either agreement. Confirm the current product list with Google, since it is the contract that governs, not a summary of it.
Is Curve Analyst HIPAA compliant?
Analyst runs on Claude through Amazon Bedrock, inside infrastructure covered by Curve's BAA with AWS, and Curve signs a BAA with every customer. It reads your account's data in place, does not export it to a separate AI product, does not use it for training, does not answer questions about individuals, and cannot take actions. It answers the same trend, source, and page questions you were asking GA4, from data that was collected under a BAA in the first place.
If you want to see what your own questions come back looking like on compliant data, book a demo of Curve and bring the three questions above.
Related articles
- GuideAI Health Platforms Are Replacing Google Search: How ChatGPT Health, Perplexity Health, and Gemini Change Patient Acquisition
- GuideGA4 Is Not HIPAA Compliant: 3 Analytics Alternatives That Are
- GuideIs Google Analytics 4 HIPAA Compliant? Why the Answer Is Still No in 2026
- GuideServer-to-Server Pixels Are Still Pixels: Google S2S and TikTok S2S in the FTC Complaint
Stay Compliant. Scale Confidently.
Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.
Book a free tracking audit