Keeping Google Workspace organized and properly secured is one of the most important steps a home-based care agency can take to protect patient data, maintain HIPAA compliance, and reduce cybersecurity risk. Below are answers to some of the most common questions home-based care agencies have about Google Workspace organization, access control, and permission management.
1. Why does it matter for home-based care where files are stored in Google Workspace?
Files stored in an individual employee’s My Drive are owned by that employee, not the organization. If that person leaves and their account is deleted or suspended, the agency can lose access to years of client records, care documentation, and operational files. Shared Drives, by contrast, are owned by the organization and remain fully accessible regardless of employee turnover. For home-based care agencies, keeping all client and business files in Shared Drives is a foundational step toward better data control and continuity.
2. What is the difference between Shared Drives and My Drive?
My Drive is personal storage tied to an individual Google account. Shared Drives are organizational storage spaces where files belong to the team, not to any individual user. When a staff member is added to or removed from a Shared Drive, their access changes accordingly. This structure makes Shared Drives far better suited for business-critical files in a home-based care environment.
3. What is the principle of least privilege and why does it matter for home-based care?
Least privilege means giving each staff member access only to the files and folders their specific role requires, nothing more. In a home-based care agency, a caregiver does not need visibility into HR records, and a scheduler does not need access to financial files. Applying least privilege reduces the risk of accidental deletion, unauthorized viewing, and data leaks, and limits the damage if any account is ever compromised.
4. What are Google Groups and how should home-based care agencies use them?
Google Groups are organizational email and access management lists. In Google Workspace, agencies can create groups aligned to job roles, such as caregivers, schedulers, billing, clinical, and leadership, and assign Shared Drive permissions at the group level rather than adding individuals one by one. When a new employee joins a role, they are added to the group and inherit the correct access automatically. When they leave, removing them from the group revokes access across all asociated resources at once.
5. What external sharing settings should home-based care agencies change?
Google Workspace’s default settings allow users to share files with people outside the organization. For agencies handling protected health information, those defaults create meaningful risk. Through the Google Workspace Admin Console, agencies should:
- Disable “Anyone with the link” sharing for Shared Drives containing client or business-sensitive data
- Restrict or disable external sharing for Shared Drives containing ePHI
- Enable audit logging to track file access and sharing changes over time
These settings are not active by default and require deliberate configuration.
6. What is a permission audit and how often should agencies conduct one?
A permission audit is a structured review of who has access to what within your Google Workspace environment. It involves checking active user accounts, verifying that access levels still match current roles, and revoking any permissions that are no longer appropriate. Home-based care agencies should conduct permission audits at least quarterly or biannually, and also whenever a staff member changes roles, a department restructures, or a contractor completes an engagement. Designating a specific person responsible for conducting and documenting these reviews is essential.
7. What should happen to Google Workspace access when an employee leaves?
Access should be revoked immediately as part of every offboarding. This includes:
- Suspending or deleting the departing employee’s Google account
- Transferring ownership of any files they held in My Drive to an appropriate organizational owner
- Reviewing and removing any direct permissions they held on Shared Drives or individual folders
- Removing them from all Google Groups to eliminate inherited access
Delays in this process are one of the most common and overlooked security gaps in home-based care agencies. For agencies handling ePHI, prompt access revocation is a HIPAA Security Rule requirement, not just a best practice.
8. How does disorganized Google Workspace affect HIPAA compliance?
When ePHI is scattered across personal My Drive accounts, accessible to staff who do not need it, or visible to former employees who still have active accounts, those conditions can each constitute a HIPAA Security Rule violation. The Security Rule requires covered entities to implement technical safeguards that control access to ePHI, conduct periodic reviews of information system activity, and have procedures in place to terminate access when employment ends. A well-organized, properly permisssioned Google Workspace environment directly supports each of those requirements.
9. How does Google Workspace organization affect cyber insurance?
Cyber insurance applications increasingly ask detailed questions about access controls, permission management, and offboarding procedures. Agencies that cannot demonstrate structured access controls, documented permission audits, or a clear offboarding process may face higher premiums or reduced coverage eligibility. A well-configured Google Workspace environment, with role-based access, restricted sharing settings, and a documented audit cadence, provides tangible evidence of a proactive security posture that insurers look for.
10. How can IT Total Care help with Google Workspace organization and access control?
IT Total Care works with home-based care agencies throughout the San Francisco Bay Area to design, implement, and maintain Google Workspace environments built for security, compliance, and operational clarity. Our services include:
- Designing a standardized, role-based Shared Drive structure tailored to your agency’s workflow
- Configuring Google Groups aligned to job roles for streamlined permission management
- Applying least-privilege access controls across your entire Google Workspace environment
- Locking down external sharing settings and enabling audit logging through the Admin Console
- Conducting scheduled permission audits and removing outdated access on your behalf
- Ensuring Google Workspace access is revoked immediately as part of every coordinated offboarding
- Documenting folder structures and permission policies so the system stays organized as your team grows
“Approximately half of the home-based care agencies we work with have SharePoint setup incorrectly when we start working with them. This incorrect setup via confusing folder structures, inaccurate permissions, and lack of clean-up have a significant negative effect on the team. Fortunately, by taking the time to correctly setup and regularly review their SharePoint we see home care, home health, and home hospice companies significantly improve their efficiency and provide better care.”
Brendan Duebner, President, IT Total Care
Need Help Organizing and Securing Your Google Workspace Environment?
IT Total Care helps home-based care agencies across the San Francisco Bay Area build secure, well-organized Google Workspace environments that support HIPAA compliance, protect patient data, and reduce operational risk. Reach out today to learn how we can help your agency get this right.




