Have been looking into issues of Gmail and HIPAA compliance (it isn't).
Turns out something has changed recently.
Google Apps for Business now is willing to sign a Business Associate Agreement (BAA) so that email, calendar and cloud storage can be HIPAA compliant. This appears to be new as of September, 2013.
This does NOT apply to conventional Gmail and Google accounts, but does apply to the Google Apps for Business accounts (50$ per user per year, I believe).
I have been using Google Apps for Business for a while, and was just considering switching to Microsoft Office 365 since it had been the only major cloud provider that was willing to sign a BAA, when I found out about this change to Google Apps.
For their help page, see here:
https://support.google.com/a/answer/3407054?hl=en Obviously, this doesn't make emailing with patients HIPAA compliant of itself, and I'm not sure whether or not any additional encryption is needed for email, but anyone who already is using Google Apps for Business should look into the BAA.
Michael
NY