No, out of the box Gmail is not HIPAA compliant. By default, they don’t provide you with a Business Associate Agreement. However, you can get a BAA from Google when setting up the administrator account on your company’s G suite profile. Further, Gmail does encrypt the message body and attachments. Encryption is a necessity for sending HIPAA compliant email. You will need a 3rd party add-on to encrypt your messages with Gmail. TotalHIPAA has a complete article on Gmail and HIPAA compliance you can find here.
Rather than going through all this to try and make your Gmail HIPAA compliant, you can simply sign up for a MailHippo account. MailHippo works great with Gmail and any other email provider. Click here to see how MailHippo works.