“We signed Google's BAA so we're compliant.”
The BAA covers Google's obligations, not yours. Sharing settings, admin permissions, and whether staff can forward patient emails to personal accounts are all on you. The BAA is the starting line, not the finish.