And given what the adtech space has been able to figure out pretty easily in terms of tracking even people who take serious steps to avoid it, you should not think that there is any reasonable amount of "anonymization" that can make otherwise-useful medical details safe to release.
Because the order of the entries in the bag of words is arbitrary, and the words have been hashed, it is impossible to go back from a bag of words representation to the original email. I don't know if this is what google does, but it is pretty normal to do so.
We took at look at this recently [3], and it turns out that mapping the word numbers back to the original words is actually a lot more doable than you'd think.
[1] ShadowCrypt: Encrypted Web Applications for Everyone http://dl.acm.org/citation.cfm?doid=2660267.2660326
[2] Mimesis Aegis: A Mimicry Privacy Shield–A System’s Approach to Data Privacy on Public Cloud https://www.usenix.org/conference/usenixsecurity14/technical...
[3] The Shadow Nemesis: Inference Attacks on Efficiently Deployable, Efficiently Searchable Encryption https://www.sigsac.org/ccs/CCS2016/agenda/