This document describes how Google Cloud and Google Workspace support the Health Insurance Portability and Accountability Act (HIPAA) and how you can configure Google Cloud to help meet your HIPAA responsibilities. This guide is intended for security officers, compliance officers, IT administrators, and other employees who are responsible for HIPAA implementation and compliance on Google Cloud and Google Workspace.
Shared responsibility
The U.S. Department of Health and Human Services (HHS) doesn't offer a certification program for HIPAA compliance. Complying with HIPAA is a shared responsibility between you and Google.
HIPAA requires compliance with the Security Rule, the Privacy Rule, and the Breach Notification Rule. Google Cloud and Google Workspace support HIPAA compliance within the scope of a Business Associate Agreement, but ultimately you are responsible for evaluating your own HIPAA compliance.
Google enters into Business Associate Agreements as necessary under HIPAA.
Customer responsibilities
You must determine the following:
- Whether you are a Covered Entity or a Business Associate of a Covered Entity.
- Whether you require a Business Associate Agreement with Google.
Google provides infrastructure security controls that are designed to support your HIPAA requirements for the storage and processing of PHI. You're responsible for ensuring that your environment and applications that you build on Google Cloud are properly configured and secured according to HIPAA requirements. For more information, see Shared fate.
For information about Google's approach to security and data protection, see the Google security overview and Google infrastructure security design overview.
Google Cloud features and pricing
The HIPAA BAA for Google Cloud includes the entire Google Cloud infrastructure, not only a subset of Google Cloud. As a result, you aren't restricted to a specific region and you can use multi-regional service redundancy. You can also use Spot VMs to reduce costs.
Google also offers HIPAA-regulated customers the same services at the same pricing that is available to all customers, including sustained use discounts.
Google Cloud supported services
Last updated: 2025-09-17
The Google Cloud BAA includes Google Cloud's entire infrastructure (all regions, all zones, all network paths, all points of presence), and the following products:
- Access Approval
- Access Context Manager
- Access Transparency
- Agent Assist for Google Cloud Contact Center as a Service (CCaaS)
- Agent Search on Gemini Enterprise Agent Platform [1]
- AI Platform Training and Prediction
- AlloyDB for PostgreSQL
- Antigravity in Gemini Enterprise
- API Gateway [2]
- Apigee
- App Engine
- Application Integration [3]
- Artifact Analysis
- Artifact Registry [4]
- Assured Workloads
- Audit Manager
- AutoML Natural Language
- AutoML Tables
- AutoML Translation
- AutoML Video
- AutoML Vision
- Backup and DR Service
- Backup for GKE
- Bare Metal Solution
- Batch
- BigQuery
- BigQuery Data Transfer Service
- BigQuery Omni
- Bigtable
- Binary Authorization
- Certificate Authority Service
- Certificate Manager
- Cloud Asset Inventory
- Cloud Build [5]
- Cloud CDN [6]
- Cloud Data Fusion
- Cloud Deploy
- Cloud Deployment Manager
- Cloud DNS
- Cloud Endpoints
- Cloud Healthcare API
- Cloud HSM (Hardware Security Module)
- Cloud Identity
- Cloud Interconnect
- Cloud Intrusion Detection System (Cloud IDS)
- Cloud Key Management Service [7]
- Cloud Life Sciences
- Cloud Load Balancing
- Cloud Logging [8]
- Cloud Monitoring [9]
- Cloud NAT
- Cloud Natural Language API
- Cloud Profiler
- Cloud Resource Manager API
- Cloud Router
- Cloud Run
- Cloud Run functions
- Cloud Scheduler
- Cloud Service Mesh
- Cloud Shell
- Cloud Source Repositories
- Cloud SQL
- Cloud Storage [10]
- Cloud Tasks
- Cloud Trace
- Cloud Translation
- Cloud Vision
- Cloud VPN
- Cloud Workstations
- Cluster Director
- Colab Enterprise
- Compute Engine
- Connect
- Container Registry [11]
- Conversational Agents [12]
- Customer Experience Agent Studio
- Customer Experience Insights
- Cyber Insurance Hub
- Data Catalog
- Data Studio [13]
- Database Migration Service [14]
- Dataflow
- Dataform
- Datastream
- Document AI
- Document AI Warehouse
- Eventarc
- Filestore [15]
- Firestore
- Firestore in Datastore mode (Datastore) [16]
- Gemini Code Assist
- Gemini Enterprise
- Gemini Enterprise Agent Platform
- Gemini Enterprise for Customer Experience
- Gemini in BigQuery
- Gemini in Colab Enterprise
- Gemini Notebook Enterprise
- Generative AI on Agent Platform
- Google Cloud Armor
- Google Cloud console
- Google Cloud Contact Center as a Service
- Google Cloud Fraud Defense [17]
- Google Cloud Identity-Aware Proxy (IAP)
- Google Cloud Managed Lustre
- Google Cloud Managed Service for Apache Kafka
- Google Cloud NetApp Volumes
- Google Cloud VMware Engine [18]
- Google Distributed Cloud connected [19]
- Google Kubernetes Engine
- Google Kubernetes Engine (GKE) Enterprise edition Config Management
- Google Kubernetes Engine (GKE) Hub
- Healthcare Data Engine
- Identity and Access Management (IAM) [21]
- Identity Platform [22]
- Infrastructure Manager
- Integration Connectors [23]
- Key Access Justifications
- Knative serving
- Knowledge Catalog [24]
- Looker (Google Cloud core) [25]
- Looker (original) [26]
- Managed Service for Apache Airflow
- Managed Service for Apache Spark
- Managed Service for Microsoft Active Directory (AD)
- Memorystore
- Model Armor
- Network Connectivity Center
- Network Service Tiers
- Persistent Disk
- Pub/Sub
- Secret Manager [27]
- Secure Source Manager
- Security Command Center
- Sensitive Data Protection [28]
- Service Directory
- Spanner
- Speech-to-Text [29]
- Storage Transfer Service
- Text-to-Speech
- Traffic Director API
- Transfer Appliance
- Vertex AI Workbench instances
- Video Intelligence API
- Virtual Private Cloud (VPC)
- VPC Service Controls
- Web Security Scanner
- Workflows
Google SecOps supported services
The following Google SecOps services[20] are supported by the BAA:
- Google Security Operations SIEM
- Google Security Operations SOAR
- Mandiant Digital Threat Monitoring
- Mandiant Security Validation
Google Workspace supported services
Last updated: 2025-08-31
The following Google Workspace services are included in the Google Cloud BAA:
- AppSheet
- Cloud Identity Management
- Gemini App (excluding Gemini in Google Chrome)
- Gemini in Google Workspace
- Gemini Mac App
- Gmail
- Google Apps Script
- Google Calendar
- Google Chat
- Google Cloud Search
- Google Drive (including Google Docs, Google Forms, Google Photos, Google Sheets, Google Slides, and Google Vids)
- Google Groups
- Google Keep
- Google Meet
- Google Sites
- Google Tasks
- Google Vault (if applicable)
- Google Voice (managed users only)
For information about HIPAA compliance for Google Workspace, see HIPAA compliance for Google Workspace.
Best practices for Google Cloud
Implement the best practices in this section to help meet your HIPAA obligations.
General Google Cloud best practices
Implement the following best practices:
- Enter in to a Google Cloud BAA. For instructions, see the Privacy compliance and records for Google Cloud to review and accept the BAA.
- Disable unsupported Google Cloud services when working with PHI. If you can't disable a service, you must not use it for PHI.
- Don't use pre-GA offerings as defined in the Service Specific Terms with PHI, unless expressly noted otherwise in a notice or other terms of the offering.
- When creating or updating resources, avoid including PHI or security credentials in resource metadata, because logs might capture that information. Audit logs never include resource data contents or query results, but they might capture resource metadata.
Identity, security, and encryption
The following table describes best practices and limitations for identity, security, and encryption services.
| Supported product | Best practices and limitations |
|---|---|
| Cloud KMS |
Determine whether your organization has encryption requirements beyond what's required by the HIPAA Security Rule. Customer content is encrypted at rest on Google Cloud. If you have additional encryption requirements, use Cloud KMS. |
| Identity and Access Management |
Use IAM best practices when configuring who has access to your project. In particular, because service accounts can be used to access resources, tightly control access to those service accounts and service account keys. |
| Identity Platform |
|
| Secret Manager |
When storing secrets in Secret Manager, review and follow the Secret Manager best practices. |
Logging, monitoring, and data protection
The following table describes best practices and limitations for logging, monitoring, and data protection services.
| Supported product | Best practices and limitations |
|---|---|
| Logging |
|
| Monitoring |
|
| Google SecOps |
Don't use the following services or features:
|
| Sensitive Data Protection |
When configuring Sensitive Data Protection jobs, ensure that any output data is written to storage targets configured as part of your secure environment. |
Storage and databases
The following table describes best practices and limitations for storage and database services.
| Supported product | Best practices and limitations |
|---|---|
| Cloud Storage |
Enable Object Versioning to help preserve historical archives and recover objects after accidental deletion. |
| Database Migration Service |
Use Private IP connectivity methods to avoid exposing a database containing PHI to the internet. |
| Filestore |
|
| Datastore |
When creating or configuring indexes, encrypt PHI, security credentials, or other sensitive data before using the data as an entity key, indexed property key, or indexed property value. For more information, see Datastore indexes. |
Data analytics and business intelligence
The following table describes best practices and limitations for data analytics and business intelligence services.
AI, machine learning, and conversational agents
The following table describes best practices and limitations for AI, machine learning, and conversational agent services.
| Supported product | Best practices and limitations |
|---|---|
| Agent Search on Gemini Enterprise Agent Platform |
Use regional APIs and resource locations for PHI. |
| Conversational Agents |
Don't include PHI or security credentials in your agent definition, including intents, training phrases, and entities. |
| Speech-to-Text |
If you have entered into a BAA with Google that covers any PHI obligations under HIPAA, don't opt in to data logging. |
Application development, integration, and networking
The following table describes best practices and limitations for application development, integration, and networking services.
| Supported product | Best practices and limitations |
|---|---|
| API Gateway |
Don't include PHI or PII in the headers. |
| Application Integration and Integration Connectors |
|
| Cloud Build |
Don't include PHI in build configuration files, source control files, or other build artifacts. |
| Cloud CDN |
Don't request caching of PHI. To prevent caching, see Prevent caching. |
| Fraud Defense |
Don't include PHI in URIs or actions. |
Compute, containers, and hybrid infrastructure
The following table describes best practices and limitations for compute, containers, and hybrid infrastructure services.
| Supported product | Best practices and limitations |
|---|---|
| Artifact Registry |
Artifact Registry encrypts data in repositories using Google default
encryption or
customer-managed encryption
keys (CMEK). Metadata, such as artifact names, is encrypted with
Google default encryption. This metadata can appear in logs and is
visible to any user account with the
Artifact
Registry Reader role ( |
| Container Registry |
Container Registry encrypts data in the storage buckets of your registries using Google default encryption or CMEK. To help prevent unauthorized access to PHI, see Best practices for securing containers. |
| VMware Engine |
Retain application-level access logs for an appropriate period to meet HIPAA requirements. |
| Distributed Cloud connected |
When deploying Distributed Cloud connected, you're responsible for certain security aspects, particularly physical security. To help secure your deployment, see Physical security best practices. |
Looker (original)
The following table describes best practices and limitations for Looker when deployed in a hosted environment by Google.
| Item | Best practices and limitations |
|---|---|
| Excluded services |
Don't use the following services, which aren't supported by the BAA:
|
| Access controls |
Consider the following when implementing access controls:
|
| Data sharing |
Consider the following when sharing data:
|
| Secure configuration |
Consider the following when configuring security:
|
| Database security controls |
Consider the following when configuring database security controls:
|
What's next
- Learn more about Google's security in the Google security overview and the Google infrastructure security design overview.
- Review HHS Health Information Privacy (HIPAA).
- Review the HHS guidance on HIPAA compliance and cloud computing.