本文档介绍了 Google Cloud 和 Google Workspace 如何支持《健康保险流通与责任法案》(HIPAA),以及如何配置 Google Cloud 以帮助您履行 HIPAA 规定的职责。本指南面向安全官员、合规官员、IT 管理员及其他负责在 Google Cloud 和 Google Workspace 上实施和遵守 HIPAA 合规性的员工。
共担责任
美国卫生与公众服务部 (HHS) 不提供 HIPAA 合规性认证计划。遵守 HIPAA 是您与 Google 共同承担的责任。
HIPAA 要求遵守其安全规则、隐私规则和违规通知规则。 Google Cloud Google Workspace 提供 HIPAA 遵从支持(在《业务伙伴协议》范围内),但您负有评估自身 HIPAA 合规性的最终责任。
Google 会根据 HIPAA 的规定,在必要时签订《业务伙伴协议》。
客户责任
您必须确定以下内容:
- 您是医疗保健服务机构还是医疗保健服务机构的业务伙伴。
- 您是否需要与 Google 签订《业务伙伴协议》。
Google 提供旨在支持您在存储和处理 PHI 方面满足 HIPAA 要求的基础设施安全控制措施。您负责确保根据 HIPAA 要求正确配置和保护在 Google Cloud 之上构建的环境和应用。如需了解详情,请参阅共同命运。
如需了解 Google 在安全和数据保护方面采取的做法,请参阅 Google 安全概览和 Google 基础架构安全设计概览。
Google Cloud 功能和价格
Google Cloud 的 HIPAA BAA 涵盖整个 Google Cloud基础架构,而不仅仅是 Google Cloud的一部分。因此,您不会受限于特定区域,并且可以使用多区域服务冗余。您还可以使用 Spot 虚拟机来降低费用。
Google 还以与所有客户相同的价格向受 HIPAA 监管的客户提供相同的服务,包括持续使用折扣。
Google Cloud 支持的服务
上次更新时间:2025 年 9 月 17 日
Google Cloud BAA 涵盖Google Cloud的整个基础架构(所有区域、所有可用区、所有网络路径、所有入网点)以及以下产品:
- Access Approval
- Access Context Manager
- Access Transparency
- Google Cloud Contact Center as a Service (CCaaS) 的 Agent Assist
- Gemini Enterprise Agent Platform 上的 Agent Search [1]
- AI Platform Training 和 AI Platform Prediction
- AlloyDB for PostgreSQL
- Gemini Enterprise 中的 Antigravity
- API Gateway [2]
- Apigee
- App Engine
- Application Integration [3]
- Artifact Analysis
- Artifact Registry [4]
- Assured Workloads
- Audit Manager
- AutoML Natural Language
- AutoML Tables
- AutoML Translation
- AutoML Video
- AutoML Vision
- 备份和灾难恢复服务
- Backup for GKE
- 裸金属解决方案
- 批次
- BigQuery
- BigQuery Data Transfer Service
- BigQuery Omni
- Bigtable
- Binary Authorization
- Certificate Authority Service
- Certificate Manager
- Cloud Asset Inventory
- Cloud Build [5]
- Cloud CDN [6]
- Cloud Data Fusion
- Cloud Deploy
- Cloud Deployment Manager
- Cloud DNS
- Cloud Endpoints
- Cloud Healthcare API
- Cloud HSM(硬件安全模块)
- Cloud Identity
- Cloud Interconnect
- Cloud Intrusion Detection System (Cloud IDS)
- Cloud Key Management Service [7]
- Cloud Life Sciences
- Cloud Load Balancing
- Cloud Logging [8]
- Cloud Monitoring [9]
- Cloud NAT
- Cloud Natural Language API
- Cloud Profiler
- Cloud Resource Manager API
- Cloud Router
- Cloud Run
- Cloud Run functions
- Cloud Scheduler
- Cloud Service Mesh
- Cloud Shell
- Cloud Source Repositories
- Cloud SQL
- Cloud Storage [10]
- Cloud Tasks
- Cloud Trace
- Cloud Translation
- Cloud Vision
- Cloud VPN
- Cloud Workstations
- Cluster Director
- Colab Enterprise
- Compute Engine
- 连接
- Container Registry [11]
- 对话智能体 [12]
- Customer Experience Agent Studio
- 客户体验分析洞见
- 网络保险中心
- Data Catalog
- 数据洞察 [13]
- Database Migration Service [14]
- Dataflow
- Dataform
- Datastream
- Document AI
- Document AI Warehouse
- Eventarc
- Filestore [15]
- Firestore
- Datastore 模式的 Firestore (Datastore) [16]
- Gemini Code Assist
- Gemini Enterprise
- Gemini Enterprise Agent Platform
- Gemini Enterprise for Customer Experience
- Gemini in BigQuery
- Gemini in Colab Enterprise
- Gemini Notebook Enterprise
- Agent Platform 上的生成式 AI
- Google Cloud Armor
- Google Cloud 控制台
- Google Cloud Contact Center as a Service
- Google Cloud Fraud Defense [17]
- Google Cloud Identity-Aware Proxy (IAP)
- Google Cloud Managed Lustre
- Google Cloud Managed Service for Apache Kafka
- Google Cloud NetApp Volumes
- Google Cloud VMware Engine [18]
- Google Distributed Cloud connected [19]
- Google Kubernetes Engine
- Google Kubernetes Engine (GKE) Enterprise 版配置管理
- Google Kubernetes Engine (GKE) Hub
- Healthcare Data Engine
- Identity and Access Management (IAM) [21]
- Identity Platform [22]
- Infrastructure Manager
- Integration Connectors [23]
- Key Access Justifications
- Knative serving
- Knowledge Catalog [24]
- Looker (Google Cloud Core) [25]
- Looker(原始版本)[26]
- Managed Service for Apache Airflow
- Managed Service for Apache Spark
- Microsoft Active Directory (AD) 托管服务
- Memorystore
- Model Armor
- Network Connectivity Center
- Network Service Tiers
- Persistent Disk
- Pub/Sub
- Secret Manager [27]
- Secure Source Manager
- Security Command Center
- Sensitive Data Protection [28]
- Service Directory
- Spanner
- Speech-to-Text [29]
- Storage Transfer Service
- Text-to-Speech
- Traffic Director API
- Transfer Appliance
- Vertex AI Workbench 实例
- Video Intelligence API
- Virtual Private Cloud (VPC)
- VPC Service Controls
- Web Security Scanner
- Workflows
Google SecOps 支持的服务
以下 Google SecOps 服务[20]受 BAA 约束:
- Google Security Operations SIEM
- Google Security Operations SOAR
- Mandiant Digital Threat Monitoring
- Mandiant Security Validation
Google Workspace 支持的服务
上次更新时间:2025 年 8 月 31 日
以下 Google Workspace 服务包含在 Google CloudBAA 中:
- AppSheet
- Cloud Identity 管理服务
- Gemini 应用(不包括 Google Chrome 中的 Gemini)
- Google Workspace 中的 Gemini
- Gemini Mac 应用
- Gmail
- Google Apps 脚本
- Google 日历
- Google Chat
- Google Cloud Search
- Google 云端硬盘(包括 Google 文档、Google 表单、Google 相册、Google 表格、Google 幻灯片和 Google Vids)
- Google 群组
- Google Keep
- Google Meet
- Google 协作平台
- Google Tasks
- Google 保险柜(如适用)
- Google Voice(仅限受管理用户)
如需了解 Google Workspace 的 HIPAA 合规性,请参阅 Google Workspace 的 HIPAA 合规性。
有关“ Google Cloud”目标的最佳实践
请遵循本部分中的最佳实践,以帮助您履行 HIPAA 义务。
一般 Google Cloud 最佳实践
请遵循以下最佳实践:
- 签订 Google Cloud BAA。如需查看相关说明,请参阅Google Cloud的隐私权合规性和记录,以查看并接受 BAA。
- 在处理 PHI 时,停用不受支持的 Google Cloud服务。如果您无法停用某项服务,则不得将其用于 PHI。
- 请勿将服务专用条款中定义的正式发布前产品用于受保护健康信息 (PHI),除非产品的通知或其他条款中另有明确说明。
- 创建或更新资源时,请避免在资源元数据中包含 PHI 或安全凭据,因为日志可能会捕获此类信息。审核日志绝不会包含资源数据内容或查询结果,但可能会捕获资源元数据。
身份、安全和加密
下表介绍了身份、安全和加密服务的最佳实践和限制。
| 支持的产品 | 最佳做法和限制 |
|---|---|
| Cloud KMS |
确定您的组织是否具有超出 HIPAA 安全规则要求的加密要求。客户内容在 Google Cloud上以静态方式加密。如果您有额外加密要求,请使用 Cloud KMS。 |
| 身份和访问权限管理 |
在配置哪些人有权访问您的项目时,请遵循 IAM 最佳实践。 特别是,由于服务账号可用于访问资源,因此请严格控制对这些服务账号和服务账号密钥的访问权限。 |
| Identity Platform |
|
| Secret Manager |
在 Secret Manager 中存储 Secret 时,请查看并遵循 Secret Manager 最佳实践。 |
日志记录、监控和数据保护
下表介绍了日志记录、监控和数据保护服务的最佳实践和限制。
| 支持的产品 | 最佳做法和限制 |
|---|---|
| 日志记录 |
|
| 监控 |
|
| Google SecOps |
请勿使用以下服务或功能:
|
| Sensitive Data Protection |
配置 Sensitive Data Protection 作业时,请确保将所有输出数据写入作为安全环境一部分配置的存储目标。 |
存储和数据库
下表介绍了存储和数据库服务的最佳实践和限制。
| 支持的产品 | 最佳做法和限制 |
|---|---|
| Cloud Storage |
启用对象版本控制,以帮助保留历史归档内容,并在意外删除后恢复对象。 |
| Database Migration Service |
使用专用 IP 连接方法,以避免将包含 PHI 的数据库公开给互联网。 |
| Filestore |
|
| Datastore |
创建或配置索引时,请先加密 PHI、安全凭据或其他敏感数据,然后再将这些数据用作实体键、索引属性键或索引属性值。如需了解详情,请参阅 Datastore 索引。 |
数据分析和商业智能
下表介绍了数据分析和商业智能服务的最佳实践和限制。
AI、机器学习和对话代理
下表介绍了 AI、机器学习和对话式代理服务的最佳实践和限制。
| 支持的产品 | 最佳做法和限制 |
|---|---|
| Gemini Enterprise Agent Platform 上的 Agent Search |
为受保护健康信息 (PHI) 使用区域级 API 和资源位置。 |
| 对话智能体 |
请勿在您的代理定义(包括意图、训练短语和实体)中包含受保护健康信息 (PHI) 或安全凭据。 |
| Speech-to-Text |
如果您已与 Google 签署 BAA,其中涵盖了 HIPAA 下的任何 PHI 义务,请勿选择启用数据日志记录。 |
应用开发、集成和网络
下表介绍了应用开发、集成和网络服务的最佳实践和限制。
| 支持的产品 | 最佳做法和限制 |
|---|---|
| API Gateway |
请勿在标题中包含 PHI 或 PII。 |
| Application Integration 和 Integration Connectors |
|
| Cloud Build |
请勿在 build 配置、源控制文件或其他构建工件中包含受保护健康信息 (PHI)。 |
| Cloud CDN |
请勿请求缓存 PHI。如需防止缓存,请参阅防止缓存。 |
| Fraud Defense |
请勿在 URI 或操作中包含受保护健康信息 (PHI)。 |
计算、容器和混合基础架构
下表介绍了计算、容器和混合基础架构服务的最佳实践和限制。
| 支持的产品 | 最佳做法和限制 |
|---|---|
| Artifact Registry |
Artifact Registry 使用 Google 默认加密或客户管理的加密密钥 (CMEK) 来加密存储库中的数据。元数据(例如制品名称)使用 Google 默认加密方式进行加密。这些元数据可能会显示在日志中,并且对拥有 Artifact Registry Reader 角色 ( |
| Container Registry |
Container Registry 使用 Google 默认加密或 CMEK 对您注册表的存储桶中的数据进行加密。 如需了解如何防止未经授权访问受保护健康信息 (PHI),请参阅保护容器的最佳实践。 |
| VMware Engine |
将应用级访问日志保留一段适当的时间,以满足 HIPAA 要求。 |
| Distributed Cloud connected |
部署联网的 Distributed Cloud 时,您需要负责某些安全方面,尤其是物理安全。如需帮助确保部署安全,请参阅实体安全最佳实践。 |
Looker(原始版本)
下表介绍了在 Google 托管的环境中部署 Looker 时的最佳实践和限制。
| 项 | 最佳做法和限制 |
|---|---|
| 排除的服务 |
请勿使用以下服务,这些服务不受 BAA 支持:
|
| 访问权限控制 |
在实现访问权限控制时,请考虑以下事项:
|
| 数据共享 |
分享数据时,请考虑以下事项:
|
| 安全配置 |
配置安全性时,请考虑以下事项:
|
| 数据库安全控制措施 |
配置数据库安全控制时,请考虑以下事项:
|
后续步骤
- 如需详细了解 Google 的安全性,请参阅 Google 安全概览和 Google 基础设施安全设计概览。
- 查看 HHS 健康信息隐私权 (HIPAA)。
- 查看 HHS 关于 HIPAA 法规遵从和云计算的指南。