本文件說明 Google Cloud 和 Google Workspace 如何支援《健康保險流通與責任法案》(HIPAA),以及如何設定 Google Cloud 以實踐您的 HIPAA 責任。本指南適用的目標對象包含資安管理人員、法規遵循監管人員、IT 管理員,以及其他負責在 Google Cloud 和 Google Workspace 中落實《健康保險流通與責任法案》並確保相關作業符合規定的員工。
共同責任
美國衛生及公共服務部 (HHS) 並未提供《健康保險流通與責任法案》合規認證計畫。遵守《健康保險流通與責任法案》是您與 Google 共同的責任。
《健康保險流通與責任法案》要求遵循安全規則、隱私權規則和資料外洩通知規則。Google Cloud Google Workspace 支援在業務夥伴協議範圍內遵循《健康保險流通與責任法案》,但您最終仍須自行評估是否符合《健康保險流通與責任法案》的相關規範。
根據《健康保險流通與責任法案》規定,Google 會視情況簽訂業務合作協議。
客戶責任
您必須判斷下列事項:
- 您是受保護實體,還是受保護實體的業務夥伴。
- 您是否需要與 Google 簽署業務合作協議。
Google 提供的基礎架構安全控管機制,可支援您在儲存及處理 PHI 時,符合《健康保險流通與責任法案》的規定。您有責任確保環境和在 Google Cloud 上建構的應用程式,都已根據《健康保險流通與責任法案》規定正確設定及保護。詳情請參閱「共用命運」。
如要瞭解 Google 的安全防護和資料保護措施,請參閱 Google 安全防護總覽和 Google 基礎架構安全防護設計總覽。
Google Cloud 功能和定價
Google Cloud 的《健康保險流通與責任法案業務合作協議》涵蓋整個基礎架構,而非僅限於部分 Google CloudGoogle Cloud。因此,您將不受特定地區的限制,可使用多區域服務備援。您也可以使用 Spot VM 降低成本。
Google 也為受《健康保險流通與責任法案》監管的客戶提供與所有客戶相同的服務,並適用相同的價格,包括持續使用折扣。
Google Cloud 支援的服務
上次更新時間:2025 年 9 月 17 日
Google Cloud 業務合作協議涵蓋整個基礎架構 (所有區域、所有可用區、所有網路路徑、所有連接點),以及下列產品:Google Cloud
- 存取權核准
- Access Context Manager
- 資料存取透明化控管機制
- Google Cloud Contact Center as a Service (CCaaS) 適用的 Agent Assist
- Gemini Enterprise Agent Platform 中的 Agent Search [1]
- AI 平台訓練和預測
- AlloyDB for PostgreSQL
- Gemini Enterprise 的 Antigravity
- API Gateway [2]
- Apigee
- App Engine
- Application Integration [3]
- Artifact Analysis
- Artifact Registry [4]
- Assured Workloads
- Audit Manager
- AutoML Natural Language
- AutoML Tables
- AutoML Translation
- AutoML Video
- AutoML Vision
- 備份和災難復原服務
- GKE 備份
- Bare Metal 解決方案
- 批次
- BigQuery
- BigQuery 資料移轉服務
- BigQuery Omni
- Bigtable
- 二進位授權
- 憑證授權單位服務
- Certificate Manager
- Cloud Asset Inventory
- Cloud Build [5]
- Cloud CDN [6]
- Cloud Data Fusion
- Cloud Deploy
- Cloud Deployment Manager
- Cloud DNS
- Cloud Endpoints
- Cloud Healthcare API
- Cloud HSM (硬體安全性模組)
- Cloud Identity
- Cloud Interconnect
- 雲端入侵偵測系統 (Cloud IDS)
- Cloud Key Management Service [7]
- Cloud Life Sciences
- Cloud Load Balancing
- Cloud Logging [8]
- Cloud Monitoring [9]
- Cloud NAT
- Cloud Natural Language API
- Cloud Profiler
- Cloud Resource Manager API
- Cloud Router
- Cloud Run
- Cloud Run functions
- Cloud Scheduler
- Cloud Service Mesh
- Cloud Shell
- Cloud Source Repositories
- Cloud SQL
- Cloud Storage [10]
- Cloud Tasks
- Cloud Trace
- Cloud Translation
- Cloud Vision
- Cloud VPN
- Cloud Workstations
- Cluster Director
- Colab Enterprise
- Compute Engine
- 連結
- Container Registry [11]
- 對話式代理 [12]
- Customer Experience Agent Studio
- Customer Experience Insights
- Cyber Insurance Hub
- Data Catalog
- 數據分析 [13]
- 資料庫遷移服務 [14]
- Dataflow
- Dataform
- Datastream
- Document AI
- Document AI 倉儲
- Eventarc
- Filestore [15]
- Firestore
- Datastore 模式的 Firestore (Datastore) [16]
- Gemini Code Assist
- Gemini Enterprise
- Gemini Enterprise Agent Platform
- Gemini Enterprise for Customer Experience
- Gemini in BigQuery
- Gemini in Colab Enterprise
- Gemini Notebook Enterprise
- Agent Platform 生成式 AI
- Google Cloud Armor
- Google Cloud 控制台
- Google Cloud Contact Center as a Service
- Google Cloud Fraud Defense [17]
- Google Cloud Identity-Aware Proxy (IAP)
- Google Cloud Managed Lustre
- Google Cloud Managed Service for Apache Kafka
- Google Cloud NetApp Volumes
- Google Cloud VMware Engine [18]
- Google Distributed Cloud connected [19]
- Google Kubernetes Engine
- Google Kubernetes Engine (GKE) Enterprise 版的 Config Management
- Google Kubernetes Engine (GKE) Hub
- Healthcare Data Engine
- 身分與存取權管理 (IAM) [21]
- Identity Platform [22]
- Infrastructure Manager
- Integration Connectors [23]
- 金鑰存取依據
- Knative serving
- Knowledge Catalog [24]
- Looker (Google Cloud Core) [25]
- Looker (原始版本) [26]
- Managed Service for Apache Airflow
- Managed Service for Apache Spark
- Managed Service for Microsoft Active Directory (AD)
- Memorystore
- Model Armor
- Network Connectivity Center
- 網路服務級別
- Persistent Disk
- Pub/Sub
- Secret Manager [27]
- Secure Source Manager
- Security Command Center
- Sensitive Data Protection [28]
- Service Directory
- Spanner
- 語音轉文字 [29]
- Storage 移轉服務
- Text-to-Speech
- Traffic Director API
- Transfer Appliance
- Vertex AI Workbench 執行個體
- Video Intelligence API
- 虛擬私有雲 (VPC)
- VPC Service Controls
- Web Security Scanner
- 工作流程
Google SecOps 支援的服務
BAA 支援下列 Google SecOps 服務[20]:
- Google Security Operations SIEM
- Google Security Operations SOAR
- Mandiant Digital Threat Monitoring
- Mandiant Security Validation
支援的 Google Workspace 服務
上次更新時間:2025 年 8 月 31 日
下列 Google Workspace 服務包含在 Google Cloud BAA 中:
- AppSheet
- Cloud Identity 管理服務
- Gemini 應用程式 (不含 Google Chrome 內建 Gemini)
- Gemini in Google Workspace
- Gemini Mac 應用程式
- Gmail
- Google Apps Script
- Google 日曆
- Google Chat
- Google Cloud Search
- Google 雲端硬碟 (包括 Google 文件、Google 表單、Google 相簿、 Google 試算表、Google 簡報和 Google Vids)
- Google 網路論壇
- Google Keep
- Google Meet
- Google 協作平台
- Google Tasks
- Google 保管箱 (如適用)
- Google Voice (僅限受管理的使用者)
如要瞭解 Google Workspace 的《健康保險流通與責任法案》法規遵循情況,請參閱「Google Workspace 的《健康保險流通與責任法案》法規遵循情況」。
Google Cloud最佳做法
請導入本節中的最佳做法,以利履行《健康保險流通與責任法案》義務。
一般 Google Cloud 最佳做法
請實作下列最佳做法:
- 輸入 BAA。 Google Cloud 如需操作說明,請參閱「隱私權法規遵循和記錄Google Cloud」一文,瞭解如何查看及接受 BAA。
- 處理受保護的健康資訊時,請停用不支援的服務 Google Cloud。如果無法停用服務,請勿使用該服務處理 PHI。
- 除非在相關通知或產品/服務的其他條款中另有明確註明,否則請勿使用《服務專屬條款》中定義的正式發布前產品處理受保護的健康資訊。
- 建立或更新資源時,請勿在資源中繼資料中加入受保護的健康資訊或安全性憑證,因為記錄檔可能會擷取這類資訊。稽核記錄絕不會包含資源資料內容或查詢結果,但可能會擷取資源中繼資料。
身分識別、安全性和加密
下表說明身分識別、安全性及加密服務的最佳做法和限制。
| 支援的產品 | 最佳做法和限制 |
|---|---|
| Cloud KMS |
判定貴機構是否有除了《健康保險流通與責任法案》安全規定以外的加密要求。客戶內容會在 Google Cloud靜態加密。如有額外加密需求,請使用 Cloud KMS。 |
| 身分與存取權管理 |
設定專案存取權時,請採用 IAM 最佳做法。特別是服務帳戶可用於存取資源,因此請嚴格控管這些服務帳戶和服務帳戶金鑰的存取權。 |
| Identity Platform |
|
| Secret Manager |
如要將密鑰儲存於 Secret Manager,請詳閱並遵循 Secret Manager 最佳做法。 |
記錄、監控和資料保護
下表說明記錄、監控和資料保護服務的最佳做法和限制。
| 支援的產品 | 最佳做法和限制 |
|---|---|
| 記錄 |
|
| 監控 |
|
| Google SecOps |
請勿使用下列服務或功能:
|
| Sensitive Data Protection |
設定 Sensitive Data Protection 工作時,請確保所有輸出資料皆已寫入儲存空間目標,且該目標經過設定已加入安全環境中。 |
儲存空間與資料庫
下表說明儲存空間和資料庫服務的最佳做法和限制。
| 支援的產品 | 最佳做法和限制 |
|---|---|
| Cloud Storage |
啟用物件版本管理功能,有助於保存歷史封存檔,並在物件意外刪除後復原。 |
| 資料庫遷移服務 |
使用私人 IP 連線方法,以免將含有受保護健康資訊的資料庫公開至網際網路。 |
| Filestore |
|
| Datastore |
建立或設定索引時,請先將受保護的健康資訊、安全性憑證或其他機密資料加密,再將其做為實體鍵、索引屬性鍵或索引屬性值。詳情請參閱「Datastore 索引」。 |
資料分析與商業智慧
下表說明資料分析和商業智慧服務的最佳做法和限制。
AI、機器學習和對話型代理
下表說明 AI、機器學習和對話式代理服務的最佳做法和限制。
| 支援的產品 | 最佳做法和限制 |
|---|---|
| Gemini Enterprise Agent Platform 的 Agent Search |
針對受保護的健康資訊使用區域性 API 和資源位置。 |
| 對話式代理 |
請勿在虛擬服務專員定義中加入受保護的健康資訊或安全性憑證,包括意圖、訓練詞組和實體。 |
| 語音轉文字 |
如果您已與 Google 簽訂《業務夥伴協議》,其中涵蓋《健康保險流通與責任法案》規定的任何受保護健康資訊義務,請勿選擇啟用資料記錄。 |
應用程式開發、整合和網路
下表說明應用程式開發、整合和網路服務的最佳做法和限制。
| 支援的產品 | 最佳做法和限制 |
|---|---|
| API Gateway |
請勿在標題中加入受保護的健康資訊或個人識別資訊。 |
| Application Integration 和 Integration Connectors |
|
| Cloud Build |
請勿在建構設定、來源控制檔案或其他建構構件中加入受保護的健康資訊。 |
| Cloud CDN |
請勿要求快取受保護的健康資訊。如要防止快取,請參閱「防止快取」。 |
| Fraud Defense |
請勿在 URI 或動作中加入受保護的健康資訊。 |
運算、容器和混合式基礎架構
下表說明運算、容器和混合式基礎架構服務的最佳做法和限制。
| 支援的產品 | 最佳做法和限制 |
|---|---|
| Artifact Registry |
Artifact Registry 會使用 Google 預設加密機制或客戶自行管理的加密金鑰 (CMEK) 來加密存放區中的資料。中繼資料 (如構件名稱) 是以 Google 預設的加密機制加密。這項中繼資料可能出現在記錄檔中,且凡是具備 Artifact Registry 讀取者角色 ( |
| Container Registry |
Container Registry 會使用 Google 預設加密機制或 CMEK 加密登錄檔儲存空間 bucket 中的資料。如要防止未經授權存取受保護的健康資訊,請參閱「保護容器的最佳做法」。 |
| VMware Engine |
保留適當期間的應用程式層級存取記錄,以符合《健康保險流通與責任法案》規定。 |
| Distributed Cloud connected |
部署Distributed Cloud Connected 時,您必須負責特定安全層面,尤其是實體安全。如要確保部署作業安全無虞,請參閱「實體安全最佳做法」。 |
Looker (原始版本)
下表說明在 Google 代管環境中部署 Looker 時的最佳做法和限制。
| 項目 | 最佳做法和限制 |
|---|---|
| 排除的服務 |
請勿使用下列服務,因為 BAA 不支援這些服務:
|
| 存取權控管 |
實作存取控管機制時,請考量下列事項:
|
| 資料共用 |
分享資料時,請注意下列事項:
|
| 安全設定 |
設定安全性時,請考量下列事項:
|
| 資料庫安全控管措施 |
設定資料庫安全控管機制時,請考量下列事項:
|
後續步驟
- 如要進一步瞭解 Google 的安全性,請參閱 Google 安全性總覽和 Google 基礎架構安全性設計總覽。
- 請參閱美國衛生與公共服務部 (HHS) 的健康資訊隱私權 (HIPAA) 頁面。
- 請參閱 HHS 關於《健康保險流通與責任法案》法規遵循和雲端運算的指南。