Solution

HIPAA compliance for google cloud

GCP offers a BAA and covered products list. Configuration, access, and logging remain your responsibility.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

GCP offers a BAA and covered products list. Configuration, access, and logging remain your responsibility.

What you get

  • Evidence from Cloud Audit Logs, IAM, Security Command Center, and CMEK
  • Covered-product verification against services actually in use
  • VPC Service Controls and data perimeter documentation
  • Workload-level ePHI classification

The shared responsibility line

This is where most teams get it wrong. Your provider secures the infrastructure. You secure your configuration, your identities, your data classification, your logging retention, and your workforce. Every enforcement action we have read involved the second half of that sentence, not the first.

How it fits together

LayerWho owns itHow SuperHIPAA helps
InfrastructureProvider (under BAA)We verify your BAA is current and covers the services you use
ConfigurationYouContinuous checks mapped to §164.312
Data classificationYouePHI inventory and flow mapping
WorkforceYouTraining, acknowledgement, access reviews
DocumentationYouPolicies, risk analysis, evidence, all versioned

Start where you are

Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.

Questions

Is a signed BAA from our cloud provider enough?

No. A BAA allocates responsibility; it does not implement safeguards. Your configuration, access control, logging, and workforce practices are still assessed against the Security Rule.

Can we do HIPAA and SOC 2 at the same time?

Yes, and you should. Roughly two-thirds of the control work overlaps. One control set, two outputs — that is how the platform is built.

How fast can we be ready for a customer security review?

Trust centre and questionnaire library go live in days. A defensible full program takes 8–12 weeks. We tell prospects the difference honestly, and so should you.

How do we get a BAA with Google Cloud?

It is self-serve: you accept the HIPAA BAA from the Cloud console admin settings, and it covers the products on Google's covered-products list. Keep the executed copy with your BAA records and re-check the list when your architecture changes.

Does the GCP BAA also cover Google Workspace?

No — Workspace has its own BAA, accepted separately in the Workspace admin console. If patient data touches Gmail, Drive, or Meet as well as your GCP workloads, you need both, and teams routinely have one without the other.

What if we are using a GCP product that is not on the covered list?

Keep ePHI out of it. Newer and pre-GA products are often excluded, and a covered project can quietly grow an uncovered dependency when someone adds a new API. We check the services you actually use against the list continuously rather than at contract time.

Is Google's default encryption enough, or do we need CMEK?

GCP encrypts everything at rest by default, which satisfies the baseline. CMEK adds key custody, rotation control, and the ability to revoke access — worth it for your most sensitive stores. Either way, record the decision as your documented rationale for the addressable encryption specification.

Can we run analytics on patient data in BigQuery?

Yes — BigQuery is on the covered list — but the data is still ePHI unless it has been de-identified to the §164.514 standard, and most 'anonymised' clinical datasets have not been. Dataset-level IAM, audit logging, and a documented de-identification method are the difference between analytics and a breach.

Are VPC Service Controls required for HIPAA?

Not by name — no specific product is. But a service perimeter around your ePHI projects is one of the strongest exfiltration mitigations available on GCP, and it gives your risk analysis a concrete answer to the data-loss threat scenarios an assessor will probe.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo