Technology guide
Google Cloud and HIPAA
How to evaluate Google Cloud services, configurations, access, logging, and recovery for workloads involving ePHI.
Reviewed August 2026
Key considerations
- Use the current Google Cloud covered-products and contractual materials for the exact services.
- Customer IAM, data controls, audit logging, network design, and recovery are part of the workload review.
- Do not turn a provider's compliance documentation into an application-level claim.
Questions to ask
- What data enters each service and where do copies or logs go?
- How are identities, keys, audit logs, and service accounts governed?
- How are incidents and support access handled?