CompyMax

Is Google Cloud HIPAA compliant?

Only under specific conditions

Yes — Google signs an agreement covering its entire infrastructure rather than a walled-off healthcare region, but only products on its covered list may touch patient data and what you build on top remains yours to configure.

Applies to Google Cloud Platform. Last reviewed against Google's own documentation. Next review February 4, 2027.

Reviewed by Lisa Tran, CISSP — Healthcare Information Security Executive.

What you must do

  • Execute the Google Cloud agreement, reviewing and accepting it through the privacy compliance and records process for Google Cloud.
  • Put patient data only in products on Google's covered-products list. Google asks you to disable, or otherwise ensure you do not use, anything outside it when working with patient information.
  • Configure audit log export. Google recommends Cloud Storage for long-term archival and BigQuery for analysis, monitoring and forensics.
  • Apply Google's identity and access management guidance to control who can reach the project.
  • Keep patient data out of the places it leaks into by accident: resource names, metadata, labels, logs and configuration files.
  • Re-check the covered-products list before adopting any new Google Cloud product.

Does Google Cloud sign a business associate agreement?

Yes. Google offers one. No special plan or support tier. Google notes it offers regulated customers the same products at the same pricing as everyone else, including sustained-use discounts. Review and accept the agreement by following Google's privacy compliance and records instructions for Google Cloud.

See their documentation.

What this means in practice

Google's pitch here is genuinely different from its competitors: the agreement covers the whole infrastructure — every region, zone and network path — rather than a separate healthcare-only environment, and Google notes regulated customers pay the same prices as everyone else. That removes a class of problem that AWS and Azure customers spend real time on.

It does not remove the list. Google publishes a covered-products list running past 180 entries and asks you to disable, or otherwise avoid using, anything outside it when working with patient information. The infrastructure being covered is not the same as every product on it being covered, and that distinction is where projects go wrong.

Google's own configuration advice is worth following literally, because it names the failure mode nobody plans for: keep patient information out of resource names, metadata, labels, logs and configuration files. Those are the places data leaks into by habit rather than by decision, and no agreement helps once it is there.

How organizations get this wrong

The specific mistakes we see with Google Cloud, not generic advice.

  • Reading “covers the entire infrastructure” as “covers every product”, and adopting something off the covered list for a quick job.
  • Naming a bucket, dataset or virtual machine after a patient, which puts identifiable information into metadata that is copied into logs and billing exports.
  • Never configuring audit log export, so the record Google recommends keeping for forensics ages out of the default retention window.
  • Adopting a newly launched Google Cloud product without re-checking the covered list, which is revised as products ship.

What the agreement does not cover

  • Any Google Cloud product not explicitly named on the covered-products list.
  • Metadata, logs and configuration where you have put patient data yourself.
  • The environment and applications you build on top, which Google states are your responsibility to configure and secure.

Alternatives

Listed on merit. We take no payment for placement and use no affiliate links.

  • Amazon Web Services

    Comparable cloud with an eligible-services list and a click-through addendum in AWS Artifact

  • Azure

    Comparable cloud where the agreement applies automatically through Microsoft's Data Protection Addendum

Signing the agreement is step one. Proving it is step two.

Once you have the agreement with Google Cloud, someone has to know it exists, where the copy is, when it needs revisiting and who owns it. That register is what a client's security questionnaire is actually asking about, and it is the section of an evidence pack most organizations cannot produce on request.

$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.

Sources

Every statement above comes from Google’s own published documentation, read on the date shown.

  1. HIPAA Compliance on Google CloudGoogle. No publication date given. Read August 10, 2026.

Change history

  • First published.

This page is information, not certification and not legal advice. It reflects Google’s published documentation as read on August 10, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.

Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.