Courseiva
Trust and security with Google CloudmediumMultiple ChoiceObjective-mapped

Cloud Digital Leader Trust and security with Google Cloud Practice Question

A healthcare company needs to store patient data in Google Cloud and must comply with HIPAA (Health Insurance Portability and Accountability Act). Which statement correctly describes how Google Cloud helps them achieve HIPAA compliance?

⚠ Common exam trap

The GCDL exam often tests the shared responsibility model by presenting options that imply full vendor responsibility (like automatic compliance) or full customer responsibility (like impossibility), and the trap here is assuming that encryption alone satisfies all HIPAA technical safeguards, ignoring access control and audit requirements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Google offers HIPAA-eligible services and signs a Business Associate Agreement (BAA), but customers must implement their own technical safeguards and access controls.

Google Cloud provides HIPAA-eligible services and offers a Business Associate Agreement (BAA) to covered entities, but compliance is a shared responsibility. Customers must configure their own technical safeguards, such as access controls, audit logging, and encryption key management, to meet HIPAA requirements. Google Cloud does not automatically make an application compliant; the customer must implement the necessary controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Storing data in Google Cloud automatically makes an application HIPAA-compliant.

    Why it's wrong here

    Simply storing protected health information (PHI) in Google Cloud does not create compliance, because HIPAA demands ongoing administrative and technical safeguards such as risk analysis, role-based access, and workforce training. Synchronizing a BAA and selecting HIPAA-eligible services only establishes the foundation; the customer must still architect controls, enforce least privilege, and monitor access. Compliance is an operational state, not an inherent property of a storage location.

  • Google offers HIPAA-eligible services and signs a Business Associate Agreement (BAA), but customers must implement their own technical safeguards and access controls.

    Why this is correct

    Google Cloud participates in HIPAA compliance by providing a BAA and offering infrastructure that addresses physical, environmental, and certain technical safeguards. However, the Shared Responsibility Model makes the customer accountable for configuring services correctly, managing access controls, enabling audit logging, encrypting data where required, and implementing contingency plans. Without these customer-side actions, even a signed BAA does not render a workload compliant.

  • HIPAA compliance is impossible on public cloud; healthcare data must stay on-premises.

    Why it's wrong here

    While some assume public cloud cannot meet healthcare regulations, HIPAA does not mandate on-premises storage. The HHS explicitly permits cloud computing when covered entities sign a Business Associate Agreement (BAA) with a compliant cloud provider like Google Cloud. Moreover, physical security and infrastructure safeguards in a hyperscale cloud often exceed those of a typical hospital data center, so the premise is technically false.

  • Google Cloud's automatic data encryption fully satisfies all HIPAA technical safeguard requirements.

    Why it's wrong here

    Automatic encryption at rest and in transit addresses one aspect of the HIPAA Technical Safeguards standard, but that standard also requires access controls including unique user identification, emergency access procedures, automatic logoff, and audit trail capabilities. Additionally, integrity controls and transmission security go beyond simple encryption, encompassing measures like hashing, integrity monitoring, and custom VPN configurations. The burden remains on the covered entity to configure and validate these controls, so encryption alone is insufficient.

About these practice questions

Courseiva writes every GCDL question from scratch — 829 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.