Courseiva
Trust and security with Google CloudeasyMultiple ChoiceObjective-mapped

Cloud Digital Leader Trust and security with Google Cloud Practice Question

An organization wants to use Google Cloud for processing healthcare data subject to HIPAA regulations in the United States. Which contractual document must the organization obtain from Google before storing Protected Health Information (PHI) in Google Cloud?

⚠ Common exam trap

It's easy for candidates to confuse a generic data protection document (like a DPA or NDA) with the HIPAA-specific BAA, or mistakenly believe that a security certification alone satisfies the contractual requirement for handling PHI.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A Business Associate Agreement (BAA), which is legally required by HIPAA before any covered entity can process Protected Health Information with a cloud provider

Under HIPAA, a covered entity or business associate must obtain a Business Associate Agreement (BAA) from any cloud service provider that will create, receive, maintain, or transmit Protected Health Information (PHI). Google Cloud offers a BAA that contractually binds Google to comply with HIPAA Security and Privacy Rules, including safeguarding PHI and reporting breaches. Without a signed BAA, storing PHI in Google Cloud would violate HIPAA regulations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A Non-Disclosure Agreement (NDA) to prevent Google from disclosing the existence of the healthcare application

    Why it's wrong here

    A Non-Disclosure Agreement (NDA) is a general confidentiality contract that prevents Google from disclosing the existence or business details of the healthcare application, but it does not contain the specific HIPAA-mandated provisions for safeguarding Protected Health Information (PHI). HIPAA requires a Business Associate Agreement (BAA) to establish each party's responsibilities for using, disclosing, and protecting PHI, including breach notification and appropriate safeguards. An NDA alone would not satisfy the Secretary of HHS's requirements for a business associate relationship, so it is a legally insufficient instrument in this context.

  • A Business Associate Agreement (BAA), which is legally required by HIPAA before any covered entity can process Protected Health Information with a cloud provider

    Why this is correct

    The BAA is non-negotiable for HIPAA compliance. Google Cloud offers a BAA that covers specific services for HIPAA workloads. Without a BAA in place, any PHI stored in Google Cloud constitutes a HIPAA violation — technical security controls alone do not satisfy the legal requirement.

  • A Data Processing Agreement (DPA) as required under GDPR for European data subjects

    Why it's wrong here

    A Data Processing Agreement (DPA) is a contractual instrument required under the GDPR to govern the processing of personal data of European data subjects, covering obligations like data subject rights, cross-border transfers, and records of processing. It does not address HIPAA-specific requirements such as the 'minimum necessary' standard, HIPAA breach notification timelines, or the U.S. HHS enforcement framework. Since the scenario concerns a healthcare application handling PHI for which HIPAA compliance is required, a BAA is the only legally apt agreement, regardless of whether the DPA might separately apply to EU personal data.

  • An ISO 27001 certificate issued by Google Cloud demonstrating information security compliance

    Why it's wrong here

    An ISO 27001 certificate is a third-party attestation that Google Cloud has implemented an information security management system (ISMS) aligned with international best practices, demonstrating controls around risk management and incident handling. However, this certification is not a legal instrument and does not create a binding obligation between the covered entity and the cloud provider regarding PHI. HIPAA expressly requires a Business Associate Agreement (BAA) to establish the cloud provider as a business associate, contractually binding it to comply with the HIPAA Security and Breach Notification Rules; a certificate cannot substitute for that contractual and regulatory commitment.

About these practice questions

This GCDL question is part of Courseiva's 829-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.