Cloud Digital Leader Trust and security with Google Cloud Practice Question
Which THREE are required to achieve HIPAA compliance on Google Cloud?
⚠ Common exam trap
Google Cloud often tests the misconception that HIPAA requires dedicated infrastructure (like a separate project) or specific security controls (like MFA), when in fact HIPAA focuses on contractual agreements (BAA), data access logging, and using only services that are contractually covered under the BAA.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sign a Business Associate Agreement (BAA) with Google
HIPAA requires covered entities and their business associates to have a written agreement that establishes the permitted and required uses of protected health information (PHI). Google Cloud provides a standard Business Associate Agreement (BAA) that customers must sign to contractually bind Google to HIPAA obligations, including safeguarding ePHI and reporting breaches. Without a signed BAA, Google is not legally liable as a business associate under HIPAA, making this a foundational requirement for compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Sign a Business Associate Agreement (BAA) with Google
Why this is correct
HIPAA mandates that covered entities and business associates enter into a Business Associate Agreement that guarantees the business associate will safeguard PHI. Google Cloud provides a BAA for covered services, making it a contractual prerequisite for any ePHI processing. Without a signed BAA, the legal liability for a breach remains with the covered entity, and Google's protected health information processing terms do not apply.
- ✓
Enable Cloud Audit Logs for tracking access to ePHI
Why this is correct
The HIPAA Security Rule requires audit controls that record and examine activity in systems containing ePHI, and Cloud Audit Logs deliver immutable, tamper-evident logs of administrator actions and data access. By enabling these logs, healthcare organizations can demonstrate that they reviewed access patterns and detected unauthorized disclosure, satisfying the audit control requirement. Critically, audit logs are a necessary technical safeguard for showing compliance during an HHS investigation or breach notification assessment.
- ✓
Use only GCP services that are covered under the BAA
Why this is correct
The Google Cloud BAA explicitly lists the GCP services that are authorized for processing ePHI, and each covered service includes additional safeguards like encryption and access transparency that are absent from non-covered services. If a healthcare customer routes ePHI to a service not on that list, the BAA no longer extends to that data, creating a HIPAA violation regardless of other security measures. This contractual limitation is an absolute requirement because covered entities must ensure every service involved in the ePHI workflow is under the BAA's protection.
- ✗
Use a dedicated project for all PHI workloads
Why it's wrong here
Although a dedicated project is a recommended architectural pattern for isolating PHI workloads and simplifying access controls, HIPAA does not mandate it. Compliance can be achieved in a shared project as long as the services used are covered by the BAA, audit logs are enabled, and access controls are configured appropriately. The Security Rule focuses on technical and physical safeguards, not project boundaries, so a separate project is an operational best practice rather than a prerequisite.
- ✗
Configure multi-factor authentication for all users
Why it's wrong here
HIPAA's Security Rule requires 'person or entity authentication' as a standard, but multi-factor authentication (MFA) is classified as an addressable implementation specification rather than a rigid requirement. A covered entity could satisfy the standard with strong unique passwords, single-factor authentication, or other measures if a formal risk analysis determines they are sufficient. While MFA is strongly recommended as a best practice and often required by security policies, it is not a specific, mandatory element of HIPAA compliance.
Go deeper
Related to this question
Learn chapter
Cloud Digital Transformation
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
Google Cloud
Google Cloud is a suite of cloud computing services offered by Google that provides infrastructure, platform, and software solutions over the internet.
About these practice questions
One of 829 original GCDL practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.