Courseiva
Trust and security with Google CloudhardMultiple SelectObjective-mapped

Cloud Digital Leader Trust and security with Google Cloud Practice Question

Which THREE are required to achieve HIPAA compliance on Google Cloud?

⚠ Common exam trap

Google Cloud often tests the misconception that HIPAA requires dedicated infrastructure (like a separate project) or specific security controls (like MFA), when in fact HIPAA focuses on contractual agreements (BAA), data access logging, and using only services that are contractually covered under the BAA.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Sign a Business Associate Agreement (BAA) with Google

HIPAA requires covered entities and their business associates to have a written agreement that establishes the permitted and required uses of protected health information (PHI). Google Cloud provides a standard Business Associate Agreement (BAA) that customers must sign to contractually bind Google to HIPAA obligations, including safeguarding ePHI and reporting breaches. Without a signed BAA, Google is not legally liable as a business associate under HIPAA, making this a foundational requirement for compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Sign a Business Associate Agreement (BAA) with Google

    Why this is correct

    HIPAA mandates that covered entities and business associates enter into a Business Associate Agreement that guarantees the business associate will safeguard PHI. Google Cloud provides a BAA for covered services, making it a contractual prerequisite for any ePHI processing. Without a signed BAA, the legal liability for a breach remains with the covered entity, and Google's protected health information processing terms do not apply.

  • Enable Cloud Audit Logs for tracking access to ePHI

    Why this is correct

    The HIPAA Security Rule requires audit controls that record and examine activity in systems containing ePHI, and Cloud Audit Logs deliver immutable, tamper-evident logs of administrator actions and data access. By enabling these logs, healthcare organizations can demonstrate that they reviewed access patterns and detected unauthorized disclosure, satisfying the audit control requirement. Critically, audit logs are a necessary technical safeguard for showing compliance during an HHS investigation or breach notification assessment.

  • Use only GCP services that are covered under the BAA

    Why this is correct

    The Google Cloud BAA explicitly lists the GCP services that are authorized for processing ePHI, and each covered service includes additional safeguards like encryption and access transparency that are absent from non-covered services. If a healthcare customer routes ePHI to a service not on that list, the BAA no longer extends to that data, creating a HIPAA violation regardless of other security measures. This contractual limitation is an absolute requirement because covered entities must ensure every service involved in the ePHI workflow is under the BAA's protection.

  • Use a dedicated project for all PHI workloads

    Why it's wrong here

    Although a dedicated project is a recommended architectural pattern for isolating PHI workloads and simplifying access controls, HIPAA does not mandate it. Compliance can be achieved in a shared project as long as the services used are covered by the BAA, audit logs are enabled, and access controls are configured appropriately. The Security Rule focuses on technical and physical safeguards, not project boundaries, so a separate project is an operational best practice rather than a prerequisite.

  • Configure multi-factor authentication for all users

    Why it's wrong here

    HIPAA's Security Rule requires 'person or entity authentication' as a standard, but multi-factor authentication (MFA) is classified as an addressable implementation specification rather than a rigid requirement. A covered entity could satisfy the standard with strong unique passwords, single-factor authentication, or other measures if a formal risk analysis determines they are sufficient. While MFA is strongly recommended as a best practice and often required by security policies, it is not a specific, mandatory element of HIPAA compliance.

About these practice questions

One of 829 original GCDL practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.