ASSOCIATE-GOOGLE-WORKSPACE-ADMINISTRATOR · Question #28
Your company operates several primary care clinics where employees routinely work with protected health information (PHI). You are in the process of transitioning the organization to Google…
The correct answer is B. Create a label for Google Drive content to help employees identify sensitive data. After signing the Business Associate Agreement (BAA) with Google, Google Workspace core services (Gmail, Drive, Meet, etc.) are covered for storing and processing PHI (Protected Health Information) under HIPAA. The BAA makes it permissible to use these services for PHI-so…
Question
Your company operates several primary care clinics where employees routinely work with protected health information (PHI). You are in the process of transitioning the organization to Google Workspace from a legacy communication and collaboration system. After you sign the Business Associate Agreement (BAA), you need to ensure that data is handled in compliance with regulations when using Google Workspace. What should you do?
Options
- AImplement a third-party backup service that is also compliant with Google Workspace core
- BCreate a label for Google Drive content to help employees identify sensitive data.
- CInstruct the staff to not store any PHI in Google Workspace core services, including Google Drive,
- DDisable integrations with third-party apps and turn off non-core Google services.
How the community answered
(46 responses)- A2% (1)
- B83% (38)
- C4% (2)
- D11% (5)
Explanation
After signing the Business Associate Agreement (BAA) with Google, Google Workspace core services (Gmail, Drive, Meet, etc.) are covered for storing and processing PHI (Protected Health Information) under HIPAA. The BAA makes it permissible to use these services for PHI-so instructing staff to avoid storing PHI there (Option C) would be unnecessarily restrictive and incorrect. Creating a Drive label for sensitive content (Option B) supports compliance by enabling staff to identify, classify, and handle PHI appropriately within the now-compliant environment. Option A (third-party backup) may add value but is not the primary compliance step. Option D (disabling integrations) is overly broad and not required by the BAA.
Topics
Community Discussion
No community discussion yet for this question.