Identity Platform:健康保险流通与责任法案 (HIPAA) 实施指南
使用集合让一切井井有条
根据您的偏好保存内容并对其进行分类。
免责声明
本指南仅供参考。Google 在本指南中提供的信息或建议不构成法律建议。每位客户都有责任独立评估其对该服务的具体使用是适当的,以履行法规遵从义务。
目标受众
对于需要遵循《健康保险流通与责任法案》(HIPAA,修订版,包括《卫生信息技术促进经济与临床健康法案》(HITECH))相关要求的客户,Google Cloud的 Identity Platform 可以支持 HIPAA 合规性,前提是正确使用。本指南面向安全官员、合规官员、IT 管理员及其他负责使用 Google CloudIdentity Platform 实施和遵守 HIPAA 合规性的员工。
根据 HIPAA 的规定,有关个人健康状况或医疗服务的某些信息被归类为受保护健康信息 (PHI)。如果 Google Cloud的客户需要遵循 HIPAA 且希望将 Google Cloud 或其 Identity Platform 用于处理 PHI,必须与 Google 签署《业务伙伴协议》(BAA)。
Google Cloud 客户需自行判断是否受 HIPAA 要求的约束,并决定是否使用或打算使用 Google 服务与 PHI 相关。未与 Google 签署 BAA 的客户不得在处理 PHI 时使用 Google 服务。
Identity Platform 服务
Google Cloud的 Identity Platform 是一种身份即服务 (IDaaS) 解决方案,可提供基于云的基础架构,以便将身份功能添加到应用或服务中。Identity Platform 服务提供基于云的用户目录/数据库和身份验证 API,可最大限度地减少与开发和管理应用身份相关的开销。
我们建议您只存储为您的应用或服务提供身份验证和授权所需的最少数据。在 Identity Platform 数据库中创建用户时,唯一必需的特性是电子邮件地址(如果使用电子邮件地址/密码登录)或手机号码(如果使用手机进行身份验证)。
虽然 Identity Platform 支持额外的可选特性(包括显示名和照片网址,以及向用户对象添加自定义特性/声明的权限),但 PHI 不应存储在任何此类特性中。如果您需要存储 PHI,建议按照 Google Cloud的实施指南,在 Google Cloud中使用通用数据库解决方案。
联合身份提供商和匿名登录
Identity Platform 支持与一系列基于互联网的社交联盟提供商以及可配置的企业联盟标准(例如 SAML 和 OpenId Connect (OIDC))相集成。但是,PHI 不应通过令牌、声明、断言或任何其他机制从这些身份提供商 (IdP) 传输到 Identity Platform。
不建议或不支持将 PHI 从外部身份系统同步到 Identity Platform,且 Google Cloud 不对该信息在传输过程中或第三方收到后的安全性作任何断言或保证。
在与 PHI 进行交互或管理/存储 PHI 时,不应使用匿名账号。
软件开发套件和客户端库 (SDK)
Identity Platform 提供了在 Identity Platform 服务之外运行的软件开发套件和客户端库。这些 SDK 可在客户端(跨 iOS、Android、Web)或以主要开发语言(Java、C++、Go、NodeJS 等)编写的服务器代码中使用。
由于此代码在 Identity Platform 服务之外运行,因此 Google Cloud对 Identity Platform 服务之外的信息安全性(如最终用户的设备上的信息)不作任何断言或保证。相应地,在与 PHI 进行交互或管理/存储 PHI 时,不应使用 SDK 和客户端库。
其他资源
这些额外的资源可以帮助您了解我们如何在确保数据隐私性、机密性、完整性和可用性的情况下设计 Google 服务。
如未另行说明,那么本页面中的内容已根据知识共享署名 4.0 许可获得了许可,并且代码示例已根据 Apache 2.0 许可获得了许可。有关详情,请参阅 Google 开发者网站政策。Java 是 Oracle 和/或其关联公司的注册商标。
最后更新时间 (UTC):2025-08-18。
[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-08-18。"],[],[],null,["# Identity Platform: HIPAA Implementation Guide\n\nDisclaimer\n----------\n\nThis guide is for informational purposes only. Google does not intend the\ninformation or recommendations in this guide to constitute legal advice. Each\ncustomer is responsible for independently evaluating its own particular use of\nthe services as appropriate to support its legal compliance obligations.\n\nIntended Audience\n-----------------\n\nFor customers who are subject to the requirements of the Health Insurance\nPortability and Accountability Act (known as HIPAA, as amended, including by the\nHealth Information Technology for Economic and Clinical Health --- HITECH --- Act),\nGoogle Cloud's Identity Platform can support HIPAA compliance if properly\nused. This guide is intended for security officers, compliance officers, IT\nadministrators, and other employees who are responsible for HIPAA implementation\nand compliance using Google Cloud's Identity Platform.\n\nUnder HIPAA, certain information about a person's health or health care services\nis classified as Protected Health Information (PHI). Google Cloud\ncustomers who are subject to HIPAA and wish to use Google Cloud or its\nIdentity Platform with PHI must sign a Business Associate Agreement (BAA) with\nGoogle.\n\nGoogle Cloud customers are responsible for determining whether they are\nsubject to HIPAA requirements and whether they use or intend to use Google\nservices in connection with PHI. Customers who have not signed a BAA with Google\nmust not use Google services in connection with PHI.\n\nThe Identity Platform Service\n-----------------------------\n\nGoogle Cloud's Identity Platform is an Identity-as-a-Service (IDaaS)\nsolution, providing cloud-based infrastructure to enable identity capabilities\nto be added to applications or services. The Identity Platform service offers a\ncloud-based user directory/database and authentication APIs that can minimize\nthe overhead associated with developing and managing identity for your\napplication.\n\nWe recommend that you only store the minimum data needed to provide\nauthentication and authorization for your application or service. When creating\na user in the Identity Platform database, the only required attribute is an\nemail address (in the case of email/password sign-in), or a Phone Number (in the\ncase of Phone Authentication).\n\nWhile the Identity Platform supports additional\n[optional attributes](/identity-platform/docs/concepts-manage-users#user_properties)\nincluding Display Name and Photo URL, as well as the ability to add Custom\nAttributes/Claims to a user object, PHI should not be stored in any of these\nattributes. If you have a requirement to store PHI, it is recommended that a\ngeneral purpose database solution be used within Google Cloud, in\naccordance with Google Cloud's\n[implementation guidance](/security/compliance/hipaa).\n\nFederated Identity Providers and Anonymous sign-in\n--------------------------------------------------\n\nIdentity Platform supports integration with a range of internet-based social\nfederation providers as well as configurable enterprise federation standards\nsuch as SAML and OpenId Connect (OIDC). However, PHI should not be transmitted\nfrom these Identity Providers (IdPs) to Identity Platform in tokens, claims,\nassertions or through any other mechanism.\n\nAny synchronization of PHI from external identity systems to Identity Platform\nis not recommended or supported and Google Cloud makes no assertions or\nguarantees as to the security of this information in transit or upon receipt by\nthe third party.\n\nAnonymous accounts should not be used when interacting, managing, or storing\nPHI.\n\nSoftware Development Kits and Client Libraries (SDKs)\n-----------------------------------------------------\n\nIdentity Platform offers Software Development Kits and Client Libraries that run\noutside of the Identity Platform service. These SDKs are available client-side\n(across iOS, Android and Web) or in server code across major development\nlanguages (Java, C++, Go, NodeJS etc).\n\nAs this code runs outside of the Identity Platform Service, Google Cloud\nmakes no assertions or guarantees as to the security of information outside of\nthe Identity Platform service, such as on an end-user's device. SDKs and Client\nLibraries should, accordingly, not be used when interacting, managing, or\nstoring PHI.\n\nAdditional Resources\n--------------------\n\nThese additional resources may help you understand how Google services are\ndesigned with privacy, confidentiality, integrity, and availability of data in\nmind.\n\n- [HIPAA Compliance on Google Cloud](/security/compliance/hipaa)\n- [Google security whitepaper](/security/overview/whitepaper)\n- [Google Infrastructure Security Design Overview](/security/infrastructure/design)"]]