Compliance Answer

Is Google Vertex AI HIPAA Compliant?

The name changed and the coverage list did not follow the old memory. Match your workload to a named product first.

The Verdict

Google Cloud signs a self-serve BAA, but coverage is by named product, and "Vertex AI" by that name is not on the covered-products list as of this writing. Vertex AI Workbench instances are covered, as are the renamed Gemini Enterprise generative products. Google contractually will not train on customer data.

The rule, match your exact workload to a named covered product before PHI, and disable everything else.

Fact table (sources checked 2026-07-12)
BAAYes, self-serve Cloud BAA; product-enumerated coverage
Trains on your dataNo (Service Terms training restriction)
Enterprise controlsCloud IAM, SSO, Cloud Audit Logs, VPC Service Controls (itself BAA-covered), configurable retention
Sourcescloud.google.com/security/compliance/hipaa (verified twice), /terms/hipaa-baa, /terms/service-terms, Gemini data-governance docs

The Catch

The naming trap. Google reorganized its AI products, and a 2023-era "Vertex AI is HIPAA supported" memory does not match today's enumerated list. Contracts follow the list, not the memory.

If Your Staff Use It

This is a build-side platform; the audience is your engineering team. Their architecture review should quote the covered-products page with a date on it.

The Policy Question Comes Before The Product Question

Whether it is Vertex AI or another cloud AI product, the first control is a policy your engineering and compliance teams can share. Generate a healthcare-ready draft in minutes, then decide which products earn a place in it.