Executive Summary
AI-generated analysis for Google Cloud Healthcare API
Google Cloud Healthcare API (cloud.google.com), a product offering from Google, has been assessed at Tier 3 (Moderate Risk) with an 82% confidence score. The moderate tier reflects not the vendor's overall security posture — which is demonstrably strong — but rather specific evidence gaps around subprocessor transparency and AI data usage policy clarity that warrant attention before deployment in healthcare data environments. The assessment surfaced a substantial array of positive signals across infrastructure, compliance, and threat intelligence dimensions:
Key Findings
- FedRAMP High authorization has been independently verified via the FedRAMP Marketplace (authorized November 2019), representing the most rigorous U.S. federal cloud security standard
- The domain has been established for over 28 years and is registered through enterprise registrar MarkMonitor with full transfer-lock protections
- Infrastructure exposure is minimal, with only 2 open ports (80 and 443) detected and zero known CVEs — well below the SaaS industry average of 8–12 open ports
- TLS 1.3 with AES-256-GCM cipher is in use, and all recommended security headers (HSTS, CSP, X-Frame-Options) are present
- Google Web Risk (Safe Browsing) returned a clean result with no malware, phishing, or unwanted software flags
- No sanctions matches, no adverse media, and no historical enforcement actions were identified across OFAC, EU, UN, SEC, or FDIC sources
- The vendor's compliance page claims an extensive list of frameworks including SOC 2, SOC 1, HITRUST CSF, PCI DSS, HIPAA, GDPR, CCPA, NIST 800-53, StateRAMP, and Cyber Essentials Plus Two areas require attention prior to or concurrent with deployment. First, Google Cloud's published subprocessor page (cloud.google.com/security/subprocessors) was located but could not be automatically parsed to extract individual subprocessors — manual review is required to satisfy GDPR Article 28 and internal vendor risk requirements. Second, the AI data usage policy at cloud.google.com/ai does not clearly articulate whether customer data may be used for AI model training, which is a material consideration given the sensitivity of healthcare data and the vendor's growing suite of AI-powered services (including Gemini). The absence of a documented no-training commitment or opt-out mechanism is the primary driver of the AI-related finding. Overall, Google Cloud Healthcare API represents a mature, compliance-forward infrastructure vendor with independently verified federal authorization. The Tier 3 rating is driven by policy transparency gaps rather than substantive security deficiencies. A conditional approval is appropriate, with the specific requirements outlined below.
Independence Statement
All evidence in this report was sourced independently through external data registries, public DNS infrastructure, threat intelligence feeds, certificate transparency logs, and publicly accessible compliance pages — without vendor participation or review.