Question-10: An electronic version of a patient's medical history that is maintained by the provider over time and may include all of the key administrative clinical data relevant to that person's care under a particular provider, including demographic information, progress notes, problems, medications, and vital signs. This type of record is referred to as an electronic health record, or EHR for short. Please see the case study on EHR Healthcare for more information on this topic. You are accountable for ensuring that an upcoming privacy compliance audit of EHR's use of Google Cloud will be successfully passed. What action should you take? (Choose two.) A.Check the product usage of the EHR against the list of compliant products that can be found on the Google Cloud compliance page. B. Advise enterprise health record keeping (EHR) to enter into a Business Associate Agreement (BAA) with Google Cloud. C. Firebase Authentication should be utilised for all user-facing applications of the EHR. D. Prometheus should be implemented so that security breaches in EHR's web-based applications can be detected and avoided. E. All Kubernetes workloads should be deployed to GKE private clusters. Correct Answer
Get All 340 Questions and Answer for Google Professional Cloud Architect
: 1,2 Explanation: The Google Cloud compliance page will provide a list of products that meet the requirements of the HIPAA.Check the product usage of the EHR against the list of compliant products that can be found on the Google Cloud compliance page.
B. Advise enterprise health record keeping (EHR) to enter into a Business Associate Agreement (BAA) with Google Cloud.
C. Firebase Authentication should be utilised for all user-facing applications of the EHR.
D. Prometheus should be implemented so that security breaches in EHR's web-based applications can be detected and avoided.
E. All Kubernetes workloads should be deployed to GKE private clusters.
Correct Answer
Get All 340 Questions and Answer for Google Professional Cloud Architect
: 1,2 Explanation: The Google Cloud compliance page will provide a list of products that meet the requirements of the HIPAA. Option 2: OK. The term BAA refers to either the HIPAA Business Associate amendment or the Business Associate Agreement that Google and the customer have entered into. This agreement must be reached because EHR is the industry standard when it comes to the provision of software for medical records. Option 3 has been taken out of the running. (Firebase authentication offers users of apps backend services, simple SDKs, and libraries that are already built. Option 4 has been crossed out. E - Eliminated Running distributed services in GKE private clusters provides businesses with services that are both secure and reliable. I'm not sure how this could possibly assist with the private compliance audit. The First and Second Options Customers who are required to comply with HIPAA and who want to use GCP for their business purposes that involve PHI are required to enter into a Business Associate Agreement (BAA) with Google. This BAA must cover specific products and services offered by Google Cloud.