Enable customer-managed encryption keys (CMEK) for Cloud Healthcare API datasets

By default, Google Cloud automatically encrypts data when it is at rest using encryption keys managed by Google. If you have specific compliance or regulatory requirements related to the keys that protect your data, you can use customer-managed encryption keys (CMEK) for your Cloud Healthcare API datasets. Instead of Google owning and managing the encryption keys that protect your data, your Cloud Healthcare API datasets are encrypted using a key that you control and manage in Cloud Key Management Service (Cloud KMS).

For more information about CMEK in general, including when and why to enable it, see Customer-managed encryption keys (CMEK).

Before you begin

Decide whether your Cloud Healthcare API dataset and Cloud KMS will be in the same Google Cloud project or different ones. For guidance, see Separation of duties.

For documentation purposes, the following conventions are used:

  • PROJECT_ID: the Cloud Healthcare API project ID
  • KMS_PROJECT_ID: the project ID where Cloud KMS runs, which might be the same as PROJECT_ID

For information about Google Cloud project IDs and project numbers, see Identifying projects.

Limitations

  • You can only use Cloud KMS keys when creating a Cloud Healthcare API dataset. You can't enable, change, or disable Cloud KMS keys on an existing Cloud Healthcare API dataset.
  • Only FHIR, DICOM, and HL7v2 stores are supported in CMEK-encrypted datasets. CMEK protection applies to DICOM, FHIR, and HL7v2 stores in the dataset and their resources.
  • You can't de-identify CMEK-encrypted resources.

CMEK operations

Cloud KMS keys are used when a CMEK-encrypted resource is created, read, updated, or deleted, and for operational tasks like billing or ensuring the key is available.

External key considerations

For information on using keys that you manage within a supported external key management partner system to protect data within Google Cloud, see Cloud External Key Manager.

If you lose keys that you manage outside of Google Cloud, Google can't recover your data.

Key unavailability and data loss

If a dataset is encrypted by a key, and that key becomes unavailable and remains unavailable, the Cloud Healthcare API disables and eventually deletes the dataset. Sometimes, a key becomes unavailable if it's disabled or destroyed, or if it's inaccessible due to revoked permissions, but this behavior occurs if the key is unavailable for any reason. The key's protection level or whether it's an external key doesn't affect this behavior. External keys can also become unavailable unpredictably. For example, connectivity issues might arise between your Google Cloud resources and your EKM.

The following process describes how key availability is checked, and how a dataset can be disabled and deleted:

  1. After a CMEK-encrypted Cloud Healthcare API dataset is created, the Cloud Healthcare API checks the key's status every five minutes to ensure the key is available. If the key is unavailable, the Cloud Healthcare API continues to support requests to the dataset for up to one hour.

  2. After one hour, if the Cloud Healthcare API is still unable to connect with Cloud KMS, the Cloud Healthcare API dataset is disabled as a protective measure. To re-enable the Cloud Healthcare API dataset, contact your support representative.

    When disabled, you can only send datasets.get and datasets.delete requests to the Cloud Healthcare API dataset. Other requests fail with a