Google supports Health Insurance Portability and Accountability Act (HIPAA) compliance (within the scope of a Business Associate Agreement) but ultimately customers are responsible for evaluating their own HIPAA compliance, including when using the Looker (original) Services.
The Business Associate Agreement (BAA) covers Looker’s Services under a Looker Hosted Deployment as described in the applicable Looker (original) services agreement to which the BAA is attached, except that the following (the "Excluded Services") are not covered by the BAA:
Given the functionality of the Services, you, as the customer, are in control of (i) the environment where you deploy the Services, (ii) the configuration of the Services (including configuration of the access permissions and security controls) in such a way that complies with your BAA, this implementation guide and HIPAA requirements, (iii) the applications that are connected to the Services by your end users, and (iv) how or if your users access Protected Health Information (PHI) when using the Services. To the extent you elect to use Excluded Services (as defined above), you must manage the risk of using such services in compliance with your obligations under HIPAA.
Essential best practices: