Challenge:
Firebase (Google) doesn't sign a business associates agreement (BAA) and is not configurable in a HIPAA-compliant manner.
Solution:
It turned out that Google makes exceptions on a case-by-case basis to accept products as HIPAA-eligible if they have done due diligence. The Freshcode team implemented so-called HIPAA Technical Safeguards, including Access Control, Audit Controls, Integrity, Transmission Security to forestall identity theft and scam. We used IAM in GCP to secure Hi Rasmus data with Firestore and signed BAA to satisfy HIPAA regulatory requirements.