Professional Data EngineerOperationalizing machine learning modelsMedium

A healthcare provider is developing a machine learning model to predict patient readmission risk. The training data contains sensitive patient health information (PHI). To comply with HIPAA regulations, they must ensure that all data used for model training and evaluation is de-identified before being processed by the ML pipeline. Which Google Cloud service should be integrated into the data ingestion pipeline to automatically detect and transform PHI?

  1. ACloud Storage Transfer Service
  2. BCloud Data Loss Prevention (DLP)
  3. CCloud Dataflow
  4. DCloud Pub/Sub
Show answer & explanation

Correct answer: B. Cloud Data Loss Prevention (DLP)

Cloud Data Loss Prevention (DLP) is specifically designed to discover, classify, and de-identify sensitive data like PHI. It can be integrated into data pipelines to automatically detect and transform sensitive information according to compliance requirements.

Why the other options are wrong

  • A. Cloud Storage Transfer Service is for moving data between storage locations, not for de-identifying sensitive information.
  • C. Cloud Dataflow is a service for executing data processing pipelines, it can orchestrate de-identification but doesn't perform the sensitive data detection itself.
  • D. Cloud Pub/Sub is a messaging service for asynchronous communication, not for data de-identification.

Cloud Data Loss Prevention (DLP)

A Google Cloud service that helps discover, classify, and protect sensitive data across various data sources.

  • Detects over 150 types of sensitive information.
  • Offers anonymization, tokenization, and pseudonymization.
  • Crucial for regulatory compliance (e.g., HIPAA, GDPR).

Memory trick: DLP is like a 'data police' guarding your sensitive patient info.

More Operationalizing machine learning models questions