On August 4, 2011, Google posted a new page with additional information about security and privacy of Google Apps dealing directly with the question, "Can I trust Google with my data?" You can view that page here: https://sites.google.com/a/googleapps.com/google-apps-solution-providers/security-and-privacy
Google has some in-depth information on the topic of security in relation to its Google Apps system. The issue of security with regards to the cloud and Google in particular has many aspects. Google meets SAS 70 Type II Compliance and meets or exceeds the requirements set forth in the CSA (Cloud Security Alliance). Dealing with particular security and privacy initiatives like HIPAA and SOX must be handled by each client individually, and is not a cut and dry topic.
I would encourage looking at the two links below for more information.
Google Apps Security Overview: http://www.google.com/apps/intl/en/business/infrastructure_security.html
Google Apps Security Whitepaper: https://docs.google.com/fileview?id=0B5Y-fwYJF2hLY2MwNzk0NjQtYTZlNy00MjdiLThmMmUtOTM1OTRjMTdjNDMx&hl=en