My understanding is that patient consent is not necessary for things like research, which Google's AI efforts could be argued to fall under. This makes sense in that requiring researchers to get consent for every piece of patient data would quickly become cost-prohibitive for many types of studies or introduce sampling issues (e.g. selection bias) or some combination of the two. Patient health data is frequently handed over to researchers, but HIPAA probably did not anticipate the case in which a powerful consumer-facing entity that is notorious for using personal data also could do legitimate research on health data.
Additionally, given that Google adheres to the HIPAA business associate agreement, healthcare institutions are allowed to give non-anonymized patient information without patient consent. A typical example might be a medical group that outsources its billing procedures. My understanding is that the medical group does not need to get patient consent in order to hand over medical data to the medical billing coders.
Someone who is more knowledgeable about HIPAA might be able to add to the discussion, but from the few details that have been publicized, it could be that Google is following the law, but people are surprised by what is allowed by the law.