
HIPAA vs GDPR: The Short Version
HIPAA and GDPR are different privacy regimes with different scopes. HIPAA is a U.S. healthcare-specific framework focused on protected health information handled by covered entities, business associates, and qualifying subcontractors. GDPR is a cross-sector privacy law for personal data, including health data as a special category, when processing falls within its territorial scope.
The practical difference is basically this:
- HIPAA follows the healthcare relationship. It applies to defined healthcare entities and their business-associate relationships, not every company that touches health-related information.
- GDPR follows personal data and processing context. It can apply across industries when an organization is established in the EU or when non-EU controllers or processors offer goods or services to people in the Union or monitor their behaviour there.
- Both may apply to the same workflow. A healthcare, healthtech, SaaS, research, or data-processing workflow may need analysis under both regimes when it involves a HIPAA-regulated relationship and GDPR-regulated personal-data processing.
- Compliance with one does not automatically satisfy the other. Some safeguards and evidence can support both, but legal bases, rights handling, breach notification, contracts, and accountability duties still need separate validation.
What HIPAA Covers
HIPAA’s Privacy Rule applies to health plans, health care clearinghouses, and health care providers that conduct specified electronic transactions. It also reaches business associates that perform covered functions or services involving protected health information, and qualifying subcontractors in that regulated chain, according to HHS’s Summary of the HIPAA Privacy Rule.
HIPAA protects protected health information, or PHI: individually identifiable health information held or transmitted by a covered entity or business associate. That distinction matters, health-adjacent data is not automatically PHI. A wellness app, analytics vendor, or SaaS provider needs to classify the relationship and data flow, not just ask whether the data “looks medical.”
HIPAA’s Privacy Rule governs uses and disclosures of PHI. The Security Rule requires covered entities and business associates to implement appropriate administrative, physical, and technical safeguards for electronic PHI, or ePHI. HIPAA also requires covered entities to designate a privacy official, and the Security Rule requires a security official.
What GDPR Covers
GDPR basically regulates the processing of personal data across sectors. Under GDPR, personal data is information relating to an identified or identifiable person. A controller determines the purposes and means of processing, while a processor processes personal data on behalf of a controller, as defined in GDPR Article 4.
GDPR’s territorial scope is broader than an industry rule. It applies to processing in the context of an EU establishment and can also apply to non-EU controllers or processors that offer goods or services to people in the Union or monitor their behaviour there, under GDPR Article 3.
Health data receives additional treatment. GDPR classifies health data as a special category of personal data. Processing personal data requires an Article 6 lawful basis, and processing special-category data also requires an applicable Article 9 condition. Consent can be one lawful basis, but GDPR is not a consent-only framework.
HIPAA vs GDPR Comparison Table
| Area | HIPAA | GDPR |
|---|---|---|
| Primary purpose | U.S. healthcare privacy and security rules for PHI handled in regulated healthcare relationships. | Cross-sector privacy framework for personal data processing within its territorial scope. |
| Jurisdiction and scope | Applies to covered entities, business associates, and qualifying subcontractors in HIPAA-regulated relationships. | Applies to EU-establishment processing and, in specified cases, non-EU controllers or processors offering goods or services to people in the Union or monitoring their behaviour there. |
| Who must comply | Health plans, health care clearinghouses, certain health care providers, business associates, and relevant subcontractors. | Controllers and processors, depending on the processing activity. |
| Data protected | PHI: individually identifiable health information held or transmitted by a covered entity or business associate. | Personal data, including health data as special-category data. |
| Organization roles | Covered entity, business associate, subcontractor. | Controller, processor. |
| Consent / legal basis | HIPAA permits or requires certain uses and disclosures without authorization; written authorization is generally required for uses or disclosures not otherwise permitted or required. | Processing needs an Article 6 lawful basis; special-category health data also needs an Article 9 condition. Consent is one possible basis, not the only one. |
| Individual rights | Includes rights such as access, amendment, and an accounting of certain disclosures. | Includes access, rectification, erasure, restriction, portability, and objection, subject to GDPR conditions and exceptions. |
| Breach notification | Individual notice is required without unreasonable delay and no later than 60 days for breaches of unsecured PHI, with HHS and media notification in specified circumstances. | Controller notice to the supervisory authority is required without undue delay and, where feasible, within 72 hours unless the breach is unlikely to risk individuals’ rights and freedoms; affected people are notified without undue delay when high risk is likely. |
| Regulators | HHS Office for Civil Rights enforces the HIPAA Privacy and Security Rules and may seek corrective action, resolution agreements, or civil money penalties. | EU supervisory authorities enforce GDPR and may impose administrative fines under Article 83. |
| Penalties | Civil money penalties may apply; current HIPAA penalty caps should be checked against current HHS materials before publication or incident planning. | Depending on the infringement, administrative fines can reach up to €10 million or 2% of worldwide annual turnover, or up to €20 million or 4%, whichever is higher. |
| Officer / accountability roles | Covered entities must designate a privacy official; the Security Rule requires a security official. | A DPO is required only in Article 37 cases, including certain large-scale monitoring or large-scale processing of special-category data; controllers must be able to demonstrate compliance. |
How to Decide Whether HIPAA, GDPR, or Both Apply
Use this as an applicability decision aid. Not a legal test. The same organization can have different roles in different workflows, and labels under one framework do not determine labels under the other.
Applicability decision tree
-
Are you a HIPAA covered entity?
If you are a health plan, health care clearinghouse, or health care provider conducting specified electronic transactions, HIPAA is likely relevant. -
Are you performing services for a HIPAA-regulated entity involving PHI?
If yes, you may be a business associate or subcontractor. HIPAA analysis is likely needed. -
Is the data PHI in that relationship?
If the data is individually identifiable health information held or transmitted by a covered entity or business associate, treat HIPAA as potentially in scope. -
Are you processing personal data under GDPR’s territorial scope?
GDPR may be relevant if processing occurs in the context of an EU establishment, or if a non-EU controller or processor offers goods or services to people in the Union or monitors their behaviour there. -
Are you a GDPR controller, processor, or both in different workflows?
Classify each processing activity separately. A SaaS provider might process data on behalf of one customer in one context and determine purposes and means in another, but that conclusion depends on the specific workflow. -
Does the same product, dataset, or process involve both HIPAA-regulated PHI and GDPR-regulated personal data?
If yes, both regimes may need analysis. Coordinate shared controls where possible, but validate legal bases, notices, contracts, rights, breach notification, and evidence separately. -
Is the answer uncertain, cross-border, incident-specific, or tied to retention or erasure?
Route to legal or subject-matter review. These questions are fact-specific and should not be resolved from a generic comparison.
Where HIPAA and GDPR Overlap — And Where They Do Not
HIPAA and GDPR both push organizations toward privacy governance, security safeguards, accountability, vendor oversight, incident response, and evidence. That does not make them interchangeable. A shared control can support multiple assessments, but each framework’s distinct legal, contractual, rights, and notification requirements need separate validation.
Control-overlap matrix
| Control area | How it can support HIPAA | How it can support GDPR | What still needs separate handling |
|---|---|---|---|
| Access control | Supports appropriate technical safeguards for ePHI. | Supports appropriate technical and organisational measures. | Role-based access rules must reflect each workflow’s data, purpose, and user population. |
| Logging and monitoring | Helps investigate access to ePHI and support security operations. | Helps demonstrate security and accountability where relevant. | Log retention, review procedures, and evidence expectations may differ by program and legal context. |
| Encryption and technical safeguards | Can support protection of ePHI, but encryption should not be described as universally mandatory under HIPAA. | Can support Article 32 security measures, depending on risk and context. | Do not assume one encryption decision satisfies both regimes without risk analysis. |
| Risk assessment | Supports HIPAA Security Rule safeguard planning. | Supports risk-based security and accountability decisions. | Assessment criteria and documentation should map to each framework separately. |
| Policies and procedures | Supports HIPAA Privacy Rule and Security Rule governance. | Supports GDPR accountability and consistent processing controls. | Notices, authorizations, lawful-basis records, and rights procedures require distinct drafting. |
| Training | Helps operationalize HIPAA privacy and security responsibilities. | Helps staff follow GDPR processing, rights, and incident procedures. | Training content should cover different role definitions, rights, and escalation paths. |
| Vendor management | Supports business associate and subcontractor oversight. | Supports controller/processor governance. | Business associate agreements and GDPR controller/processor terms are not the same document type. |
| Incident response | Helps detect, assess, and escalate suspected incidents. | Helps meet breach assessment and notification obligations. | HIPAA and GDPR have different triggers, timelines, recipients, and risk thresholds. |
| Evidence management | Helps respond to audits, investigations, customer reviews, and internal assurance. | Helps demonstrate accountability and control operation. | Evidence must still be mapped to the specific obligation it is intended to support. |
Key Differences That Matter in Practice
Consent and lawful basis
HIPAA authorization and GDPR consent are not the same mechanism. HIPAA permits or requires certain PHI uses and disclosures without authorization, while written authorization is generally required for uses or disclosures not otherwise permitted or required. GDPR requires a lawful basis under Article 6 for personal-data processing; for special-category health data, an Article 9 condition is also needed.
Operationally, this means a product team should not treat “we have consent” as a universal answer—or, more precisely, as an answer that works across both regimes. Under GDPR, consent has specific requirements and alternatives may apply. Under HIPAA, authorization is tied to uses and disclosures of PHI within the Privacy Rule structure.
Individual rights
HIPAA and GDPR both give individuals rights, but the rights are not identical. HIPAA includes rights such as access, amendment, and an accounting of certain disclosures. GDPR includes access, rectification, erasure, restriction, portability, and objection, subject to conditions and exceptions under Articles 15–22.
The operational consequence is that a single intake form may not be enough. Teams should classify the request, identify the applicable regime, confirm identity and authority, and route the response through the right deadline, exception analysis, and evidence trail. Erasure and retention questions, especially in healthcare-record contexts, require jurisdiction- and record-specific legal review.
Breach notification
HIPAA and GDPR should not be reduced to “60 days versus 72 hours”—or, rather, to a timeline comparison alone. The real difference is the combination of trigger, threshold, recipient, and routing.
Under the HHS Breach Notification Rule, a breach is generally an impermissible use or disclosure of unsecured PHI presumed to be a breach unless a required risk assessment shows a low probability of compromise. Required individual notice is without unreasonable delay and no later than 60 days, with HHS and media notifications in specified circumstances.
Under GDPR Articles 33 and 34, a controller notifies the competent supervisory authority without undue delay and, where feasible, within 72 hours unless the breach is unlikely to risk individuals’ rights and freedoms. Affected people are notified without undue delay when the breach is likely to create a high risk.
For dual-scope workflows, incident response should preserve both analyses rather than forcing every event into one framework’s vocabulary.
Officer roles and accountability
HIPAA requires covered entities to designate a privacy official, and the Security Rule requires a security official. GDPR’s DPO requirement is different. A DPO is required only in the cases specified by Article 37, including certain large-scale monitoring or large-scale processing of special-category data.
Do not treat a HIPAA privacy officer, HIPAA security officer, and GDPR DPO as interchangeable titles. One person may hold multiple responsibilities in some organizations, but the appointment, independence, expertise, and task expectations need separate analysis.
Regulators and penalties
HIPAA Privacy and Security Rule enforcement sits with HHS’s Office for Civil Rights, which may seek corrective action, resolution agreements, or civil money penalties, as described in HHS’s OCR enforcement overview.
GDPR enforcement is handled by supervisory authorities. Under GDPR Article 83, administrative fines can reach up to €10 million or 2% of worldwide annual turnover, or up to €20 million or 4%, whichever is higher, depending on the infringement. Those are maximum ceilings, not automatic outcomes.
What to Do If Both HIPAA and GDPR May Apply
If a workflow may fall under both regimes, start with classification before control implementation.
- Map data flows. Identify where PHI, personal data, and special-category health data appear.
- Classify roles separately. Determine HIPAA covered entity, business associate, or subcontractor status separately from GDPR controller or processor status.
- Identify shared controls. Access control, logging, training, risk assessment, vendor management, and incident response can support both programs.
- Separate distinct obligations. Validate lawful basis, authorizations, notices, rights workflows, contracts, officer roles, breach triggers, and evidence requirements independently.
- Test breach response against both regimes. Make sure incident triage captures the right facts for HIPAA and GDPR assessments.
- Escalate complex questions. Cross-border processing, erasure, retention, and incident-specific decisions need legal or subject-matter review.
- Maintain evidence continuously. Do not wait for an audit, investigation, or customer review to reconstruct control history.
For teams managing multiple frameworks, Ciphrix can help operationalize this mapping by connecting controls to frameworks, maintaining evidence, and reducing repeated manual evidence collection. That support does not replace legal analysis or control ownership; it helps teams manage the operational side once scope and obligations are understood.
FAQs About HIPAA vs GDPR
Is HIPAA the US version of GDPR?
No. HIPAA is a U.S. healthcare-specific privacy and security framework for PHI in regulated healthcare relationships. GDPR is a broader privacy regime for personal data processing across sectors within its territorial scope.
Can HIPAA and GDPR both apply?
Yes, they may both need analysis when a workflow involves a HIPAA-regulated relationship and processing that falls within GDPR’s territorial scope. The answer depends on the organization’s role, data, geography, and what the processing activity is.
Is PHI the same as personal data?
No. PHI is individually identifiable health information held or transmitted by a HIPAA covered entity or business associate. GDPR personal data is broader: it is information relating to an identified or identifiable person. Health data can be special-category personal data under GDPR.
Does GDPR apply to healthcare data?
Yes, GDPR can apply to health data when the processing falls within GDPR’s scope. Health data is treated as special-category personal data, so processing needs both an Article 6 lawful basis and an applicable Article 9 condition.
Does HIPAA compliance mean GDPR compliance?
No. HIPAA safeguards and evidence may support parts of a GDPR program, but GDPR has separate rules for lawful basis, special-category data, controller and processor obligations, data-subject rights, breach notification, accountability, and DPO requirements.
Which has stricter breach notification rules?
There is no safe universal answer. HIPAA and GDPR use different triggers, thresholds, recipients, and timelines. HIPAA individual notice is without unreasonable delay and no later than 60 days for breaches of unsecured PHI. GDPR supervisory-authority notice is without undue delay and, where feasible, within 72 hours unless the breach is unlikely to risk individuals’ rights and freedoms.
Do you need both a HIPAA privacy/security officer and a GDPR DPO?
Possibly, depending on your roles and processing activities. HIPAA requires covered entities to designate a privacy official and requires a security official under the Security Rule. GDPR requires a DPO only in Article 37 cases, such as certain large-scale monitoring or large-scale processing of special-category data. These roles should not be assumed to be interchangeable in practice.
