Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

GDPR vs HIPAA — guide from Governance Docs

GDPR vs HIPAA: The Differences That Actually Matter

GDPR vs HIPAA is a comparison people reach for when a US healthcare business
starts selling into Europe, or a European company handles health data for US customers. They are
often described as equivalents. They are not: they differ in who they bind, what they protect and how
they are enforced.

GDPR vs HIPAA: scope is the fundamental difference

GDPR is horizontal. Regulation (EU) 2016/679 applies to the processing of
personal data relating to people in the EU, by any organisation, in any sector. A bakery’s mailing
list is in scope.

HIPAA is vertical. It applies only to covered entities — health
plans, health care clearinghouses and providers transmitting health information electronically for
covered transactions — and their business associates. A fitness app collecting far more
sensitive health information than a clinic is typically outside HIPAA entirely, because it is not a
covered entity.

That asymmetry is the single most consequential point in GDPR vs HIPAA, and it is the one most
often got wrong. “We handle health data, so HIPAA applies” does not follow.

GDPR vs HIPAA: what each one protects

GDPR protects personal data — any information relating to an identified or
identifiable person — with health data treated as a special category needing an additional
condition for processing. HIPAA protects protected health information: individually
identifiable health information held or transmitted by a covered entity or business associate.

GDPR vs HIPAA: lawful basis versus permitted use

GDPR requires a lawful basis for every processing activity, chosen from six, and
consent is only one — often the weakest, because it can be withdrawn. HIPAA works the other way:
it permits use and disclosure for treatment, payment and health care operations
without authorisation, and requires written authorisation for most other purposes. A European
organisation applying GDPR habits to a US clinical workflow tends to over-collect consent it does not
need; a US organisation applying HIPAA habits in Europe tends to have no documented basis at all.

Both document sets, ready to edit.

The GDPR Toolkit covers records of processing, lawful basis assessments, DPIAs and Article 28 terms; the HIPAA Toolkit covers the security risk analysis, policies, business associate agreements and breach response — 160+ templates.

Explore the GDPR Toolkit →

Breach notification: where GDPR vs HIPAA differ most sharply

GDPR requires notification to the supervisory authority without undue delay and where
feasible within 72 hours
of becoming aware, with notification to individuals where the risk
to them is high. HIPAA requires notification to affected individuals without unreasonable
delay and no later than 60 days
from discovery, with HHS notified on a schedule that depends
on how many people are affected.

Seventy-two hours versus sixty days is not a detail. If both regimes apply to the same incident,
the GDPR clock is the one that will catch you out, and it starts before you have finished
investigating.

GDPR vs HIPAA: penalties and enforcement

GDPR fines run to €20 million or 4% of total worldwide annual turnover,
whichever is higher, for the most serious infringements. HIPAA uses tiered civil monetary penalties
based on culpability, with annual caps per violation type, and OCR resolves most matters through
settlement and a corrective action plan rather than a fine.

Neither has a certification. There is no such thing as being “GDPR certified” or “HIPAA certified”
in the way you can be certified to ISO 27001 — what exists in both cases is evidence.

What to do when both apply

Where GDPR vs HIPAA both apply, build one control set and map it to both. The security measures overlap almost entirely, and ISO
27001 is the usual backbone for that. Then layer the regime-specific requirements: for GDPR, the
record of processing, lawful basis, transparency, data subject rights and transfers; for HIPAA, the
security risk analysis, business associate agreements and the notice of privacy practices.

Do not try to satisfy the stricter of the two and assume it covers both — they are strict
about different things. GDPR’s data subject rights have no HIPAA equivalent in scope, and HIPAA’s
business associate machinery is more prescriptive than GDPR’s Article 28.

See our guides to GDPR implementation,
HIPAA implementation and the
HIPAA risk assessment template.

References

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.