HIPAA vs GDPR: Health Data Compliance Compared
A side-by-side guide to the two rules that govern health data, and how they shape AI use.
HIPAA and GDPR are not interchangeable. HIPAA is a US law that protects health data held by specific healthcare organizations. GDPR is a European Union and UK law that protects all personal data, with health data treated as an extra-sensitive category.
Many organizations must follow both at once. If you serve US patients, HIPAA applies. If you handle data about people in the EU or UK, GDPR applies. A US telehealth provider with European users can be bound by each rule at the same time.
This guide compares the two on scope, consent, vendor contracts, breach timelines, and penalties. It also covers what each means when you feed health data into AI tools.
HIPAA vs. GDPR: Side-by-Side
| Dimension | HIPAA | GDPR |
|---|---|---|
| Who and what is covered | US covered entities (providers, health plans, clearinghouses) and their business associates. Protects PHI, individually identifiable health data. | Any organization processing personal data of people in the EU or UK. Health data is a special category under Article 9 needing extra protection. |
| Consent and lawful basis | Allows many uses for treatment, payment, and healthcare operations without extra sign-off. Written authorization is needed for uses outside those. | Needs a lawful basis under Article 6, plus a separate Article 9 condition for health data, often explicit consent. Both must apply. |
| Vendor contract | Business Associate Agreement (BAA) required before a vendor touches PHI. | Data Processing Agreement under Article 28 required between controller and processor. |
| Breach notification | Notify affected individuals and HHS without unreasonable delay, no later than 60 calendar days from discovery (verify current rules on HHS.gov). | Notify the supervisory authority without undue delay, where feasible within 72 hours of becoming aware (Article 33). |
| Individual rights | Right to access and get copies of records, request amendments, and get an accounting of disclosures. | Broader rights: access, erasure, data portability, restriction, and objection, subject to conditions. |
| Penalties | Tiered civil money penalties based on culpability, adjusted yearly for inflation, plus possible criminal charges (verify current amounts on HHS.gov). | Two tiers, the higher up to 20 million euros or 4% of global annual turnover, whichever is greater (Article 83). |
| Territorial reach | US-focused. Applies to covered entities and business associates handling PHI in the United States. | Applies to organizations in the EU or UK, and to those elsewhere that offer goods or services to, or monitor, people in the EU or UK (Article 3). |
HIPAA vs GDPR at a Glance
HIPAA is narrow and sector-specific, while GDPR is broad and applies across every industry. HIPAA governs health data held by US healthcare organizations. GDPR governs all personal data about people in the EU and UK, and gives health data extra protection.
The core difference is reach. HIPAA follows a type of organization and a type of data. GDPR follows the person, wherever the organization sits.
Both share a goal: keep sensitive data private and secure. They differ on who is bound, what counts as protected, and how strict the consent and breach rules are.
Neither replaces the other. An organization can satisfy HIPAA and still fall short of GDPR, or the reverse.
Comparing HIPAA and GDPR to figure out which one governs your AI tools, or whether both do? Layer3 Labs maps your data flows and checks your vendor contracts so you deploy AI without a compliance gap.
Book a ConsultationScope and Who Is Covered
HIPAA covers a defined list of organizations, not everyone who holds health data. The U.S. Department of Health and Human Services calls these covered entities: healthcare providers who bill electronically, health plans, and healthcare clearinghouses. Their vendors are business associates and are also bound.
GDPR covers far more organizations. The UK Information Commissioner's Office explains that GDPR applies to any organization processing personal data of people in the EU or UK.
This means a fitness app or an employer can be outside HIPAA but inside GDPR. HIPAA does not cover most consumer health apps, because they are not covered entities.
The practical test differs. For HIPAA, ask what kind of organization you are. For GDPR, ask whose data you handle.
What Counts as Protected Health Data
HIPAA protects PHI, individually identifiable health information held by a covered entity or business associate. This includes diagnoses, treatment records, billing tied to care, and identifiers linked to that data.
GDPR uses a wider net. All personal data is protected, and data concerning health is a special category under Article 9. Special category data needs stronger safeguards and a specific legal condition to process.
The scope gap matters for AI. Health signals that fall outside HIPAA, like data from a wellness app, can still be special category data under GDPR.
When data is truly de-identified, HIPAA rules ease. GDPR anonymization is a high bar, and data that can be re-linked to a person still counts as personal data.
Consent and Lawful Basis
HIPAA and GDPR treat consent very differently. HIPAA lets covered entities use PHI for treatment, payment, and healthcare operations without separate patient sign-off. Written authorization is needed for uses outside those permitted purposes, like marketing.
GDPR requires a lawful basis before any processing. Article 6 lists the options, such as consent, contract, or legitimate interests.
Health data adds a second layer. Under Article 9, you also need a specific condition, and explicit consent is the most common one. Both Article 6 and Article 9 must be met at the same time.
So GDPR often demands a clear, freely given yes for health data. HIPAA leans on permitted uses for core care, and asks for authorization only outside them.
Vendor Contracts: BAA vs DPA and the AI Angle
Both rules require a written contract before a vendor touches protected data, but they use different names. HIPAA requires a Business Associate Agreement, a BAA, before a vendor handles PHI. GDPR requires a Data Processing Agreement under Article 28 between the controller and its processor.
This is the sharpest risk point for AI tools. Most consumer AI assistants and note-takers do not sign a BAA by default. Without one, sending PHI to them can breach HIPAA.
In our AI-compliance work with healthcare-adjacent and nonprofit clients, the failure mode we see most is staff pasting patient data into consumer AI tools with no BAA in place. The tool may be capable, but the contract is missing.
Some enterprise AI vendors will sign a BAA and a Data Processing Agreement for eligible plans. Microsoft offers a HIPAA BAA for covered services, and OpenAI offers a BAA for eligible API use. Confirm coverage in writing before any real health data flows in.
- HIPAA: sign a BAA before any PHI reaches the vendor.
- GDPR: sign an Article 28 Data Processing Agreement with each processor.
- AI tools: default consumer versions rarely include either. Verify the plan and the signed contract first.
Breach Notification Timelines
The breach clocks are very different, so verify the exact rule that applies to you. Under the HIPAA Breach Notification Rule, covered entities must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery. Notice to HHS follows related deadlines that depend on how many people are affected.
GDPR is faster for the regulator. Under Article 33, a controller must notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a breach.
The 72-hour clock starts when you have reasonable certainty a breach happened, not when the full investigation ends. A late notice must explain the delay.
GDPR also requires telling affected individuals when the breach is likely to be a high risk to their rights. Always confirm current windows on HHS.gov and with your supervisory authority, because details vary by case.
Penalties for Getting It Wrong
Both regimes carry real financial risk, but they calculate it differently. HIPAA uses tiered civil money penalties based on the level of culpability, and the amounts are adjusted each year for inflation. Serious or willful violations can also lead to criminal charges.
GDPR fines are set by turnover. Article 83 creates two tiers, and the higher tier reaches up to 20 million euros or 4% of global annual turnover, whichever is greater.
Do not rely on a memorized dollar figure for HIPAA. The tier amounts and annual caps change, so check the current numbers on HHS.gov before you quote them.
Beyond fines, both bring investigation costs, corrective action plans, and reputational harm. For many organizations, the cleanup and lost trust outlast the penalty itself.
What It Means for AI Tools Handling Health Data
AI tools do not get a pass on either rule. If an AI system processes PHI, HIPAA treats the vendor as a business associate that needs a BAA. If it processes health data about people in the EU or UK, GDPR treats the vendor as a processor that needs an Article 28 agreement.
Free and personal AI accounts are the usual trap. Consumer versions of ChatGPT, Gemini, and similar tools are built for general use, not regulated health data, and rarely sign these contracts.
GDPR adds duties that AI teams often miss. You may need a Data Protection Impact Assessment for high-risk processing, and clear limits on how model providers reuse inputs.
The safe path is boring and effective. Use enterprise plans with signed contracts, turn off training on your data where possible, minimize what you send, and keep a record of your legal basis.
- Confirm the vendor will sign a BAA (HIPAA) and a Data Processing Agreement (GDPR).
- Use enterprise or business tiers, not personal accounts, for regulated data.
- Turn off or contractually limit training on your inputs.
- Assess high-risk AI processing before launch, and document your lawful basis.
Which One Applies to Me?
The answer for many organizations is both. HIPAA applies if you are a US covered entity or business associate handling PHI. GDPR applies if you process personal data about people in the EU or UK, wherever your organization sits.
Start with two questions. Do you handle PHI as a US healthcare organization or its vendor? Do you handle data about people in the EU or UK?
A yes to the first pulls in HIPAA. A yes to the second pulls in GDPR. A yes to both means you build to satisfy each, usually by meeting the stricter requirement in each area.
When in doubt, map your data flows and get professional review. This guide is practical guidance, not legal advice, and the official sources plus qualified counsel should confirm your obligations.
The Verdict
HIPAA and GDPR are not interchangeable, and treating one as a substitute for the other is a costly mistake. HIPAA is sector-specific and US-focused, built around covered entities, PHI, and the BAA. GDPR is broad and person-focused, covering all personal data of people in the EU and UK, with health data protected as a special category.
If you serve US patients, you need HIPAA. If you touch data about people in the EU or UK, you need GDPR. Many organizations, especially telehealth, digital health, and cross-border employers, need both at the same time.
GDPR is broader and generally stricter on consent, individual rights, and breach speed, with its 72-hour authority notice and turnover-based fines. HIPAA is narrower but detailed, with permitted uses for core care and its own 60-day individual notice window. Where both apply, meeting the tougher standard in each area is the cleanest route.
For AI, the deciding factor is the same under both rules: a signed vendor contract and disciplined data handling. Verify current penalty figures and breach windows on the official pages, and get qualified legal review before you rely on any single interpretation.
Researched from primary vendor documentation and public regulator sources. Pricing and availability are accurate as of Aug 19, 2026 and can change — confirm current terms with each vendor before you buy.
Frequently Asked Questions
- Neither is simply stricter, because they cover different things. GDPR is broader and often tougher on consent, individual rights, and breach speed. HIPAA is narrower but detailed for US health data, with its own rules on permitted uses and business associates.
- Yes, and many are. A US healthcare or digital health organization that also serves people in the EU or UK can be bound by HIPAA and GDPR at the same time. The usual approach is to meet the stricter requirement in each area.
- A BAA is HIPAA's required contract before a vendor handles PHI. A Data Processing Agreement under Article 28 is GDPR's required contract between a controller and its processor. They serve a similar role but come from different laws, so you may need both.
- GDPR is faster for regulators. Article 33 requires notifying the supervisory authority within 72 hours where feasible. HIPAA requires notifying affected individuals no later than 60 calendar days after discovery. Verify current details on HHS.gov and with your supervisory authority.
- Yes. GDPR classifies health data as a special category under Article 9. Processing it needs a lawful basis under Article 6 plus a specific Article 9 condition, often explicit consent. Both conditions must be met at once.
- Usually not for regulated data. Personal and free AI accounts rarely sign a BAA or a Data Processing Agreement. Use enterprise plans with signed contracts, limit training on your inputs, and confirm coverage in writing before sending real health data.
- HIPAA uses tiered civil money penalties based on culpability, adjusted yearly, plus possible criminal charges. GDPR's higher fine tier reaches up to 20 million euros or 4% of global annual turnover, whichever is greater. Verify current HIPAA figures on HHS.gov.
- Probably not, unless you handle data about people in the EU or UK. GDPR follows the data subject, not just the organization's location. If you have no EU or UK users and do not monitor them, HIPAA is likely your main concern.
Not Sure Whether HIPAA, GDPR, or Both Apply to Your AI Tools?
Layer3 Labs helps healthcare and cross-border teams roll out AI without breaching HIPAA or GDPR. We map your data flows, check vendor BAAs and Data Processing Agreements, and flag the gaps before regulators do. Book a free AI compliance review to see where you stand.
Book a Consultation