Reviewed by Jonathan West · Updated Aug 19, 2026

AI + Health-Data Privacy Laws by Country

How each country's HIPAA-equivalent law governs AI use with medical and client data, and how to find the right rules for where you operate.

Reviewed by Jonathan West · Updated Aug 19, 2026

There is no single global HIPAA. Every country writes its own health-privacy law, with its own regulator, its own definition of health data, and its own rules for AI. If you handle medical or client data in more than one country, you must follow each country's law where the people you serve live.

This hub compares five common regimes: the United States (HIPAA), New Zealand (Privacy Act 2020 and the Health Information Privacy Code 2020), Australia (Privacy Act 1988 and the Australian Privacy Principles), the UK and EU (UK GDPR and EU GDPR), and Canada (PIPEDA plus Ontario's PHIPA). For each, we name the law, the regulator, what counts as health data, the offshore-transfer rule, and one AI-specific catch.

Use the country guides linked throughout to go deeper. This page is practical guidance, not legal advice, so confirm the details on each regulator's official page and get local review before you deploy AI on real health data.


Health-Privacy Laws by Country: A Side-by-Side View

Each country's HIPAA-equivalent law shares the same goal but differs in the details. Below is the law, the regulator, the definition of health data, the cross-border rule, and one AI implication for each of the five regimes.

Read the row for every country where your patients, clients, or donors live. The country guides linked at the end of this page cover each in full.

  • United States (HIPAA): The Health Insurance Portability and Accountability Act, enforced by the U.S. Department of Health and Human Services Office for Civil Rights. It protects "protected health information" (PHI) held by covered entities (providers, health plans, clearinghouses) and their business associates. HIPAA sets no flat geographic ban on offshore storage, but the covered entity stays responsible and needs a signed agreement with any vendor. AI catch: a consumer AI tool is a business associate only if it signs a Business Associate Agreement (BAA), and most do not by default.
  • New Zealand (Privacy Act 2020 + Health Information Privacy Code 2020): Enforced by the Office of the Privacy Commissioner. The Code sets 13 health-information privacy rules for any "health agency" and defines health information broadly. Rule 12 limits sending health information to a foreign person or entity unless comparable safeguards apply. AI catch: putting patient notes into an offshore AI service can be a cross-border disclosure under Rule 12.
  • Australia (Privacy Act 1988 + Australian Privacy Principles + My Health Records): Enforced by the Office of the Australian Information Commissioner. Health information is "sensitive information" under the 13 APPs, and the My Health Records Act 2012 adds rules for connected practices. APP 8 makes you accountable for personal information you disclose overseas. AI catch: sending health data to an overseas AI vendor triggers your APP 8 accountability for what that vendor does with it.
  • United Kingdom and European Union (UK GDPR / EU GDPR): The UK is overseen by the Information Commissioner's Office; EU member states have their own supervisory authorities coordinated by the European Data Protection Board. Health data is "special category" data under Article 9 and needs both an Article 6 lawful basis and an Article 9 condition. Transfers outside the UK or EEA need adequacy or an Article 46 safeguard. AI catch: training or processing health data in a foreign AI model is a restricted transfer that needs a safeguard and a risk assessment.
  • Canada (PIPEDA federal + PHIPA Ontario): The federal law is overseen by the Office of the Privacy Commissioner of Canada; in Ontario, health information is governed by PHIPA and the Information and Privacy Commissioner of Ontario. PHIPA governs "personal health information" held by a health information custodian and is deemed substantially similar to PIPEDA. Under PIPEDA's accountability principle you stay responsible for data you transfer to a processor, including one outside Canada. AI catch: an offshore AI vendor is a transfer for processing, so you remain accountable for its safeguards.

Operating across the US, New Zealand, Australia, the UK, or Canada and unsure which health-privacy law governs your AI tools? Layer3 Labs maps each country's rules to your workflow so you can deploy AI without a cross-border misstep.

Book a Consultation

What Is the Same Almost Everywhere

The five regimes disagree on words but agree on core duties. If you build to the strictest common standard, you cover most of what each law asks.

These shared duties are a useful checklist before any AI project touches health data. Confirm the exact wording with the regulator for your country, because thresholds and timelines differ.

The overlap exists because these laws share the same fair-information roots. That is good news for a team that operates in several countries. You do not need five separate programs. You need one strong baseline and a short list of local add-ons.

  • Lawful basis and consent: You need a clear, lawful reason to collect and use health data, and often explicit consent for sensitive uses.
  • Data minimization: Collect and share only the health data you actually need for the task.
  • Security safeguards: You must protect health data with reasonable technical and organizational controls, such as access limits and encryption.
  • Breach notification: Serious breaches must be reported to the regulator, and often to affected people, within the timeframe each law sets.
  • Vendor and processor contracts: A written agreement (a BAA in the US, a data processing agreement or DPA under GDPR, a comparable contract elsewhere) must bind any vendor that handles the data.
  • Cross-border transfer limits: Sending health data to another country is restricted, and you stay responsible for how the overseas recipient handles it.
Build to the strictest rule that applies to you, and the weaker regimes are usually satisfied too.

How AI Changes the Picture

AI does not create new privacy laws, but it stresses the ones you already have in specific ways. Four issues come up in almost every health AI project.

The first is training-data reuse. Some consumer AI tools may use your inputs to improve their models, which can be an unlawful secondary use of health data. Turn this off or use an enterprise tier that contractually prevents it.

The second is offshore cloud processing. Most large AI services run in data centers abroad, so a single prompt can become a cross-border transfer under Rule 12, APP 8, GDPR Chapter V, or PIPEDA accountability.

The third is automatic note-taking and recording. AI scribes and meeting recorders capture health data by default, so consent, retention limits, and a signed vendor agreement all apply before you switch one on.

The fourth is human oversight. AI can be wrong, so a person should review AI output before it affects care, eligibility, or a client record. In our AI-compliance work with healthcare-adjacent and nonprofit clients, the failure mode we see most is staff pasting client data into consumer AI tools with no signed agreement in place.

  • Disable training on your data, or use a tier that bans it in the contract.
  • Confirm where the AI vendor processes and stores data, and whether that triggers a cross-border rule.
  • Get consent and a vendor agreement before deploying an AI note-taker or recorder.
  • Keep a human in the loop for any output that affects a person's care or record.

The Cross-Border Trap Most Teams Miss

Cross-border transfer is the rule AI most often breaks by accident. The moment health data leaves the country in a prompt or an upload, a transfer rule can apply.

In New Zealand, Rule 12 of the Health Information Privacy Code limits disclosing health information to an overseas entity without comparable safeguards. In Australia, APP 8 keeps you accountable for what an overseas recipient does. In the UK and EU, a transfer outside the UK or EEA needs adequacy or an Article 46 safeguard plus a transfer risk assessment. In Canada, PIPEDA's accountability principle keeps you responsible for any processor abroad.

The practical fix is the same everywhere: know where your AI vendor processes data, prefer a region that matches your users, and sign a contract that binds the vendor to protect the data.


Common Health-AI Mistakes Across Every Regime

The same handful of mistakes causes most health-AI privacy problems, no matter which country's law applies. Knowing them helps you spot risk before a tool goes live.

The most common is treating a consumer AI account as safe for health data. Without a signed agreement, that vendor is not bound to protect the data, and you may have already breached your duty.

A close second is ignoring where data goes. Teams enable an AI feature in an app they already trust, without checking that the processing happens abroad. That quiet default can trip a cross-border rule.

The third is skipping the record of why. Every regulator wants to see your reasoning, so a short written note of your lawful basis, vendor checks, and controls is worth the time.


How to Choose Your Compliance Path

Start by listing every country where the people in your data live, not just where your office sits. Your obligations follow the individuals, so a New Zealand clinic serving Australian patients may face both regimes.

If you operate in one country, follow that country's guide, map your AI tools to its rules, and sign the right vendor agreement. If you operate in several, build to the strictest common standard and confirm each country's extra requirements.

Then choose AI tools that fit. Prefer enterprise tiers that sign a BAA or DPA, keep data in a region you control, and let you disable training on your inputs. Document your decisions so you can show the regulator your reasoning.

Do not forget your existing tools. Many teams already run AI inside email, note apps, and video calls without noticing. Inventory what is switched on today, then decide what is safe to keep for health data.

Finally, get local legal review before go-live. This page and the country guides help you ask better questions, but a qualified adviser confirms the final answer for your situation.

  • Map data by where people live, not where you are based.
  • One country: follow its guide and sign its required vendor contract.
  • Several countries: build to the strictest rule, then add local extras.
  • Pick AI tools that offer a signed agreement, regional data, and no training on your data.
  • Document choices and get local legal review before launch.

Frequently Asked Questions

  • No. HIPAA is a United States law. Every other country has its own health-privacy regime, such as New Zealand's Health Information Privacy Code 2020, Australia's Privacy Act 1988, the UK and EU GDPR, and Canada's PIPEDA and PHIPA. You follow each country's law where the affected people live.
  • Usually the law of the country where the patient or client lives applies, not just where your organization is based. If you serve people in several countries, more than one regime can apply at once, so map your data by the people it describes.
  • Often, yes. Most AI services process data in data centers abroad, so a single prompt can be a cross-border transfer under NZ Rule 12, Australian APP 8, GDPR Chapter V, or PIPEDA accountability. Check where the vendor processes data and use a safeguard or matching region.
  • Not by default. A consumer AI tool is only a HIPAA business associate if it signs a Business Associate Agreement, which standard consumer tiers do not offer. Use an enterprise tier that will sign a BAA, or keep protected health information out of the tool.
  • Other regimes use a data processing agreement (DPA) or a comparable contract instead of a HIPAA BAA. Under GDPR you need an Article 28 processor agreement; under PIPEDA and PHIPA you need a contract that binds the vendor to protect the data. The name differs but the duty to bind your vendor is shared.
  • Every regime defines health data broadly. It generally covers any information about a person's physical or mental health, disability, or health services they received, and often genetic and biometric data. When in doubt, treat information that reveals someone's health status as regulated health data.
  • Usually you need a lawful basis, and often explicit consent, before using health data in AI. Consent rules differ by country and by use, so check the regulator's guidance and get review before deploying AI note-takers, scribes, or recorders that capture health data.
  • Build to the strictest common standard, then add each country's extra requirements. Sign the right vendor agreement, keep data in a region you control, disable training on your inputs, keep a human reviewing AI output, and document your reasoning for each country's regulator.

Not Sure Which Health-Privacy Rules Apply to Your AI?

Layer3 Labs helps healthcare-adjacent and nonprofit teams map their AI tools to the right health-privacy law in each country they serve. We find the gaps, from missing vendor agreements to accidental offshore transfers, and give you a clear path to fix them. Book a free AI compliance review to get started.

Book a Compliance Review