GDPR vs HIPAA
GDPR vs HIPAA for SaaS and health technology: compare protected data, territorial scope, legal roles, individual rights, security, and breach rules.
Key differences
| Dimension | GDPR | HIPAA |
|---|---|---|
| Protected information | GDPR covers personal data about an identifiable person; health data is a special category under Article 9. | HIPAA covers PHI created or received by covered entities and business associates; not all US health data is PHI. |
| Territorial and entity scope | Applies to covered EU establishments and Article 3 offering or monitoring, regardless of where the vendor is incorporated. | Applies by regulated role and PHI relationship in the United States, not simply because data is medically sensitive. |
| Organizational roles | Controllers determine purposes and means; processors act on documented instructions and manage subprocessors under Article 28. | Covered entities and business associates allocate duties through law and BAAs; subcontractors can also be business associates. |
| Legal basis | Processing needs an Article 6 basis and, for health data, an Article 9 condition unless an exception applies. | Uses and disclosures are allowed or required under Privacy Rule categories, authorizations, and minimum-necessary rules. |
| Individual rights | Articles 12–22 include access, correction, erasure, restriction, portability, objection, and automated-decision protections. | HIPAA provides access, amendment requests, accounting of disclosures, restrictions requests, and confidential communications, with different limits. |
| Security standard | Article 32 requires risk-appropriate technical and organisational measures for personal data. | The Security Rule specifies administrative, physical, and technical safeguards for ePHI at 45 CFR §§164.308–312. |
| Breach timing | Controllers generally notify authorities within 72 hours where Article 33’s risk threshold is met; processors notify controllers without undue delay. | Notices are due without unreasonable delay and no later than 60 days after discovery, with different individual, media, and HHS paths. |
Control overlap
Both regimes require accountable protection of health information, but the covered datasets are not coextensive. A single data inventory can tag GDPR personal and special-category data alongside HIPAA PHI/ePHI. Article 32 measures overlap with /controls/hipaa/164-308-a-1 risk analysis, /controls/hipaa/164-312-a-2-iv encryption, /controls/hipaa/164-312-b audit controls, and /controls/hipaa/164-312-e-1 transmission security. Vendor files can hold Article 28 DPAs and /controls/hipaa/baa-requirements evidence. Separate overlays are still needed for GDPR lawful basis, Chapter V transfers and broad rights, and HIPAA permitted-use, minimum-necessary, Notice of Privacy Practices, and BAA rules.
Sequencing advice
A SaaS or health-tech team should classify data by legal status before selecting controls: identify EU personal data, special-category health data, PHI/ePHI, the relevant entity role, purpose, geography, and recipient. Establish DPAs and BAAs as separate contractual tracks, then implement shared IAM, encryption, logging, retention, vendor, and incident operations. Design the incident playbook with two clocks and decision trees—GDPR’s 72-hour authority assessment and HIPAA’s discovery-based notification framework—plus customer escalation terms. Test access and amendment workflows using realistic support tickets, and obtain counsel review for lawful basis, authorizations, de-identification, and international transfers rather than assuming one regime’s permission covers the other.