Updated: August 2026
What is HIPAA? Are there similarities and differences between HIPAA and GDPR? And does your organisation need to comply with both?
• HIPAA protects the health data of US citizens wherever it’s processed, while GDPR protects the personal data of EU and EEA residents wherever it’s processed, so the two laws can apply to the same organisation at the same time.
• HIPAA fines scale with culpability, from $137 for a minor tier-1 violation up to $2,067,813 a year for wilful neglect, while GDPR fines can reach €20 million or 4% of global annual turnover, whichever is higher.
• Meeting HIPAA doesn’t mean an organisation also meets GDPR, or the other way round: both require consent and both reach across borders, but HIPAA takes a risk-based approach to health data specifically, while GDPR takes a rights-based approach across every sector.
HIPAA is the Health Insurance Portability and Accountability Act of 1996. It was designed to prevent the disclosure of patient-sensitive data (Protected Health Information, or PHI) without the patient’s consent or knowledge. A federal law, it applies to the PHI of US citizens, regardless of where that data is held.
If an international company processes US PHI data, it’s as bound by HIPAA as an organisation in Maine, Montana, or Mississippi.
HIPAA imposes administrative, physical, and technical safeguards on US patient data. It sets boundaries for releasing health records and requires healthcare providers and related entities to implement detailed security measures, including access controls, encryption, and employee training. It gives patients more control over their personal information.
HIPAA compliance is required for all “covered entities” and their “business associates.” Covered entities are healthcare providers (like doctors, clinics, and hospitals), health plans (like insurance companies), and clearinghouses. Business associates are any third parties that handle Protected Health Information on behalf of a covered entity, such as billing companies, cloud storage providers, or IT contractors. If these organisations process or access the PHI of US citizens, regardless of their location, they must comply with HIPAA requirements.
GDPR is the General Data Protection Regulation, a data privacy law enacted by the European Union in 2016 and enforced from 25 May 2018. It was created to protect the personal data of individuals within the EU and EEA and to give them more control over how their data is collected, used, and stored. The law applies regardless of where the data processor or controller is located. If a company outside the EU handles the personal data of EU citizens, it must comply with GDPR just as a company based in France, Finland, or Germany would.
Any organisation, whether inside or outside the EU, must comply with GDPR if it collects or processes data of people located in the EU or EEA. This includes businesses, non-profits, public authorities, and third parties that store, manage, or analyse such data. Both data controllers (who determine how and why data is used) and data processors (who handle data on behalf of controllers) must meet GDPR requirements.
GDPR imposes strict rules on collecting, processing, and storing personal data. It grants individuals several key rights, including the right to access, correct, delete, or restrict the use of their data. Organisations must implement strong data protection measures, conduct impact assessments, report breaches, and gain explicit consent when needed. GDPR increases transparency, accountability, and trust in how personal information is handled.
The General Data Protection Regulation (GDPR) grants individuals a wider range of rights than HIPAA. GDPR gives data subjects the right to access their data, the right to be forgotten, and the right to data portability. GDPR rights also extend beyond healthcare settings.
HIPAA violations can result in significant penalties, ranging from fines to criminal charges. The level of culpability determines the fine tier, and the tier determines the per-violation fine.
At the time of writing, for example, the minimum penalty for a tier 1 violation, that is, a violation due to a lack of knowledge, could be as little as $137. In contrast, a tier 4 violation (one that involves wilful neglect not corrected within 30 days of becoming aware of the violation) could attract the maximum yearly penalty of $2,067,813.
GDPR’s maximum fine operates on a different scale, with companies liable for €20 million or 4% of annual global turnover, whichever is greater.
HIPAA applies to the data of US citizens. GDPR applies to the data of EU residents. Here’s what that means in practice:
• Noah is a US citizen but spends a year studying in Paris and is therefore an EU resident. His PHI is protected by HIPAA, no matter where that data is processed, because he remains a US citizen. His personal data is also protected by GDPR, no matter where it is processed, because he is an EU resident. It will remain protected for as long as he remains in the EU.
• Isabella is originally from Spain. She’s currently living and working in Boston for a few months. Her PHI is not protected by HIPAA because she is not a US citizen. Her personal data is not protected by GDPR either, because she is not currently an EU resident.
• XYZ Inc. is a US organisation based in Tampa that handles a lot of personal data, some of it relating to EU residents and some to US citizens. It is bound by GDPR even though it is not based in the EU. If it processes health-related data, it is also bound by HIPAA.
• ABC AG is a German company based in Düsseldorf. It processes the personal health information of US citizens and EU residents. It is bound by HIPAA because the data it holds is PHI-related. It is also bound by GDPR because the personal health data it holds qualifies as personal data for GDPR purposes.
Only in a fairly loose sense. They are both data protection laws. Both are mandatory. Both have extraterritorial reach, meaning they apply wherever the data they protect is processed.
Both laws also require organisations that handle personal data to obtain meaningful consent. GDPR emphasises explicit, informed consent for data processing activities, so individuals know how their data will be used and can choose to grant or withhold it. HIPAA requires health providers to gain patient consent for the use of PHI in all but routine circumstances.
Beyond these points, it’s almost surprising how little HIPAA and GDPR overlap. The main reason is how each law was drafted. HIPAA’s legislators took a risk-based approach, which is why the law contains language like this:
Entities must:
• Detect and safeguard against anticipated threats to the security of the information
• Protect against anticipated impermissible uses or disclosures that are not allowed by the rule
• Certify compliance by their workforce
GDPR takes a rights-based approach instead, built around explicit and informed consent for data processing activities, so individuals understand how their data will be used and can grant or withhold consent accordingly.
We speak with many organisations looking to ensure compliance across legislation. They expect that meeting their obligations for one standard will largely mean meeting them for both. Our comparison of HIPAA and GDPR shows that’s not the case.
HIPAA focuses on safeguarding the health data of US citizens, while GDPR applies to individuals’ rights across every sector, including health. Compliance with both laws overlaps in some basic ways, but the differences are significant enough that meeting one doesn’t mean you’ve met the other.
GDPRLocal can help ensure you correctly comply with the data protection legislation of all the territories in which you trade. Get expert help managing your data protection here, appoint your Article 27 GDPR rep, or call +1 303 317 5998.
HIPAA requires organisations to protect patient data with administrative, physical, and technical precautions. It limits how health records are shared and ensures security measures like access control and encryption are in place. It also gives patients more control over their health information.
Companies that violate HIPAA face fines based on the severity of the violation. Minor, unintentional breaches might cost as little as $137, while severe cases involving wilful neglect can lead to fines of over $2 million annually. Some violations may also lead to criminal charges.
GDPR requires that personal data be collected lawfully, used fairly, kept secure, and only held as long as necessary. It emphasises transparency and gives individuals rights like access, correction, and deletion of their data, with consent being a key requirement.
GDPR violations can result in fines of up to €20 million or 4% of a company’s global annual revenue, whichever is higher. The fine amount depends on the severity of the breach and how the company responds.
Disclaimer: This blog post is intended solely for informational purposes. It does not offer legal advice or opinions. This article is not a guide for resolving legal issues or managing litigation on your own. It should not be considered a replacement for professional legal counsel and does not provide legal advice for any specific situation or employer.