Your marketing coordinator just launched a German-language landing page for the practice's joint replacement program, complete with a euro-denominated price sheet and an intake form. Nobody asked the privacy officer. Six weeks later a prospective patient in Munich emails asking your practice to delete everything you hold on her — and cites a regulation your policy binder has never mentioned. That is the moment the hipaa vs gdpr question stops being academic and becomes a documented obligation with a one-month clock attached.

This article is for the person who has to answer that email. It covers which law applies to your practice, what each one requires in writing, where the timelines diverge, and what evidence you need in the file if a regulator ever asks.

The 90-Second Version: Does GDPR Even Apply to Your Practice?

GDPR applies to your US practice only if one of these is true:

  • You offer goods or services to people located in the EU or EEA — evidenced by things like foreign-language marketing, euro pricing, EU country codes in your booking form, or a medical tourism referral arrangement.
  • You monitor the behavior of people located in the EU — remote patient monitoring, a wearable-linked app, or ad-tracking pixels served to EU visitors.
  • You have an establishment in the EU — a satellite office, an EU-based employee, a research site.

What does not trigger GDPR: treating a German tourist who walks into your urgent care while visiting Ohio. Incidental treatment of a person who happens to be an EU citizen is not "offering services to data subjects in the Union." Citizenship is irrelevant; location and intent are what matter.

Meanwhile, HIPAA applies based on what you are, not who your patients are. If you are a covered entity that transmits health information electronically in connection with a standard transaction, HIPAA governs every patient record you hold — including the record of that patient in Munich.

HIPAA vs GDPR: Who Is Regulated and What Data Is Covered

HIPAA is entity-based and narrow

HIPAA reaches covered entities (providers, health plans, clearinghouses) and their business associates. It protects protected health information — individually identifiable health information created or received by those entities. Your employee HR files are not PHI. Your patient's browsing history on a site you don't control is not PHI.

That narrowness is why the FTC's Health Breach Notification Rule exists for health apps outside HIPAA. The FTC's health privacy guidance for businesses is worth a read if your practice has spun off a wellness app or a direct-pay concierge arm that may sit outside covered-entity status.

GDPR is activity-based and broad

GDPR protects all "personal data" of identified or identifiable natural persons. Health data, genetic data, and biometric data used for identification are "special categories" under Article 9, requiring an additional lawful condition on top of the Article 6 basis. Employee data, vendor contact data, and website analytics all fall inside the perimeter.

Practical consequence: if GDPR applies to your practice at all, it applies to your staff records and your email marketing list, not just your charts. Privacy officers routinely underestimate this scope expansion.

The Contract Problem: BAA Under HIPAA vs Article 28 DPA Under GDPR

HIPAA requires a Business Associate Agreement before a vendor creates, receives, maintains, or transmits PHI on your behalf. HHS publishes sample BAA provisions, and those provisions are the floor, not the ceiling.

GDPR requires a Data Processing Agreement under Article 28 between controller and processor, with mandatory terms: documented instructions, confidentiality commitments, security measures, sub-processor authorization, assistance with data subject rights, deletion or return at contract end, and audit rights.

The overlap is real but incomplete. A BAA does not obligate your vendor to assist with erasure requests or to name sub-processors. A DPA does not obligate your vendor to report to HHS or to comply with the Security Rule's specific administrative safeguards. If a vendor touches both regimes, you need both instruments — often as a single contract with two annexes.

The failure mode here is boring and common: the practice signs the vendor's template, never reads the sub-processor clause, and discovers during a breach that the transcription service outsourced to a fourth party in a country with no adequacy decision. If your vendor list has grown faster than your contract file, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX — a one-time purchase, no subscription, which is usually faster than chasing counsel for a fifteenth variation of the same document.

Cross-border transfers add a third layer

If GDPR applies and you move data from the EU to the US, you need a Chapter V transfer mechanism — typically Standard Contractual Clauses, or reliance on the EU-U.S. Data Privacy Framework if your organization is eligible to self-certify. Note the eligibility trap: DPF self-certification requires being subject to FTC or DOT jurisdiction, which excludes many nonprofit health systems. Nonprofit practices generally land on SCCs plus a transfer impact assessment.

Two Breach Clocks: 60 Days Under HIPAA, 72 Hours Under GDPR

This is the single most operationally dangerous difference in the hipaa vs gdpr comparison, because your incident response playbook probably assumes only one of them.

HIPAA. Notify affected individuals without unreasonable delay and no later than 60 calendar days from discovery. For breaches affecting 500 or more residents of a state or jurisdiction, notify HHS contemporaneously and provide notice to prominent media outlets. For breaches under 500, log them and submit annually, within 60 days after the end of the calendar year. HHS maintains the Breach Notification Rule guidance, and every reportable breach lands on the public OCR breach portal.

GDPR. Notify the lead supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware — unless the breach is unlikely to result in a risk to individuals. If the breach is likely to result in a high risk, communicate to affected individuals without undue delay as well. There is no volume threshold and no annual log option.

Read those side by side. Under HIPAA, a low-probability-of-compromise risk assessment can conclude that no breach occurred. Under GDPR, the default is to notify unless you can document why risk is unlikely. Under HIPAA you have weeks. Under GDPR you have three days, including weekends.

What this means for your incident runbook

  1. Hour 0-4: Contain. Identify the data categories and whether any affected individuals were located in the EU at the time of collection.
  2. Hour 4-24: Privacy officer opens a single incident record. Two determinations run in parallel: HIPAA four-factor risk assessment, and GDPR risk-to-rights assessment.
  3. Hour 24-72: If GDPR applies, file with the supervisory authority even if the investigation is incomplete — Article 33 permits phased notification.
  4. Day 3-60: Complete the HIPAA determination, draft individual notices, and document the decision either way. "We concluded no breach occurred" is only defensible if the four-factor analysis is in writing.

Patient Access: 30 Days Under HIPAA, One Month Under GDPR

HIPAA's right of access requires you to act on a request within 30 calendar days, with one 30-day extension if you notify the individual in writing of the reason and the new date. Fees must be reasonable and cost-based. HHS has published extensive right of access guidance, and access failures have been one of OCR's most consistent enforcement themes for years.

GDPR's Article 15 subject access right runs one month from receipt, extendable by two further months for complex or numerous requests — but you must inform the requester of the extension within the first month. The first copy is free.

The erasure trap

HIPAA gives patients a right to amend a record, not to delete it. Your retention obligations come from state law, CMS conditions of participation, malpractice statutes of limitation, and payer contracts. You cannot simply delete a chart because someone asked.

GDPR's Article 17 right to erasure has exceptions that cover most of this — processing necessary for compliance with a legal obligation, for preventive or occupational medicine, or for public health purposes. So the correct response to a deletion demand from an EU patient is usually a documented refusal citing the applicable exception, not compliance and not silence. Draft that template before you need it, and have counsel review the citation.

HIPAA lets you use PHI for treatment, payment, and health care operations without patient authorization. Marketing communications and sale of PHI require authorization. That's the whole framework, and most practices manage it through the Notice of Privacy Practices plus a signed authorization form for the exceptions.

GDPR requires you to identify and record a lawful basis for every processing activity before you start, plus an Article 9 condition for health data. Consent under GDPR must be freely given, specific, informed, unambiguous, and as easy to withdraw as to give. Pre-checked boxes fail. Bundled consent fails.

This is why an unreviewed marketing campaign is a bigger GDPR risk than a clinical workflow. Clinical care usually has a solid Article 9(2)(h) footing. A newsletter blast to EU addresses collected from a webinar signup usually does not.

Roles and Records: Privacy Officer vs Data Protection Officer

HIPAA requires a designated Privacy Official and a Security Official — one person can hold both roles at a small practice, and the designation must be documented.

GDPR requires a Data Protection Officer when core activities involve large-scale processing of special category data. A hospital system almost certainly needs one. A three-provider clinic with occasional EU telehealth almost certainly does not — but you should write down the analysis that led to that conclusion.

GDPR also requires Article 30 records of processing activities. The under-250-employee exemption evaporates when you process special category data on anything other than an occasional basis, which describes every medical practice. If GDPR applies to you, build the processing inventory.

Where the two frameworks are converging

HHS published a proposed overhaul of the Security Rule in January 2025 that would replace much of the addressable/required structure with explicit mandates — asset inventories, network mapping, encryption, multi-factor authentication, and defined timelines. It is not final. But the direction of travel is toward the kind of specificity GDPR practitioners already live with, and toward the risk-analysis discipline described in NIST SP 800-66 Revision 2. If you build to that standard now, a final rule becomes a documentation exercise rather than a rebuild.

Your Q1 2026 Sequencing Plan

  1. Week 1 — Scope determination. Privacy officer documents, in one page, whether GDPR applies. Inputs: marketing languages and currencies, telehealth state and country licensure, research affiliations, EU-based staff or contractors, website analytics geography. Sign and date it. Re-review annually or when marketing changes.
  2. Week 2-3 — Contract audit. Pull every vendor with data access. Confirm a current BAA. Where GDPR applies, confirm an Article 28 DPA and a transfer mechanism. Flag missing sub-processor disclosures.
  3. Week 4 — Runbook update. Add the 72-hour branch to your incident response procedure and name who makes the call at 2 a.m. on a Saturday.
  4. Week 5-6 — Request templates. Access acknowledgment, extension letter, erasure refusal with citation, and a fee schedule that survives scrutiny.
  5. Week 7-8 — Risk analysis refresh. Update your Security Rule risk analysis and map the findings to your safeguards. If you are still doing this in a spreadsheet that nobody has opened since 2023, automated risk analysis and policy generation will get you to a defensible document set faster than another all-hands meeting.

The Documentation Standard Both Regimes Share

Whatever the hipaa vs gdpr analysis produces for your practice, the evidentiary expectation is identical: a regulator asks what you decided, when, and on what basis. Undocumented good judgment is indistinguishable from negligence in an audit file.

Start with the contracts, because they are the fastest gap to close and the most common finding. If your vendor file has holes, build the missing Business Associate Agreements now — six steps, PDF and DOCX export, one-time purchase — and get signatures before your next new-vendor onboarding creates another one.