Do health data rules apply to a cloud provider?
Short answer
Yes as a business associate in the US sense and as a processor in the EU sense, when health records are hosted.
Read against the registers 2026-08-26.
Who the role is
Whoever runs infrastructure, hosting or a platform for someone else's data and traffic.
What the topic covers
Health records are a special category everywhere, but the boundary differs. The GDPR follows the data. HIPAA follows the covered entity. PIPL follows the sensitive category and asks for separate consent.
Duties the EU acts name for this role
- GDPR — Regulation (EU) 2016/679, Article 28: Process personal data only on documented instructions, under a written processor agreement.
The rows behind the answer
European Union
- GDPR — Regulation (EU) 2016/679: Health data is a special category: processing needs a condition in addition to the legal basis.
United States
- HIPAA Security Rule: Applies to covered entities and business associates, with administrative, physical and technical safeguards.
China
- Personal Information Protection Law of the People's Republic of China: Health data is sensitive personal information: separate consent and a necessity assessment apply.
Where companies usually start
- Decide first whether you are a covered entity in the US sense, then read the EU and Chinese tests separately.
- Write the necessity assessment before the product decision, not after it.
- Keep access logs for health records apart from general application logs.
This page reads published registers and describes common practice. It is not legal advice and it is not a compliance verdict.
Other questions for cloud service provider
- Do ai governance rules apply to a cloud provider?
- Do personal data rules apply to a cloud provider?
- Do cross-border data rules apply to a cloud provider?
- Do cybersecurity rules apply to a cloud provider?
- Do online platforms rules apply to a cloud provider?
- Do consumer rights rules apply to a cloud provider?
- Do product safety rules apply to a cloud provider?
- Do climate disclosure rules apply to a cloud provider?
- Do export controls rules apply to a cloud provider?
ExploreWorldAI is operated by Valkiv Ventures AB (Reg. no. 556995-1311), Kungsgatan 8, 111 43 Stockholm, Sweden. EU-hosted, with data processing assessed against the GDPR. Contact: hello@exploreworldai.com.
Machine-readable summaries for AI agents: /llms.txt and /llms-full.txt.