Do health data rules apply to a manufacturer?
Short answer
Yes for products that record health data. The special category rules apply to the manufacturer for the records it holds.
Read against the registers 2026-08-26.
Who the role is
Whoever makes the product, or puts a name or trademark on it, carries the first line of product duties.
What the topic covers
Health records are a special category everywhere, but the boundary differs. The GDPR follows the data. HIPAA follows the covered entity. PIPL follows the sensitive category and asks for separate consent.
The rows behind the answer
European Union
- GDPR — Regulation (EU) 2016/679: Health data is a special category: processing needs a condition in addition to the legal basis.
United States
- HIPAA Security Rule: Applies to covered entities and business associates, with administrative, physical and technical safeguards.
China
- Personal Information Protection Law of the People's Republic of China: Health data is sensitive personal information: separate consent and a necessity assessment apply.
Where companies usually start
- Decide first whether you are a covered entity in the US sense, then read the EU and Chinese tests separately.
- Write the necessity assessment before the product decision, not after it.
- Keep access logs for health records apart from general application logs.
This page reads published registers and describes common practice. It is not legal advice and it is not a compliance verdict.
Other questions for manufacturer
- Do ai governance rules apply to a manufacturer?
- Do personal data rules apply to a manufacturer?
- Do cross-border data rules apply to a manufacturer?
- Do cybersecurity rules apply to a manufacturer?
- Do online platforms rules apply to a manufacturer?
- Do consumer rights rules apply to a manufacturer?
- Do product safety rules apply to a manufacturer?
- Do climate disclosure rules apply to a manufacturer?
- Do export controls rules apply to a manufacturer?
ExploreWorldAI is operated by Valkiv Ventures AB (Reg. no. 556995-1311), Kungsgatan 8, 111 43 Stockholm, Sweden. EU-hosted, with data processing assessed against the GDPR. Contact: hello@exploreworldai.com.
Machine-readable summaries for AI agents: /llms.txt and /llms-full.txt.