Health data compared: GDPR, HIPAA and PIPL
How is health data treated in the EU, the United States and China?
Health records are a special category everywhere, but the boundary differs. The GDPR follows the data. HIPAA follows the covered entity. PIPL follows the sensitive category and asks for separate consent.
Rows read against the registers 2026-08-26.
European Union
- GDPR — Regulation (EU) 2016/679, 32016R0679: Health data is a special category: processing needs a condition in addition to the legal basis.
Open the European Union register
United States
- HIPAA Security Rule, 45 CFR Part 164, Subpart C: Applies to covered entities and business associates, with administrative, physical and technical safeguards.
Open the United States register
China
- Personal Information Protection Law of the People's Republic of China, PIPL, adopted by the NPCSC on 20 August 2021: Health data is sensitive personal information: separate consent and a necessity assessment apply.
What they ask for in common
- All three treat health records as a category that needs more than a general notice.
- All three require access to the records to be limited and logged.
Where they differ
- HIPAA scope follows who you are. The GDPR and PIPL scope follows what the data is.
- A wellness app outside a covered entity can sit outside HIPAA and inside the GDPR at the same time.
- PIPL asks for a separate consent step, which the GDPR usually handles through an Article 9 condition.
What companies usually do first
- Decide first whether you are a covered entity in the US sense, then read the EU and Chinese tests separately.
- Write the necessity assessment before the product decision, not after it.
- Keep access logs for health records apart from general application logs.
This page describes what the registers say and what is common practice. It is a reading of published sources, not legal advice, and it is not a compliance verdict.
Does this apply to us
- Do health data rules apply to an online marketplace?
- Do health data rules apply to an online seller?
- Do health data rules apply to a manufacturer?
- Do health data rules apply to an importer?
- Do health data rules apply to a cloud provider?
Related comparisons
- AI rules compared: EU, United States and China
- Personal data compared: GDPR, CCPA/CPRA and PIPL
- Cross-border data transfers compared: EU, United States and China
- Cybersecurity duties compared: EU, United States and China
- Online platform duties compared: EU, United States and China
- Online consumer rights compared: EU and United States
- Product safety and market access compared: EU and China
- Climate and emissions reporting compared: United States and the EU
- Export controls compared: China and the EU market side
ExploreWorldAI is operated by Valkiv Ventures AB (Reg. no. 556995-1311), Kungsgatan 8, 111 43 Stockholm, Sweden. EU-hosted, with data processing assessed against the GDPR. Contact: hello@exploreworldai.com.
Machine-readable summaries for AI agents: /llms.txt and /llms-full.txt.