Healthcare Data Compliance: HIPAA, GDPR, and APAC Regulations Compared
Healthcare data compliance is not a single law. It is a layered obligation, a combination of the jurisdiction where your organization operates, where your patients or members reside, and where your data is stored or processed.
For healthcare technology teams building products that cross borders, this matters immediately. An EHR platform deployed in Vietnam must follow Vietnamese Ministry of Health regulations. If it processes data belonging to EU residents, GDPR applies on top of that. If the clinical team managing the system includes US-based covered entities, HIPAA adds a third layer. The regulations overlap in purpose but differ sharply in scope, consent logic, breach timelines, and penalties.
This article compares HIPAA, GDPR, and the key APAC health data frameworks (Thailand PDPA, China PIPL, and Vietnam Circular 24) across the dimensions that matter most for system architecture and compliance program design. For a broader view of the technical decisions involved, see Healthcare Software Development: What to Build and What to Buy.

Healthcare data compliance spans HIPAA, GDPR, and APAC-specific frameworks — each with distinct scope, consent rules, and penalties
1. What is healthcare data compliance?
Healthcare data compliance refers to the set of legal, regulatory, and technical obligations governing how organizations collect, store, use, share, and protect health-related personal information.
The field divides into three operational domains:
Privacy rules
Who can access patient data, under what conditions, and with what consent? HIPAA’s Privacy Rule and GDPR Article 9 (special categories) are the two most widely referenced frameworks.
Security rules
Technical, physical, and administrative safeguards that protect data in storage and transit. HIPAA’s Security Rule specifies required and addressable implementation specifications; ISO 27001 and SOC 2 are commonly used to satisfy security obligations under GDPR and APAC frameworks.
Breach notification rules
Timelines and thresholds for reporting incidents to regulators and affected individuals. These vary significantly: GDPR requires 72 hours to the supervisory authority; HIPAA allows 60 days; China’s PIPL requires notification to the CAC for severe incidents, with specific timelines defined in implementing regulations (organizations should verify current requirements with China-qualified counsel).
For software vendors and healthcare IT providers, compliance is both a contractual requirement (customers demand it) and a market access condition (regulatory approval is required in several APAC markets before a health data platform can operate).
2. Is HIPAA the same as GDPR?
HIPAA and GDPR are not the same. They share the goal of protecting health-related personal information but differ fundamentally in geographic scope, who they cover, how consent works, and the severity of penalties.
Geographic scope
HIPAA applies only to US-based covered entities (healthcare providers, health plans, and healthcare clearinghouses) and their business associates. An organization outside the US is not subject to HIPAA unless it contracts directly with a US covered entity as a business associate.
GDPR applies to any organization that processes personal data of EU residents, regardless of where that organization is based. A Vietnam-based telehealth platform with EU patients is subject to GDPR. A US hospital is not subject to GDPR unless it actively offers services to EU residents.
Data scope
HIPAA protects Protected Health Information (PHI): individually identifiable health information in 18 specific categories, including names, geographic identifiers, dates related to care, phone numbers, and medical record numbers. Financial information is covered only when linked to health data.
GDPR covers all personal data, with health data classified as a special category requiring a higher standard of justification for processing. GDPR’s scope is broader: it includes genetic data, biometric identifiers, and any information that could be used to infer health status.
Consent and legal basis
HIPAA permits disclosure without patient authorization for treatment, payment, and healthcare operations. Authorization is required for uses outside those categories.
GDPR requires an explicit lawful basis for every processing activity. For health data, the lawful basis is usually explicit consent or a statutory exemption (such as public health or research). There is no equivalent of HIPAA’s treatment-payment-operations carve-out; each purpose must be documented separately.
Penalties
HIPAA penalties are tiered by culpability: from USD 141 per violation (unknowing) to USD 71,162 per violation (willful neglect, uncorrected), with annual caps of USD 1.9M per violation category. The HHS Office for Civil Rights enforces HIPAA.
GDPR penalties are significantly higher: up to EUR 20M or 4% of global annual turnover, whichever is greater, for the most serious violations. Data protection authorities across EU member states enforce GDPR, and enforcement has been active since 2018.

HIPAA and GDPR share the goal of protecting health data but differ sharply in geographic scope, consent logic, and penalty thresholds
3. Is HIPAA only for the USA?
Yes. HIPAA is a US federal law that applies exclusively to US-based covered entities and their business associates. It does not apply directly to organizations in other countries unless those organizations contract with US covered entities and become business associates under the Act.
This is a common point of confusion for APAC healthcare technology teams. The practical implication: if you are building or operating a health data platform in Vietnam, Thailand, Singapore, or elsewhere in Asia, HIPAA compliance is not a regulatory requirement unless you are providing services to US-covered entities as part of a contractual arrangement.
What does apply in APAC:
| Country / Market | Framework | Health data classification |
| Thailand | Personal Data Protection Act (PDPA), in force June 2022 | Sensitive data requires explicit consent |
| China | Personal Information Protection Law (PIPL), effective November 2021 | Sensitive personal information; data localization requirements |
| Vietnam | Circular 24/2020/TT-BYT (Ministry of Health) + Decree 13/2023/ND-CP | Electronic health records; patient consent required for most disclosures |
| Singapore | Personal Data Protection Act (PDPA) + National Electronic Health Record framework | Health-specific rules under the NEHR framework |
| India | Digital Personal Data Protection Act (DPDPA) 2023 + Health Data Management Policy (ABDM) | Health data covered; sector-specific rules for digital health platforms |
For organizations operating across markets, the practical approach is to design to the most demanding applicable framework (typically GDPR for cross-border EU exposure or PIPL for China operations) and document jurisdiction-specific variations as overlays rather than rebuilding compliance architecture per country.
4. How do APAC health data regulations compare to HIPAA and GDPR?
The comparison table below maps the key compliance dimensions across the five frameworks most relevant to healthcare technology teams operating in or exporting to the US, EU, and Asia-Pacific:
| Factor | HIPAA (US) | GDPR (EU) | PDPA (Thailand) | PIPL (China) | Vietnam Circular 24 |
| Who it covers | US-based covered entities + business associates | Any org processing EU residents’ data, wherever based | Controllers/processors handling Thai residents’ data | Entities processing Chinese citizens’ personal info | Healthcare providers operating in Vietnam |
| Data scope | PHI: 18 identifiers | Personal data, including health, as a special category | Personal data; health data = sensitive category | Sensitive PI including health, biometric, and medical records | Patient health records, diagnoses, prescriptions |
| Consent model | Authorization for disclosure; treatment, payment, and operations exempt | Explicit consent or statutory basis required for health data | Explicit consent; limited treatment exemptions | Explicit consent; national security and public health exemptions | Patient written consent; disclosure rules per Ministry of Health |
| Max penalty | Up to USD 1.9M per violation category per year | Up to EUR 20M or 4% global annual turnover | Up to THB 5M; criminal liability for directors | Up to CNY 50M or 5% prior-year revenue | Administrative sanctions: MoH license suspension |
| Breach notice | 60 days to HHS; media notice if 500+ affected in a state | 72 hours to supervisory authority; without undue delay to subjects | 72 hours to PDPC if high risk to data subjects | Notification to CAC for severe incidents; verify timelines with China counsel | Notify MoH per Circular 24 guidance; patient notice required |
| Cross-border transfer | No explicit restriction; BAA required | Adequacy decision, SCCs, or BCRs required | PDPC approval or SCCs equivalent required | Security assessment + CAC approval for sensitive data | In-country storage guidance; cross-border transfers subject to MoH authorization |
GDPR and PIPL are the most expansive in scope and the most aggressive in penalties. HIPAA is narrower in who it covers but well-enforced. PDPA and Vietnam Circular 24 follow the GDPR consent model in spirit but are enforced through regulatory and licensing mechanisms rather than large fines. For multi-jurisdictional deployments, data residency and cross-border transfer rules are the highest-friction requirement. Both PIPL (China) and Vietnam Circular 24 impose data localization for health records; GDPR imposes transfer restrictions that require contractual safeguards such as Standard Contractual Clauses.
5. What are the most common HIPAA violations?
The five HIPAA violation categories that generate the largest volume of enforcement actions and financial settlements are impermissible disclosure, lack of safeguards for PHI, patient access failures, lack of Business Associate Agreements, and failure to conduct a security risk analysis.
Impermissible disclosure
Sharing PHI with individuals or entities not authorized to receive it. This includes sending records to the wrong patient, disclosing information to family members without authorization, and breaches through unsecured digital channels. This category accounts for the majority of reported HIPAA incidents.
Lack of PHI safeguards
Failure to implement technical controls (encryption, access controls, audit logs) or physical controls (workstation policies, device management) that prevent unauthorized access. Unsecured portable devices remain one of the most frequently cited issues.
Patient right of access failures
The 2021 HIPAA Right of Access Initiative focused specifically on covered entities failing to provide patients with timely access to their own records. OCR has issued settlements in this category ranging from USD 3,500 to USD 240,000.
Missing Business Associate Agreements (BAAs)
Any vendor that creates, receives, maintains, or transmits PHI on behalf of a covered entity must have a signed BAA. Software vendors providing EHR, cloud storage, or analytics services to US healthcare organizations need to be aware of this requirement.
Failure to conduct a security risk analysis
HIPAA’s Security Rule requires covered entities to conduct a thorough assessment of risks to PHI confidentiality, integrity, and availability. Failure to complete and document this analysis regularly is one of the most common findings in OCR investigations.
6. Does GDPR apply to healthcare?
Yes. GDPR applies to healthcare organizations in the EU and to any organization outside the EU that processes personal data of EU residents, including health data. Health data is classified as a special category under GDPR Article 9 and carries stricter processing requirements than ordinary personal data.
For healthcare technology vendors, GDPR application depends on two questions: where the data subjects are located and whether the vendor actively targets or monitors EU residents. A vendor that provides services to EU hospitals, accepts EU patients in a digital health platform, or processes EHR data for EU-based clinical teams is subject to GDPR regardless of where the vendor is incorporated.
GDPR requirements that affect healthcare system architecture:
| GDPR requirement | Healthcare architecture implication |
| Data minimization | Collection schemas must be limited to what is necessary for the specified purpose. Systems that aggregate patient data for analytics must demonstrate collection is minimized. |
| Purpose limitation | Data collected for primary care cannot be repurposed for insurance underwriting without a new legal basis. Affects how health platforms can monetize secondary data uses. |
| Right to erasure | Systems need an erasure workflow that can remove personal identifiers from structured and unstructured records, including archived data. |
| Data Protection Impact Assessment (DPIA) | Required for large-scale processing of health data and systematic use of biometric data. AI diagnostic tools and population health analytics typically require a DPIA. |
7. What does the HIPAA Security Rule require?
The HIPAA Security Rule establishes the standards covered entities and business associates must meet to protect electronic Protected Health Information (ePHI). It divides requirements into three safeguard categories: administrative, physical, and technical.
Administrative safeguards
Administrative safeguards are the policies, procedures, and processes that govern how an organization manages and protects ePHI. They are the largest category in the Security Rule. Key requirements include:
- Security risk analysis: A required (not addressable) assessment of risks to ePHI confidentiality, integrity, and availability. Must be documented and reviewed periodically.
- Security management process: Documented policies and procedures to prevent, detect, contain, and correct security violations.
- Workforce training: All workforce members who work with ePHI must receive documented security awareness training.
- Contingency plan: Data backup, disaster recovery, and emergency mode operation plans to ensure ePHI availability during and after an emergency.
- Business Associate Agreements: Contracts with every vendor that handles ePHI, specifying permitted uses and the vendor’s security obligations.
Physical and technical safeguards
Physical safeguards cover facility access controls, workstation policies, and device and media controls. Technical safeguards cover access controls (unique user identification, automatic logoff), audit controls (hardware, software, and procedural mechanisms that record ePHI activity), integrity controls, and transmission security (encryption in transit).
HIPAA uses a required vs. addressable specification distinction for technical safeguards. Required specifications must be implemented as stated. Addressable specifications must be implemented if reasonable and appropriate; if not, the covered entity must document why and implement an equivalent alternative. Encryption of ePHI at rest is addressable, not required, but OCR has consistently found its absence to be evidence of inadequate safeguards in breach investigations.

The HIPAA Security Rule divides safeguards into three categories: administrative, physical, and technical each with required and addressable specifications
8. How does AI change healthcare data compliance obligations?
AI systems in healthcare create compliance obligations that existing frameworks were not designed to address directly: model training on historical patient data, algorithmic decision-making that affects diagnosis or treatment, and real-time inference on live patient records each raise distinct legal questions.
The three areas where AI most often creates compliance complexity:
Training data use
Training an AI model on historical PHI requires a legal basis under HIPAA (typically the research exception with IRB approval or a de-identification process meeting the Safe Harbor or Expert Determination standard) and under GDPR (typically research or explicit consent for each data subject). De-identified data that has been re-identified through model outputs is a significant enforcement risk.
Algorithmic transparency
GDPR Article 22 restricts decisions based solely on automated processing that produce significant effects on individuals. Healthcare AI applications with diagnostic or treatment implications generally need a documented human review step and an explanation mechanism for adverse outputs. What constitutes “meaningful human review” is still being interpreted by supervisory authorities.
Vendor risk in AI pipelines
When AI inference is performed by a third-party model provider, the data processing agreement (GDPR) or Business Associate Agreement (HIPAA) must cover the model provider’s access to patient data, including data sent in prompts and whether that data is used for model training.
Two implementation patterns from healthcare AI projects illustrate this in practice. In a mental health chatbot deployment, session data was separated from identifiable records so the AI inference layer operated on anonymized inputs. In an AI document intelligence system for a US healthcare client, clinical records passed through a de-identification pipeline before entering the AI extraction layer. Both patterns address the same architectural question: how to use AI on patient data without creating a new category of PHI exposure at the model interface.






