GDPR Compare to HIPAA

How Does GDPR Compare to HIPAA?

The General Data Protection Regulation (GDPR) of the EU and the Health Insurance Portability and Accountability Act (HIPAA) of the United States are two government acts that protect personal and sensitive data. These two pieces of regulative guidelines have contributed a considerable amount to the global data security field. GDPR vs HIPAA is not a choice between two standards. If your data touches EU residents and US patients, both apply. Continue reading to find out how these two protections differ, and what each has to offer.

What is GDPR?

The European Parliament, the European Commission and the Council of the European Union enacted the GDPR on April 27, 2016, and it took effect on May 25, 2018. According to the EU GDPR website, the GDPR replaced an earlier data protection act. It consolidates data privacy law across Europe and protects every EU citizen. It also reframes how companies approach data collection. According to its website, most observers call the GDPR the most significant shift in data privacy regulation in twenty years.

The GDPR comprises 91 articles, which cover everything from consent to cross-border transfers. So here are some of the benefits of this new set of provisions:

  • You need individual consent before collecting or processing any data.
  • Individuals get prompt notice if their data is breached.
  • Anonymize all data and keep it that way.
  • International data transfers will be managed more securely.
  • Some companies will be required to appoint a data protection officer (DPO) to streamline and more seriously protect client data.
  • Any company that provides a service or product to residents of the EU is required to comply with the GDPR.
  • Companies that do not comply with the GDPR regulations will be subject to hefty fines.

What is HIPAA?

Congress passed the Health Insurance Portability and Accountability Act in 1996, and it still sets the standard for medical data. The law protects sensitive medical information while it moves electronically. It started as a way to help patients keep insurance through a job loss or change. HIPAA also cuts medical costs, because administrators can use electronic records. Those are more secure and more efficient than paper. The United States Department of Health and Human Services regulates and enforces HIPAA.

HITECH, the Health Information Technology for Economic and Clinical Health Act, is part of the 2009 ARRA. The HITECH act broadened HIPAA’s scope and expanded its privacy and security protections. It also increased the legal actions available for non-compliance. Systems under HIPAA must notify patients of any data breach. Violations carry substantial fines and penalties. HIPAA protects the following:

  • Patient identity and social security number
  • Patient diagnosis and condition
  • Record of care or treatment provided to a patient
  • Payment information that could potentially be used to identify the patient

Related reading

GDPR vs HIPAA: Understanding Both

GDPR vs HIPAA comes down to two distinct sets of regulations. Each has raised the bar on information security and privacy. Data centers keep multiplying worldwide. So more companies will have to navigate these regulations and treat data protection as a priority.  Building a server system that will carry sensitive data in the US or Europe? Contact Volico today. We can help you design a system that meets the stricter privacy standards now spreading worldwide.

Discover how Volico can help you with your Compliance & Security needs.

•  Call: (305) 735-8098
•  Chat with a member of our team to discuss which solution best fits your needs.

Share this blog

About cookies on Volico.com

Volico Data Centers use cookies to collect and analyse information on site performance and usage. This site uses essential cookies which are required for functionality.  More detail is available in our privacy policy. Learn more