A US medical school records a European exchange student’s OSCE. That school is not choosing between GDPR and HIPAA. It answers to both. Complying with one does not substitute for the other. GDPR protects personal data belonging to any EU or UK resident. It does not matter where the processing organization is based. HIPAA protects health information handled by a US covered entity. It does not matter where the patient or student lives. A single recorded assessment can trigger both at once.
What Is GDPR Called in the USA?
There is no direct US equivalent. HIPAA covers health information specifically, not personal data in general. The United States has no single federal privacy law matching GDPR’s scope. State laws fill part of the gap. California, Colorado, and Virginia now regulate personal data broadly. Coverage still varies state by state. GDPR applies uniformly across the whole EU instead.
What Are GDPR, HIPAA, and CCPA?
GDPR is the European Union’s general data protection law. It covers all personal data belonging to EU and UK residents. HIPAA is a US federal law. It covers protected health information handled by covered entities and their business associates. The California Consumer Privacy Act, or CCPA, sits between the two. It is a US state law, like HIPAA in jurisdiction. It covers personal data broadly, like GDPR in scope. An institution recording assessments across US and EU campuses can answer to all three at once.
Does GDPR Apply to US Hospitals and Medical Schools?
Yes, whenever they process the personal data of someone in the EU or UK. It does not matter where the institution itself is based. Picture a US medical school with an EU exchange student. Picture an EU-based external examiner reviewing recordings. Picture an EU research partner processing that data. Each one puts the school’s recordings under GDPR. HIPAA compliance does not exempt a US institution from this. The two obligations run in parallel. Neither substitutes for the other.
What Are the 7 GDPR Principles?
GDPR Article 5 sets out seven principles for processing personal data. They are lawfulness, fairness, and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; and accountability. HIPAA does not organize its rules around an equivalent set. Its Privacy Rule defines permitted uses and disclosures directly instead. It has no parallel minimization-and-accountability framework layered on top.
Where GDPR and HIPAA Actually Differ
The two frameworks diverge most sharply on scope, individual rights, and penalties.
GDPR protects any data that could identify a living person. HIPAA protects health information specifically. HIPAA also only applies when a covered entity or business associate handles that information. GDPR grants a right to erasure. It also grants a right to data portability. HIPAA provides neither right at all. On penalties, GDPR authorizes fines up to 20 million euros or 4 percent of global annual turnover, whichever is higher. HIPAA’s civil penalties run through a tiered structure instead. The HITECH Act introduced four culpability tiers in 2009. The combined annual maximum is 1.5 million dollars per identical violated provision. That ceiling sits several orders of magnitude below GDPR’s maximum for a large organization.
Where They Overlap
Both frameworks require breach notification, though on different timelines. GDPR gives supervisory authorities 72 hours. HIPAA’s Breach Notification Rule allows 60 days instead. Both require a named accountability role. GDPR requires a Data Protection Officer. HIPAA requires a Privacy Officer and a Security Officer, covered in Videolab’s HIPAA FAQ. Both also require appropriate safeguards, though they specify this differently. GDPR’s Article 32 leaves the standard risk-based and open-ended. HIPAA’s Security Rule sets out defined safeguard categories instead: administrative, physical, and technical.
Running a Program Under Both
The practical fix is not two separate compliance programs. Build to GDPR’s stricter baseline first. A system meeting GDPR’s minimization, consent, and erasure requirements satisfies most of HIPAA’s requirements as a byproduct. Then layer on the HIPAA-specific elements GDPR does not cover. Add the Security Rule’s defined safeguard categories. Add the Breach Notification Rule’s 60-day timeline. Add a signed business associate agreement with any vendor handling protected health information. For the video-specific version of this, see Videolab’s guide to GDPR compliant video recording. It covers the recording-specific requirements this page does not.
