HIPAA focuses on healthcare organizations and how personal health information is used in the US. GDPR, on the other hand, is broader legislation that supervises any organization handling personally identifiable information (PII) of an EU or UK citizen.

GDPR governs the use of and applies to all personal data of persons within its scope. In contrast, HIPAA’s narrower scope only applies to HIPAA-protected health information (PHI).

GDPR sets compliance standards for all entities within its scope. HIPAA sets standards for covered entities and business associates (BAA).

Regarding consent, GDPR requires explicit consent for processing personal health data (which falls under sensitive data). However, the data may be processed without consent if it meets one of the processing conditions in Article 9 of GDPR and a legal basis applies.

A HIPAA authorization is consent obtained from an individual that permits a covered entity or business associate to use or disclose that individual’s protected health information to someone else for a purpose otherwise not permitted by the HIPAA Privacy Rule. HIPAA allows disclosure of some PHI for 12 national priority purposes, including treatment purposes, without the individual’s consent (authorization).

We’ve written some posts to help you understand GDPR and HIPAA requirements and how they might apply to you:

Is Google Analytics GDPR-compliant?

Is Google Analytics illegal in the EU?

How PHI and PII impact your HIPAA compliance and marketing

Is your analytics project HIPAA-compliant?


  • 25 years of digital analytics with Brian Clifton: Being data-informed, not just data-driven

    As organizations increasingly rely on data in their business decisions, the challenges of ensuring data accuracy, consistency, and ethical collection are becoming more and more important. Along with understanding the audience’s needs, supporting collaboration between teams, and securing privacy compliance, these challenges have evolved into data collection and analytics priorities.  Let’s dive into the third…

    Read more

  • Piwik PRO is HIPAA certified

    Piwik PRO is officially HIPAA certified!

    At Piwik PRO, ensuring the highest level of security and data protection has always been our top priority. Developing privacy-friendly analytics is just one aspect of our commitment. We validate our approach by obtaining external certifications from independent organizations. As such, we are pleased to announce that a HIPAA (Health Insurance Portability and Accountability Act)…

    Read more