Compliance libraryHIPAA

HIPAA for European healthtech: your GDPR work already covers half of it

US healthcare is the largest health market on earth, and no hospital, insurer or pharmacy will sign with a vendor who cannot execute a BAA. If you are GDPR compliant, you are already most of the way — here is exactly what is missing.

KoComply Research·Jul 2026·15 min read
Key takeaways
  • HIPAA applies to anyone handling PHI on behalf of a US covered entity, regardless of where the company is based.
  • No signed Business Associate Agreement means no contract — this is the hard gate for European vendors.
  • GDPR covers roughly half to two-thirds of HIPAA's expectations; the gaps are BAAs, PHI-specific safeguards, de-identification, and HHS breach mechanics.
  • CE marking and DiGA status do not substitute for HIPAA — they answer a different regulator.

The gate at the edge of the US market

European digital health is in strong shape. London anchors AI diagnostics and genomics, Berlin leads prescription digital therapeutics, Stockholm exports remote care models, Dublin sits next to the European headquarters of US pharma, and Zurich and Basel hold the precision-medicine corridor.

Then comes US expansion, and a procurement gate that has nothing to do with product quality: a US hospital, insurer or pharmacy cannot hand protected health information to a vendor who will not sign a Business Associate Agreement and evidence HIPAA compliance. Not "prefers not to" — cannot, without accepting regulatory exposure themselves.

It applies equally to European vendors. HIPAA follows the data and the relationship, not the office address.

$4.3T
US healthcare market
50-60%
Of HIPAA already covered by GDPR work
60 days
HHS breach notification deadline

What HIPAA asks for, in plain terms

HIPAA is not one document. The parts that matter for a technology vendor are the Privacy Rule, the Security Rule, the Breach Notification Rule and the Omnibus Rule that made business associates directly liable.

  • Administrative safeguards: a documented risk analysis, a risk management plan, workforce training, sanctions, and a named security official.
  • Physical safeguards: facility access, workstation use and device and media disposal controls — including for a distributed European team.
  • Technical safeguards: access control, unique user identification, audit controls, integrity controls, and transmission security. Encryption is "addressable", which means you either implement it or document a defensible reason not to. In practice, implement it.
  • Organisational requirements: Business Associate Agreements with your customers, and equivalent downstream agreements with every subcontractor that touches PHI.
  • The minimum necessary standard: access and disclosure limited to what the task actually requires — an access-model requirement, not a policy sentence.

GDPR to HIPAA: what carries over, and what does not

RequirementGDPR positionHIPAA positionYour gap
Encryption in transit and at restExpected under Article 32Addressable — implement or justifyMinimal: align standards and document
Access control and least privilegeRequiredRequired, plus unique user IDsMinimal: map roles, prove uniqueness
Business Associate AgreementNo equivalentMandatory before any PHI flowsMust implement from scratch
PHI-specific safeguardsPartial via special-category dataComprehensive and prescriptiveExtend existing controls
Minimum necessaryData minimisation principleSpecific enforceable ruleAdapt policies and access model
Breach notification72 hours to the supervisory authority60 days to HHS and individuals, media over 500Add a parallel HHS process
De-identificationAnonymisation, principle-basedSafe Harbor (18 identifiers) or Expert DeterminationMust implement a defined method
Physical safeguardsGeneral requirementSpecific facility and device controlsDocument formally
Audit loggingImplied by accountabilityExplicit audit controls requirementProve retention and review

The pattern is consistent: your technical posture mostly transfers, your documentation mostly transfers, and the genuinely new work is contractual (BAAs), definitional (PHI and de-identification) and procedural (HHS breach mechanics).

The four things that actually block European vendors

  • No BAA capability. Until you can sign one and mean it, no US covered entity can onboard you. Downstream subcontractor agreements are part of the same obligation.
  • PHI data flows that were never mapped as PHI. Your GDPR record of processing describes personal data; a US reviewer wants to see where the eighteen HIPAA identifiers live, who reaches them and for how long they are retained.
  • De-identification done by intuition. "We stripped the names" is not Safe Harbor. Either meet all eighteen identifier requirements or hold an expert determination on file.
  • A breach process that only knows about the 72-hour DPA clock. You need a documented HHS path, individual notification, the 500-record media threshold, and state-level requirements layered on top.

Things European teams commonly get wrong

  • Assuming CE marking or DiGA listing counts. They answer medical-device and reimbursement regulators, not HIPAA.
  • Assuming a US entity is required. It is not — HIPAA follows PHI wherever it is processed. A US point of contact for regulatory correspondence is practical, not statutory.
  • Assuming EU data residency solves it. Hosting location does not change your obligations; it does change the transfer analysis you owe under GDPR in the other direction.
  • Treating HIPAA as a certification. There is no HIPAA certificate. What buyers accept is a current risk analysis, documented safeguards, training records, a signed BAA and, increasingly, a SOC 2 report mapped to HIPAA safeguards.
  • Letting engineering support access production PHI ad hoc. This is the most common finding in vendor security reviews and the easiest to fix before anyone asks.

A three-to-four week bridge

The compressible part is the documentation and mapping work — which is precisely the work that traditionally consumes three to six months of consultancy time at €40K-€100K. The parts that stay on your calendar are engineering remediation, if your access model needs real change, and your customers' own review cycles.

WeekFocusDeliverable
1GDPR-to-HIPAA gap analysis and PHI data-flow mappingPrioritised remediation roadmap
2BAA templates, HIPAA policy set, PHI access controls and audit loggingSignable BAA and approved policy pack
3-4Workforce training, breach procedures, continuous monitoringEvidence package for US client review

Running GDPR and HIPAA together

For European healthtech this is the steady state, not a transition. You will hold both indefinitely: GDPR for your European patients and clinicians, HIPAA for your US covered entities.

Run one control environment with two evidence views. Encryption, access control, logging, vendor management and incident response are shared; the framework-specific layers — lawful basis, DSARs and transfer mechanisms on one side, BAAs, minimum necessary and HHS notification on the other — sit above them. Maintaining two parallel programs is how small compliance teams burn out and how evidence starts to contradict itself.

Frequently asked

Can we fast-track HIPAA using our GDPR work?

Yes. Roughly half to two-thirds of the substantive expectations overlap. The efficient approach is to map existing controls to HIPAA safeguards and only build what genuinely has no equivalent — chiefly BAAs, de-identification method and HHS breach procedures.

Do we need a US entity or US hosting?

Neither is required by HIPAA. A US-based point of contact for breach and regulatory correspondence is sensible, and some buyers will ask for US hosting contractually — that is a commercial term, not a statutory one.

Is there a HIPAA certificate we can show buyers?

No. HHS certifies nobody. Buyers accept a current risk analysis, documented safeguards, training evidence, a signed BAA and often an independent report such as SOC 2 mapped to HIPAA safeguards.

What about digital therapeutics and SaMD?

FDA clearance and HIPAA are separate, parallel requirements. Clearance addresses the device; HIPAA addresses the health information the device handles. You need both for US market access.

Who signs the BAA on our side?

Whoever can commit the company contractually — usually a founder or general counsel. What matters more is that the obligations inside it are actually operable: breach timelines, subcontractor flow-down and return or destruction of PHI at termination.

The short version

European healthtech does not start HIPAA from zero. GDPR has already forced you to know your data, control access, encrypt sensibly and respond to incidents. What is missing is a contract you can sign, a definition of PHI you can defend, a de-identification method that meets the standard, and a breach path that ends at HHS rather than a DPA.

Put agents on the mapping, the drafting and the evidence, and the bridge from GDPR to HIPAA becomes a few weeks of focused work instead of two quarters of consultancy — with your team spending its attention on the clinical product rather than the paperwork around it.

Let an agent do this part for you

Free forever on Questionnaire, Infra Health and Codebase Health. Upgrade when you're ready for the full program.

Start free

Keep reading

Put an agent on this instead
Free forever on Questionnaire, Infra Health and Codebase Health.