{"id":2631,"date":"2020-07-23T08:08:44","date_gmt":"2020-07-23T07:08:44","guid":{"rendered":"https:\/\/staging.techgdpr.com\/?p=2631"},"modified":"2024-12-30T14:10:02","modified_gmt":"2024-12-30T13:10:02","slug":"hipaa-the-gdpr-and-medtech","status":"publish","type":"post","link":"https:\/\/techgdpr.com\/blog\/hipaa-the-gdpr-and-medtech\/","title":{"rendered":"HIPAA, the GDPR and MedTech"},"content":{"rendered":"\n<p><span style=\"font-weight: 400;\">There are different regulations on how medical data can be processed and stored in different nations. If your company operates in the MedTech sector in the Western world most likely you have at least heard of HIPAA or the GDPR. This article aims at analysing how both legislations relate to healthcare. The article is particularly useful for those looking to extend their business operations to the EU or US for the first time.&nbsp;<\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span style=\"font-weight: 400;\">What are HIPAA and the GDPR?<\/span><\/h2>\n\n\n\n<p><span style=\"font-weight: 400;\"><a href=\"https:\/\/www.hhs.gov\/hipaa\/index.html\">HIPAA<\/a> refers to the Health Insurance Portability and Accountability Act of 1996. HIPAA was enacted to specifically deal with how medical data are shared and processed. Unlike HIPAA <a href=\"https:\/\/gdpr.eu\/\">the GDPR<\/a> regulates any information which can lead to the identification of a living person whether it is health-related or not. The GDPR denotes health data as <\/span><span style=\"font-weight: 400;\">special categories of personal data, commonly referred to as sensitive data<\/span><span style=\"font-weight: 400;\">. This means that non-consensual processing of health-related data is strictly prohibited unless the processing purposes are related to medical diagnosing, preventative or occupational medicine, provision and management of health or social care or treatment, in accordance with a contract with a medical professional or based on Union or Member State law.&nbsp;<\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">The GDPR defines health data as <\/span><i><span style=\"font-weight: 400;\">personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his\/her health status<\/span><\/i><span style=\"font-weight: 400;\"> (GDPR Art.4). HIPAA denotes protected health information as any data uncovering an agent&#8217;s identity in respect to his or her past, future or present physical or mental condition, provision of and payment for the health treatment and services. Both definitions are similar, yet HIPAA also designates financial information of the recipient of the treatment as health data. The GDPR applies to all <\/span><b>organizations operating in the EU or offering goods or services to individuals located in the EU <\/b><span style=\"font-weight: 400;\">territorially no matter of the citizenship. HIPAA, on the other hand, applies to <\/span><b>special covered entities<\/b><span style=\"font-weight: 400;\"> within the US, those include healthcare providers, health care clearinghouses and health plan providers.<\/span><\/p>\n\n\n<div class=\"wp-block-image is-style-rounded\">\n<figure class=\"aligncenter size-large is-resized\"><img decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/12\/medtech-1024x683.webp\" alt=\"\" class=\"wp-image-10015\" style=\"width:790px;height:auto\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/12\/medtech-1024x683.webp 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/12\/medtech-300x200.webp 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/12\/medtech-768x512.webp 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/12\/medtech-1536x1024.webp 1536w, https:\/\/techgdpr.com\/wp-content\/uploads\/2024\/12\/medtech.webp 1600w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<h2 class=\"wp-block-heading\"><span style=\"font-weight: 400;\">The key differences&nbsp;<\/span><span style=\"color: inherit; font-size: 1.80556rem;\">betw<\/span><span style=\"color: inherit; font-size: 1.80556rem;\">een HIPAA and GDPR relevant to MedTech&nbsp;<\/span><\/h2>\n\n\n\n<p><span style=\"font-weight: 400;\">The principal difference between the regulations is obviously their <\/span><b>scope<\/b><span style=\"font-weight: 400;\">. As previously stated, the GDPR relates to all organizations processing all types of data relating to a person. Furthermore, the GDPR applies to a much broader range of entities. Even if the company is located in the US (or anywhere in the world) and processes data of subjects located in the EU, it must comply with the GDPR. Contrastingly HIPAA only applies to covered entities located in the US.&nbsp;<\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">The <\/span><b>right to be forgotten<\/b><span style=\"font-weight: 400;\"> is another aspect specific only to the GDPR. It stipulates that under certain conditions, such as the revoking of previously granted consent or when the data is no longer necessary, the data subject may exercise a right to request a free of charge erasure of his or her personal data. If a company relies on third-party cloud storage services, it should ensure that it is able to locate and erase the data when required. The GDPR is also stricter on <\/span><b>data breaches<\/b><span style=\"font-weight: 400;\">, it only grants 72 hours to report a data breach while HIPAA allows for up to 60 days to report a data breach if more than 500 individuals. If less than 500 people are affected, the data breach may be reported by the final day of reporting each year.&nbsp;<\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">The GDPR also introduced the notion of <\/span><b>privacy by design and by default.<\/b><span style=\"font-weight: 400;\"> The concept postulates that when developing new services related to MedTech, or any other sector, involving processing personal data, the company must always consider privacy. HIPAA makes no mention of such a framework for launching new services is present in HIPAA.&nbsp;<\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">Both regulations are compulsory and impose <\/span><b>fines<\/b><span style=\"font-weight: 400;\"> for non-compliance. <\/span><span style=\"font-weight: 400;\">HIPAA fines are mostly around $25.000 per violation, although in the worst case circumstances a company may be fined of up to $1.5 million per yea<\/span><span style=\"font-weight: 400;\">r. GDPR opens the door to potentially much larger maximum fines of <\/span><span style=\"font-weight: 400;\">up to 4% of the annual worldwide turnover.&nbsp;<\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Do HIPAA and GDPR overlap?<\/h2>\n\n\n\n<p><span style=\"font-weight: 400;\">There are some similarities and overlap between HIPAA and the GDPR which is good news for companies required to comply with both regulations. Firstly, both include obligations relating to individuals or entities handling data on behalf of covered entities who control the processing of data. Under HIPAA, those are distinguished as <\/span><b>business associates<\/b><span style=\"font-weight: 400;\"> and are required to sign a business associate agreement (BAA), this is similar to the <\/span><b>data processors <\/b><span style=\"font-weight: 400;\">under the GDPR.<\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">Secondly, HIPAA, as is the case with the GDPR, requires companies to ensure <\/span><b>safeguards<\/b><span style=\"font-weight: 400;\"> are in place to protect the data collected and stored from unauthorised access and disclosure. Article 32 of the GDPR specifically deals with the obligation of minimising risks of a security breach. Appropriate measures include <\/span><span style=\"font-weight: 400;\">pseudonymisation and encryption of data, maintenance of \u2018<\/span><i><span style=\"font-weight: 400;\">ongoing confidentiality, integrity, availability and resilience of processing systems and services\u2019<\/span><\/i> <span style=\"font-weight: 400;\">as well as \u2018<\/span><i><span style=\"font-weight: 400;\">ability to restore availability and access to data in the event of an accident<\/span><\/i><span style=\"font-weight: 400;\">\u2019. The same article prescribes regularly testing, assessing and evaluating the effectiveness of security measures in place. Furthermore, the entity subject of the GDPR shall ensure all personnel processing data on their behalf adheres to the code of conduct prescribed by the legislation and does not process data except on their instructions. <\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">Parallel obligations of the covered entities can be found under HIPAA\u2019s Security Rule. <\/span><span style=\"font-weight: 400;\">HIPAA also postulates confidentiality, integrity, and availability of protected health information in electronic form (ePHI). Likewise, covered entities must ensure potential security threats, or unlawful uses or disclosures of ePHI, are considered and addressed. HIPAA also obliges the covered entities to \u2018<\/span><i><span style=\"font-weight: 400;\">ensure compliance of the workforce<\/span><\/i><span style=\"font-weight: 400;\">\u2019.&nbsp;<\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">Both regulations call for <\/span><b>minimisation of data collection<\/b><span style=\"font-weight: 400;\"> and minimisation of data disclosure. Data should be disclosed for research purposes, judicial proceedings, public health interest and if required by law in both legislations.<\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">HIPAA and the GDPR grant data subjects analogous rights. In particular, with a few exceptions, such as access to psychotherapy notes, both regulations grant the data subject the <\/span><b>right to access <\/b><span style=\"font-weight: 400;\">and review a copy of the processed data. Moreover, if the information is inaccurate or incomplete, the data subject has a right to request an <\/span><b>amendment of the information<\/b><span style=\"font-weight: 400;\">. <\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">HIPAA and the GDPR grant data subjects a right to be informed of <\/span><i><span style=\"font-weight: 400;\">how <\/span><\/i><span style=\"font-weight: 400;\">and for <\/span><i><span style=\"font-weight: 400;\">what purpose <\/span><\/i><span style=\"font-weight: 400;\">their personal data is used and processed, this includes information regarding <\/span><span style=\"font-weight: 400;\">the <\/span><i><span style=\"font-weight: 400;\">recipients or categories of recipient to whom the personal data have been or will be disclosed<\/span><\/i><span style=\"font-weight: 400;\">. The <\/span><b>privacy notice<\/b><span style=\"font-weight: 400;\"> must include information on individual rights with respect to their personal information and how those rights may be exercised, and the covered entities obligations as well as the purpose of data usage and processing. Interestingly, both GDPR and HIPAA require the privacy notice to be written in clear and plain language.&nbsp;&nbsp;<\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span style=\"font-weight: 400;\">HIPAA and GDPR application <\/span><\/h2>\n\n\n\n<p><span style=\"font-weight: 400;\">Two global trends may be identified with regards to MedTech and data processing. On one hand, there is an evident explosion of consumer health data. Technological advancement has stimulated vast growths in consumer-generated health data. Those can be put to work through data analytics to extract powerful insights. Secondly, as life expectancy increases and larger sections of the population account for senior citizens, the market boom for healthcare is explained by a demand to further digitise and employ analytics to identify the most cost and health effective treatments and insurance plans.&nbsp;<\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">Beyond the similarities and differences outlined earlier, there is a fair amount of divergence in how the two frameworks are implemented. Consider an app developer seeking to re-use healthcare data to extract insights. Under the GDPR, this app developer handles a <\/span><i><span style=\"font-weight: 400;\">special category of data <\/span><\/i><span style=\"font-weight: 400;\">and this handling is subject to strict safeguards. However, in the US, the same app developer will not be is not a subject HIPAA and the GDPR -provided they do not process personal data from an EU data subject. That is because HIPAA postulates that only covered entities of healthcare providers and insurers or their business associates are subject to the legislation. In other words, medical data that is collected and processed in a hospital will be subject to HIPAA and considered PHI. <\/span><\/p>\n\n\n\n<p><span style=\"font-weight: 400;\">If an individual voluntarily provides his or her health information to a mobile app, which is not connected to healthcare activities of a covered entity (i.e. not a business associate of any covered entity), most likely this falls outside of HIPAAs\u2019 jurisdiction but the app developer remains subject to additional state or federal law. An example of such laws is the FTC Act that generally regulates commercial use of personal data or the Children Online Privacy Protection Act with regards to the use of children\u2019s data. Ultimately, this has an effect on how consent should be extracted to process the data, as well as on the appropriate security and organisational protection measures, regardless of HIPAA.&nbsp;<\/span><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><em>This article is for information purposes only, and does not constitute or replace legal advice. Seek professional support for any specific questions you may have.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>There are different regulations on how medical data can be processed and stored in different nations. If your company operates in the MedTech sector in the Western world most likely you have at least heard of HIPAA or the GDPR. This article aims at analysing how both legislations relate to healthcare. The article is particularly [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":2633,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[74,60,62],"tags":[35,19,72,70,71,50],"class_list":["post-2631","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-comparison","category-regulation","category-strategy","tag-gdpr","tag-gdpr-analysis","tag-hipaa","tag-medical-data","tag-medtech","tag-personal-data"],"acf":[],"featured_image_urls":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2020\/07\/Blog-GDPR-and-HIPAA-photo-1.jpg",7200,3580,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2020\/07\/Blog-GDPR-and-HIPAA-photo-1-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2020\/07\/Blog-GDPR-and-HIPAA-photo-1-300x149.jpg",300,149,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2020\/07\/Blog-GDPR-and-HIPAA-photo-1-768x382.jpg",640,318,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2020\/07\/Blog-GDPR-and-HIPAA-photo-1-1024x509.jpg",640,318,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2020\/07\/Blog-GDPR-and-HIPAA-photo-1.jpg",1536,764,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2020\/07\/Blog-GDPR-and-HIPAA-photo-1.jpg",2048,1018,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2020\/07\/Blog-GDPR-and-HIPAA-photo-1.jpg",200,99,false]},"post_excerpt_stackable":"<p>There are different regulations on how medical data can be processed and stored in different nations. If your company operates in the MedTech sector in the Western world most likely you have at least heard of HIPAA or the GDPR. This article aims at analysing how both legislations relate to healthcare. The article is particularly useful for those looking to extend their business operations to the EU or US for the first time.&nbsp; What are HIPAA and the GDPR? HIPAA refers to the Health Insurance Portability and Accountability Act of 1996. HIPAA was enacted to specifically deal with how medical&hellip;<\/p>\n","category_list":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/comparison\/\" rel=\"category tag\">Comparison<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/regulation\/\" rel=\"category tag\">Regulation<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/strategy\/\" rel=\"category tag\">Strategy<\/a>","author_info":{"name":"Olya A.","url":"https:\/\/techgdpr.com\/blog\/author\/olya\/"},"comments_num":"0 comments","featured_image_urls_v2":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2020\/07\/Blog-GDPR-and-HIPAA-photo-1.jpg",7200,3580,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2020\/07\/Blog-GDPR-and-HIPAA-photo-1-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2020\/07\/Blog-GDPR-and-HIPAA-photo-1-300x149.jpg",300,149,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2020\/07\/Blog-GDPR-and-HIPAA-photo-1-768x382.jpg",640,318,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2020\/07\/Blog-GDPR-and-HIPAA-photo-1-1024x509.jpg",640,318,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2020\/07\/Blog-GDPR-and-HIPAA-photo-1.jpg",1536,764,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2020\/07\/Blog-GDPR-and-HIPAA-photo-1.jpg",2048,1018,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2020\/07\/Blog-GDPR-and-HIPAA-photo-1.jpg",200,99,false]},"post_excerpt_stackable_v2":"<p>There are different regulations on how medical data can be processed and stored in different nations. If your company operates in the MedTech sector in the Western world most likely you have at least heard of HIPAA or the GDPR. This article aims at analysing how both legislations relate to healthcare. The article is particularly useful for those looking to extend their business operations to the EU or US for the first time.&nbsp; What are HIPAA and the GDPR? HIPAA refers to the Health Insurance Portability and Accountability Act of 1996. HIPAA was enacted to specifically deal with how medical&hellip;<\/p>\n","category_list_v2":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/comparison\/\" rel=\"category tag\">Comparison<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/regulation\/\" rel=\"category tag\">Regulation<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/strategy\/\" rel=\"category tag\">Strategy<\/a>","author_info_v2":{"name":"Olya A.","url":"https:\/\/techgdpr.com\/blog\/author\/olya\/"},"comments_num_v2":"0 comments","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>HIPAA, the GDPR and MedTech - TechGDPR<\/title>\n<meta name=\"description\" content=\"Discussing HIPAA and GDPR with examples. The key differences\u00a0between HIPAA and GDPR relevant to MedTech. Do the regulations overlap?\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/techgdpr.com\/blog\/hipaa-the-gdpr-and-medtech\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"HIPAA, the GDPR and MedTech - TechGDPR\" \/>\n<meta property=\"og:description\" content=\"Discussing HIPAA and GDPR with examples. The key differences\u00a0between HIPAA and GDPR relevant to MedTech. Do the regulations overlap?\" \/>\n<meta property=\"og:url\" content=\"https:\/\/techgdpr.com\/blog\/hipaa-the-gdpr-and-medtech\/\" \/>\n<meta property=\"og:site_name\" content=\"TechGDPR\" \/>\n<meta property=\"article:published_time\" content=\"2020-07-23T07:08:44+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-12-30T13:10:02+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2020\/07\/Blog-GDPR-and-HIPAA-photo-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"7200\" \/>\n\t<meta property=\"og:image:height\" content=\"3580\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Olya A.\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:site\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Olya A.\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/hipaa-the-gdpr-and-medtech\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/hipaa-the-gdpr-and-medtech\\\/\"},\"author\":{\"name\":\"Olya A.\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/0f85bcd08f8a89659255f94399bebf0c\"},\"headline\":\"HIPAA, the GDPR and MedTech\",\"datePublished\":\"2020-07-23T07:08:44+00:00\",\"dateModified\":\"2024-12-30T13:10:02+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/hipaa-the-gdpr-and-medtech\\\/\"},\"wordCount\":1514,\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/hipaa-the-gdpr-and-medtech\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2020\\\/07\\\/Blog-GDPR-and-HIPAA-photo-1.jpg\",\"keywords\":[\"GDPR\",\"GDPR Analysis\",\"HIPAA\",\"medical data\",\"MedTech\",\"personal data\"],\"articleSection\":[\"Comparison\",\"Regulation\",\"Strategy\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/hipaa-the-gdpr-and-medtech\\\/\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/hipaa-the-gdpr-and-medtech\\\/\",\"name\":\"HIPAA, the GDPR and MedTech - TechGDPR\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/hipaa-the-gdpr-and-medtech\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/hipaa-the-gdpr-and-medtech\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2020\\\/07\\\/Blog-GDPR-and-HIPAA-photo-1.jpg\",\"datePublished\":\"2020-07-23T07:08:44+00:00\",\"dateModified\":\"2024-12-30T13:10:02+00:00\",\"description\":\"Discussing HIPAA and GDPR with examples. The key differences\u00a0between HIPAA and GDPR relevant to MedTech. Do the regulations overlap?\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/hipaa-the-gdpr-and-medtech\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/techgdpr.com\\\/blog\\\/hipaa-the-gdpr-and-medtech\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/hipaa-the-gdpr-and-medtech\\\/#primaryimage\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2020\\\/07\\\/Blog-GDPR-and-HIPAA-photo-1.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2020\\\/07\\\/Blog-GDPR-and-HIPAA-photo-1.jpg\",\"width\":7200,\"height\":3580,\"caption\":\"Medic sitting next to a computer\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/hipaa-the-gdpr-and-medtech\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/techgdpr.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"HIPAA, the GDPR and MedTech\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"name\":\"TechGDPR\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/techgdpr.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\",\"name\":\"TechGDPR\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"contentUrl\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"width\":501,\"height\":334,\"caption\":\"TechGDPR\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/techgdpr\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/techgdpr\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/0f85bcd08f8a89659255f94399bebf0c\",\"name\":\"Olya A.\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1c4d11ac479bfebeefef05e8c9aaed8d6796cfafd6a9864a0574927c1c47d921?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1c4d11ac479bfebeefef05e8c9aaed8d6796cfafd6a9864a0574927c1c47d921?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1c4d11ac479bfebeefef05e8c9aaed8d6796cfafd6a9864a0574927c1c47d921?s=96&d=mm&r=g\",\"caption\":\"Olya A.\"},\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/author\\\/olya\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"HIPAA, the GDPR and MedTech - TechGDPR","description":"Discussing HIPAA and GDPR with examples. The key differences\u00a0between HIPAA and GDPR relevant to MedTech. Do the regulations overlap?","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/techgdpr.com\/blog\/hipaa-the-gdpr-and-medtech\/","og_locale":"en_US","og_type":"article","og_title":"HIPAA, the GDPR and MedTech - TechGDPR","og_description":"Discussing HIPAA and GDPR with examples. The key differences\u00a0between HIPAA and GDPR relevant to MedTech. Do the regulations overlap?","og_url":"https:\/\/techgdpr.com\/blog\/hipaa-the-gdpr-and-medtech\/","og_site_name":"TechGDPR","article_published_time":"2020-07-23T07:08:44+00:00","article_modified_time":"2024-12-30T13:10:02+00:00","og_image":[{"width":7200,"height":3580,"url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2020\/07\/Blog-GDPR-and-HIPAA-photo-1.jpg","type":"image\/jpeg"}],"author":"Olya A.","twitter_card":"summary_large_image","twitter_creator":"@techgdpr","twitter_site":"@techgdpr","twitter_misc":{"Written by":"Olya A.","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/techgdpr.com\/blog\/hipaa-the-gdpr-and-medtech\/#article","isPartOf":{"@id":"https:\/\/techgdpr.com\/blog\/hipaa-the-gdpr-and-medtech\/"},"author":{"name":"Olya A.","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/0f85bcd08f8a89659255f94399bebf0c"},"headline":"HIPAA, the GDPR and MedTech","datePublished":"2020-07-23T07:08:44+00:00","dateModified":"2024-12-30T13:10:02+00:00","mainEntityOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/hipaa-the-gdpr-and-medtech\/"},"wordCount":1514,"publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/hipaa-the-gdpr-and-medtech\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2020\/07\/Blog-GDPR-and-HIPAA-photo-1.jpg","keywords":["GDPR","GDPR Analysis","HIPAA","medical data","MedTech","personal data"],"articleSection":["Comparison","Regulation","Strategy"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/techgdpr.com\/blog\/hipaa-the-gdpr-and-medtech\/","url":"https:\/\/techgdpr.com\/blog\/hipaa-the-gdpr-and-medtech\/","name":"HIPAA, the GDPR and MedTech - TechGDPR","isPartOf":{"@id":"https:\/\/techgdpr.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/hipaa-the-gdpr-and-medtech\/#primaryimage"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/hipaa-the-gdpr-and-medtech\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2020\/07\/Blog-GDPR-and-HIPAA-photo-1.jpg","datePublished":"2020-07-23T07:08:44+00:00","dateModified":"2024-12-30T13:10:02+00:00","description":"Discussing HIPAA and GDPR with examples. The key differences\u00a0between HIPAA and GDPR relevant to MedTech. Do the regulations overlap?","breadcrumb":{"@id":"https:\/\/techgdpr.com\/blog\/hipaa-the-gdpr-and-medtech\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/techgdpr.com\/blog\/hipaa-the-gdpr-and-medtech\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/blog\/hipaa-the-gdpr-and-medtech\/#primaryimage","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2020\/07\/Blog-GDPR-and-HIPAA-photo-1.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2020\/07\/Blog-GDPR-and-HIPAA-photo-1.jpg","width":7200,"height":3580,"caption":"Medic sitting next to a computer"},{"@type":"BreadcrumbList","@id":"https:\/\/techgdpr.com\/blog\/hipaa-the-gdpr-and-medtech\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/techgdpr.com\/"},{"@type":"ListItem","position":2,"name":"HIPAA, the GDPR and MedTech"}]},{"@type":"WebSite","@id":"https:\/\/techgdpr.com\/#website","url":"https:\/\/techgdpr.com\/","name":"TechGDPR","description":"","publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/techgdpr.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/techgdpr.com\/#organization","name":"TechGDPR","url":"https:\/\/techgdpr.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/","url":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","contentUrl":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","width":501,"height":334,"caption":"TechGDPR"},"image":{"@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/techgdpr","https:\/\/www.linkedin.com\/company\/techgdpr"]},{"@type":"Person","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/0f85bcd08f8a89659255f94399bebf0c","name":"Olya A.","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1c4d11ac479bfebeefef05e8c9aaed8d6796cfafd6a9864a0574927c1c47d921?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1c4d11ac479bfebeefef05e8c9aaed8d6796cfafd6a9864a0574927c1c47d921?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1c4d11ac479bfebeefef05e8c9aaed8d6796cfafd6a9864a0574927c1c47d921?s=96&d=mm&r=g","caption":"Olya A."},"url":"https:\/\/techgdpr.com\/blog\/author\/olya\/"}]}},"_links":{"self":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/2631","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/comments?post=2631"}],"version-history":[{"count":12,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/2631\/revisions"}],"predecessor-version":[{"id":10017,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/2631\/revisions\/10017"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media\/2633"}],"wp:attachment":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media?parent=2631"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/categories?post=2631"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/tags?post=2631"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}