Health data compared: GDPR, HIPAA and PIPL

How is health data treated in the EU, the United States and China?

Health records are a special category everywhere, but the boundary differs. The GDPR follows the data. HIPAA follows the covered entity. PIPL follows the sensitive category and asks for separate consent.

Rows read against the registers 2026-08-26.

European Union

Open the European Union register

United States

Open the United States register

China

Open the China register

What they ask for in common

Where they differ

What companies usually do first

This page describes what the registers say and what is common practice. It is a reading of published sources, not legal advice, and it is not a compliance verdict.

Does this apply to us

Related comparisons

ExploreWorldAI is operated by Valkiv Ventures AB (Reg. no. 556995-1311), Kungsgatan 8, 111 43 Stockholm, Sweden. EU-hosted, with data processing assessed against the GDPR. Contact: hello@exploreworldai.com.

Machine-readable summaries for AI agents: /llms.txt and /llms-full.txt.