A telehealth startup serving patients in New York, Berlin, and Bengaluru is not dealing with one privacy problem in three markets. It is dealing with three genuinely different laws that happen to overlap on the same record. HIPAA, GDPR, and India's DPDP Act share a goal — protect people's data — but they were built on different foundations, regulate different things, and impose different duties. Treat them as three flavours of the same rule and you will build a programme that is fully compliant with none of them. Understand where they diverge and you can build one strong core and bolt on the deltas each law demands.
Three Laws, Three Logics
The most important difference isn't in the details — it's in the design. Each law answers a different founding question, and that shapes everything downstream.
HIPAA is sectoral. It asks: is this health information, held by a healthcare provider, plan, clearinghouse, or one of their vendors? If yes, a specific set of rules applies; if no, HIPAA is silent. It regulates a slice of the economy, deeply. GDPR is omnibus. It asks: is this personal data of someone in the EU? If yes, it applies — to a hospital, a bank, or a bakery alike — and health data simply gets extra protection as a special category. India's DPDP Act is also omnibus but built around consent: it asks whether you are processing the digital personal data of an individual, and centres the framework on the person's agreement to that processing.
Those three questions — is it health data in a health context, is it any personal data of an EU person, is it digital personal data being processed with consent — are why the same patient record lands in three different regimes with three different sets of obligations.
What Each One Governs
Start with the plain facts of each law: where it applies, what it protects, and who it binds.
| Law | Region | What it protects | Who it binds |
|---|---|---|---|
| HIPAA | United States | Protected health information (PHI) in a healthcare context | Covered entities & business associates |
| GDPR | EU / EEA (and beyond, extraterritorially) | All personal data; health data as a special category | Controllers & processors |
| DPDP Act | India (and processing offering goods/services in India) | All digital personal data | Data fiduciaries & processors |
Notice the role vocabulary already differs. HIPAA has covered entities and business associates; GDPR has controllers and processors; the DPDP Act has data fiduciaries and data processors. They rhyme, but the definitions and duties attached to each are not interchangeable — a fact that trips up teams porting a data-processing agreement from one regime to another.
How Each Treats Health Data
This is where a health platform feels the differences most sharply, because each law handles health information in a fundamentally different way.
HIPAA: health data is the whole point
Under HIPAA, health information in a covered context is the entire subject. Every rule — Privacy, Security, Breach Notification — exists to govern it. There is no "ordinary" data to contrast it against; PHI is the object of the law.
GDPR: health data is a special category
GDPR treats health data as one of its special categories under Article 9. Processing it is prohibited by default unless a specific condition applies — most often the individual's explicit consent — layered on top of an ordinary Article 6 lawful basis. So a health platform under GDPR needs two justifications for the same processing, and the bar for the second is high.
DPDP: no special category at all
Here is the difference that surprises everyone migrating from GDPR: the DPDP Act does not carve out a sensitive or health-data category. All digital personal data sits under one framework. Health data receives the same baseline consent-and-purpose protections as an email address. That doesn't make it low-risk — reputationally and ethically it's as sensitive as ever — but it means the statute won't differentiate for you; your own controls have to.
A team fluent in GDPR often assumes every privacy law has a special category for health, and builds around it. Under the DPDP Act that assumption is wrong — there is no separate sensitive tier. Conversely, a HIPAA-first team assumes health data is always specially regulated, and is surprised that GDPR reaches far beyond the clinical context to any personal data at all. Each law's treatment of health data has to be checked, not inherited.
The Comparison That Matters
With the foundations clear, here is the head-to-head across the dimensions a health platform actually has to operationalise.
| Dimension | HIPAA | GDPR | DPDP Act |
|---|---|---|---|
| Type of law | Sectoral (healthcare) | Omnibus (all personal data) | Omnibus (digital personal data) |
| Health data | The entire subject | Special category (Article 9) | No special category |
| Basis to process | Treatment, payment, operations without authorisation; authorisation for most else | An Article 6 basis + an Article 9 condition (often explicit consent) | Consent, or defined "legitimate uses" |
| Individual rights | Access, amendment, accounting of disclosures | Access, erasure, portability, objection, and more | Access, correction, erasure, grievance, nomination |
| Breach notice | To individuals & HHS, within 60 days | To the supervisory authority within 72 hours | To the Data Protection Board & affected persons, as prescribed |
| Enforcer | HHS OCR (civil); DOJ (criminal) | National supervisory authorities (DPAs) | Data Protection Board of India |
| Maximum penalty | ~$50K per violation, ~$1.5M/yr cap; criminal up to $250K & 10 yrs | Up to €20M or 4% of global annual turnover | Up to ₹250 crore |
| Reaches outside its border? | No — US only, flows via contract (BAAs) | Yes — extraterritorial | Yes — covers processing aimed at India |
The 72-hour GDPR breach clock versus HIPAA's 60 days is a small example of a big theme: even where all three require the same action, they require it on different timelines, to different recipients, under different penalties. A single breach playbook has to satisfy the strictest of each dimension at once.
What It Means for Your Platform
For a global health platform, the practical upshot is that one user's record can trigger all three regimes simultaneously — and the obligations stack rather than substitute.
- A US patient's record handled for a provider puts you squarely in HIPAA business-associate territory: BAAs, the Security Rule, the 60-day breach clock.
- An EU patient's record adds GDPR: an Article 6 basis plus an Article 9 condition, the full suite of data-subject rights, a 72-hour breach notification, and transfer rules for moving data out of the EU.
- An Indian patient's record adds the DPDP Act: valid consent, data-principal rights, and notice obligations — with no separate sensitive-data tier to lean on.
You cannot pick the "strongest" law and assume it covers the rest, because they protect different things. HIPAA's tight security won't supply GDPR's lawful basis; GDPR's consent machinery won't satisfy HIPAA's BAA requirement; the DPDP Act's consent framework won't meet either one's breach recipients. The compliance surface is the union of the three, not the maximum of them. For the EU-and-India slice specifically, we go deeper in GDPR vs DPDP.
Build the Shared Core Once
The situation sounds overwhelming until you separate what overlaps from what doesn't. A large share of the work — the security foundation — is common to all three, and you build it once. The privacy-specific obligations are the deltas you add per law.
✓ Build Once (shared core)
- Encryption at rest and in transit
- Access control and audit logging
- A documented risk assessment
- Vendor / sub-processor agreements
- An incident-response capability
- Data inventory and minimisation
◐ Add Per Law (the deltas)
- HIPAA: BAAs, minimum-necessary, 60-day breach
- GDPR: lawful basis + Article 9, DSAR rights, 72-hour breach, transfers
- DPDP: consent + notice, data-principal rights, Board notification
- Region-specific data-residency choices
An ISO 27001 information security management system is the most efficient way to build that shared core, because its controls map onto the security expectations of all three laws at once. That is exactly the strategy we lay out in ISO 27001 for healthcare and, for the India dimension, ISO 27001 + DPDP Act. Build the security machine once; run the three privacy overlays on top.
The winning pattern for a global health platform is not three parallel compliance projects. It is a single, strong security programme — encryption, access control, logging, risk assessment, vendor management, incident response — that every regulator recognises, plus three thin, deliberate overlays that add each law's unique privacy duties. Build the core once, and each new market becomes an overlay, not a rebuild.
Final Thought
HIPAA, GDPR, and the DPDP Act are often lumped together as "the data laws," and that shorthand hides the one insight that actually makes them manageable: they are built on different logics. One regulates a sector, one regulates a data type, one regulates consent. Once you see that, the fear of three overlapping regimes gives way to a plan — a shared security core that satisfies all of them, and three small overlays that honour what each demands uniquely.
The test: take a single patient record that belongs to a US, an EU, and an Indian user in turn, and ask what changes each time. If your platform can name the added obligation for each — a BAA here, an Article 9 condition there, a consent record for the third — you are running one coherent programme. If the answer is the same for all three, you have collapsed three laws into one and are compliant with none.
Frequently Asked Questions
HIPAA is a sectoral US law that protects health information held by healthcare providers, plans, and their vendors. GDPR is an EU omnibus law covering all personal data, which treats health data as a special category needing extra justification. India's DPDP Act is an omnibus law covering all digital personal data, built around consent — and notably it does not carve out a separate sensitive or health-data category. Different geographies, different scope, different logic.
GDPR covers health data, but very differently. HIPAA's entire subject is health information in a healthcare context. GDPR treats health data as a special category under Article 9, prohibited from processing unless a specific condition — usually explicit consent — is met, on top of an ordinary lawful basis. HIPAA regulates a sector; GDPR regulates a data type within a much broader law.
No. Unlike GDPR's special categories, the DPDP Act 2023 does not create a separate class of sensitive or health data. All digital personal data is treated under one consent-centric framework, so health data gets the same baseline protections as any other personal data — the differentiation has to come from your own controls rather than the statute.
No. HIPAA compliance builds much of the security foundation the other two need, but it does not deliver GDPR's lawful basis and data-subject rights or the DPDP Act's consent and data-principal rights. The security core overlaps heavily; the privacy obligations — legal basis, individual rights, cross-border transfer, breach timelines — are law-specific and must be built on top.