HIPAA vs. GDPR vs. ISO 13485: Which One Applies to You?

Andrey Tatarenko
CEO of 26bitz

They answer different questions. HIPAA and GDPR protect personal health data: HIPAA in the US, for healthcare providers, health plans, and their vendors; GDPR in the EU, for any organization that processes personal data of people there. ISO 13485 isn't about privacy at all. It's a quality management standard for companies that design and make medical devices, software included. Many products fall under more than one.
Side by side
Three common mix-ups
- There's no official "HIPAA certification." Vendors show compliance through safeguards, signed agreements with customers, and audits.
- A consumer wellness app is often outside HIPAA but still inside GDPR, if it has EU users.
- An ISO 13485 certificate says nothing about privacy. And certification alone doesn't guarantee compliance with FDA's new rule.
Four quick scenarios
- A telehealth platform for US clinics: HIPAA (you're a business associate). GDPR only if you also serve EU patients.
- A wellness app with EU users and no medical claims: GDPR. Not HIPAA, and not ISO 13485 unless it becomes a medical device.
- A skin-analysis SaMD sold in the US and EU: ISO 13485 for the device, GDPR for EU users, HIPAA if hospital customers send you patient data.
- A pharma team's internal reporting tool: none of the device rules. Privacy rules depend on the data.
What changed recently
- HIPAA: HHS has pushed final action on its Security Rule overhaul from May 2026 to July 2027. The proposal would remove the "addressable" category, making nearly all safeguards mandatory. It's still only a proposal, and the existing Security Rule stays in effect.
- GDPR: The Digital Omnibus changes the Commission proposed in November 2025 are still being negotiated. Your current GDPR obligations remain fully in force.
- FDA and ISO 13485: FDA's QMSR took effect on February 2, 2026, and incorporates ISO 13485:2016 by reference. If you make a regulated device for the US, your ISO 13485 quality system now matters directly.
How to decide, in three questions
- Whose data, and where? US healthcare customers point to HIPAA. People in the EU point to GDPR.
- Is it a medical device? If yes, ISO 13485 is your quality system. See our guide to SaMD vs. non-regulated health software.
- Who's your customer? Healthcare providers will ask for a business associate agreement before they send you data.
Need help building this into your product? See how we handle compliance and security.
Last reviewed: October 2026. This is general information, not legal or regulatory advice.
FAQs
No. HIPAA is a US law about health information held by healthcare organizations and their vendors. GDPR is an EU law covering all personal data, with extra rules for health data.
No. It's for companies that design or make medical devices. Handling patient data alone doesn't trigger it.
No official one exists. You show compliance through safeguards, agreements with customers, and audits.
Yes, if it offers services to people in the EU or monitors their behavior.
Stay Updated with 26bitz
Subscribe to our newsletter for the latest insights, updates, and news from 26bitz.

Insights on Healthcare Tech
Exploring Innovations in Healthcare Technology
HIPAA vs. GDPR vs. ISO 13485: Which One Applies to You?
SaMD vs. Non-Regulated Health Software

Designing Brain Health Software That Actually Helps: Where Clinical Insight Meets Thoughtful UX

B2B Wellness Software: Boost Performance and Reduce Burnout
Future-Proof Your Healthcare Software
Contact us to design solutions that grow with you secure, smart, and patient-focused.
