GLACIS·EU AI Act series·EU AI Act vs HIPAA·Updated August 2026

EU AI Act vs HIPAA.

A side-by-side reference for healthcare and life-sciences operators with obligations on both sides of the Atlantic. The two regimes were drafted for different purposes — PHI protection (HIPAA) and AI-system safety and rights (EU AI Act) — and neither substitutes for the other. This crosswalk reads them in parallel across scope, trigger, evidence, penalties, enforcement, and AI-specific provisions.

Talk to us Series hub →
Healthcare AI Life sciences CMIO Privacy counsel
Scope
HIPAA: PHI handling in the US · EU AI Act: AI systems used in the EU
Penalty context
HIPAA: tiered and inflation-adjusted · EU: provision-, role-, and turnover-specific
Enforcement
HHS OCR · National competent authorities + AI Office
Aug 2026
Use current HHS and EU authority materials for live enforcement status
What changed by August 2026

After a provisional agreement in May 2026, the AI Omnibus was adopted as Regulation (EU) 2026/1744 and entered into force on 27 July 2026. Relevant Annex III high-risk obligations apply from 2 December 2027 and relevant Annex I product-embedded obligations from 2 August 2028. MDR/IVDR-linked systems often require analysis under the Annex I pathway, but classification remains product- and use-case-specific.

HIPAA continues to apply through its technology-neutral rules where the facts fall within scope. HHS tracking-technology guidance is guidance, not an AI enforcement action. The Sharp HealthCare matter is a pending putative-class complaint, not an OCR action or adjudicated precedent. A shared evidence architecture may support both programs, but HIPAA audit controls and EU Article 12 duties have different scopes and must be mapped separately.

By Joe Braidwood·14 min read·Updated August 26, 2026

Executive summary

HIPAA and its implementing rules govern protected health information held or handled by covered entities and business associates within the rules’ scope. The EU AI Act (Regulation 2024/1689, consolidated text current to 27 July 2026) regulates specified AI actors and uses under its own territorial and role-based rules. Neither regime’s applicability follows merely from “health data,” and compliance with one does not satisfy the other.

For an organization within both regimes’ scope, some operational records can support more than one review. A cryptographically verifiable record may help demonstrate selected system activity for HIPAA audit-control review and selected events in an Article 12 logging design. The record does not, by itself, establish compliance with either regime.

This crosswalk reads the two regimes in parallel across ten dimensions, identifies what HIPAA does not cover (AI-specific obligations) and what the AI Act does not cover (US PHI handling), and shows where a shared evidence trail can reduce duplication without collapsing two legal assessments into one.

In this crosswalk

Why this crosswalk matters now: Sharp HealthCare (Nov 2025)

A proposed class action was filed November 2025 against Sharp HealthCare alleging that an ambient AI scribe recorded an estimated 100,000+ patients without proper consent and that false consent statements appeared in medical records, citing California privacy law and HIPAA-adjacent consent requirements. Source

Healthcare AI operators with dual obligations face compounding liability — neither HIPAA documentation nor AI-Act documentation alone produces the evidence the class-action discovery process will demand.

The relationship between HIPAA and the EU AI Act

Understanding how HIPAA and the EU AI Act relate requires recognizing their fundamentally different origins and objectives. These frameworks emerged from different regulatory traditions to address different risks—yet both apply to healthcare AI systems operating across the Atlantic.

HIPAA: protecting health information

HIPAA, enacted in 1996 and substantially updated through the HITECH Act (2009), focuses on protecting the privacy and security of individually identifiable health information. Its core concern is preventing unauthorized access, use, and disclosure of Protected Health Information (PHI). HIPAA applies to “covered entities” (healthcare providers, health plans, clearinghouses) and their “business associates” who handle PHI on their behalf.

For AI systems, HIPAA asks: Is PHI adequately protected from unauthorized access, modification, or disclosure?

EU AI Act: ensuring AI safety and rights

The EU AI Act, enacted in 2024, focuses on ensuring AI systems are safe, respect fundamental rights, and operate transparently. Its core concern is preventing AI systems from causing harm to health, safety, or fundamental rights. The AI Act applies to providers and deployers of AI systems based on the risk level of the AI application, regardless of what data the AI processes.

For AI systems, the EU AI Act asks: Is this AI system designed and operated to prevent harm to individuals and society?

Complementary, not overlapping

These frameworks operate in different dimensions when their respective scope tests are met:

  • HIPAA is entity- and information-specific: Its Privacy and Security Rules protect PHI maintained or handled by covered entities and business associates; health information outside that relationship is not automatically subject to HIPAA.
  • EU AI Act is actor- and use-specific: It applies across sectors to covered providers, deployers and other operators, with different duties by role, intended purpose and risk classification.

Both regimes apply only when their separate triggers are satisfied—for example, a covered entity or business associate handles PHI and an AI provider or deployer is within the AI Act’s territorial and substantive scope. A patient’s EU location alone does not trigger HIPAA, and the presence of health information alone does not decide AI Act classification.

Side-by-side: ten dimensions

Dimension EU AI Act HIPAA
Primary focus Safety, transparency, and fundamental rights of AI systems Privacy and security of Protected Health Information (PHI)
Jurisdiction European Union (27 member states); extraterritorial — output used in the EU triggers obligations even where provider and deployer are outside the EU US federal rules for covered entities and business associates with PHI in scope
Scope trigger Provision or deployment of an AI system in the EU; provider/deployer status determined by Articles 3, 25 and 26 Creation, receipt, maintenance or transmission of PHI by a covered entity or business associate in a covered function
Risk classification Four-tier system: prohibited (Article 5), high-risk (Annex I or III), limited-risk (Article 50 transparency), minimal-risk No AI risk tiers; covered PHI is subject to applicable Privacy, Security and Breach Notification Rules. Properly de-identified information is not PHI.
Enforcement bodies National competent authorities in each member state plus the EU AI Office for GPAI; market surveillance under Article 74 HHS Office for Civil Rights (OCR); state attorneys general; civil-monetary-penalty tiers by culpability
Penalty ceiling €35M or 7% of global turnover (prohibited practices); €15M or 3% (other non-compliance); €7.5M or 1% (incorrect information) Current figures under HHS’s January 28, 2026 rule reach $73,011 per violation and a $2,190,294 calendar-year cap per identical provision in applicable tiers; the tier and amount depend on culpability, correction, and the facts
Evidence requirement Article 11 technical documentation per Annex IV; Article 12 automatic logging; Article 9 risk-management records; Article 14 human-oversight measures 45 CFR §164.312(b) audit controls; §164.308(a)(1)(ii)(D) information system activity review; risk analysis under §164.308(a)(1)(ii)(A)
Conformity assessment Article 43: internal control (most Annex III systems) or notified-body assessment (biometric ID, certain medical AI); EU declaration of conformity No general conformity-assessment or certification pathway; regulated entities implement required safeguards and may face OCR complaint, audit, investigation, or enforcement processes
Documentation retention Provider documentation generally retained for 10 years (Article 18); deployer logs under its control retained for an appropriate period of at least six months unless other EU or national law applies (Article 26(6)) 6 years from creation or last effective date (whichever is later) under §164.530(j)
Breach / incident notification Report immediately after the Article 73 causal trigger; general 15-day outer limit, 2 days for specified widespread/critical-infrastructure incidents, and 10 days where death occurs Affected individuals without unreasonable delay and no later than 60 days; under-500 breaches to HHS within 60 days after year-end; 500+ to HHS contemporaneously with individual notice; media notice only when more than 500 residents of a state or jurisdiction are affected

Key differences

While both frameworks aim to protect individuals, their approaches differ substantially in several critical areas.

1. Focus: data vs system

HIPAA: Data-Centric

HIPAA’s requirements center on PHI in the hands of covered entities and business associates. Safe-harbor de-identification requires removal of specified identifiers plus no actual knowledge that the remaining information can identify an individual; expert determination is a separate route. Entity, function and information all matter.

EU AI Act: System-Centric

The EU AI Act’s requirements depend on the actor, intended purpose, deployment context and classification route. A medical-device AI is high-risk under Article 6(1) only when both product-law coverage and the required third-party conformity-assessment trigger are met; the kind of data processed does not replace that analysis.

2. Sector specificity vs technology specificity

HIPAA is entity- and information-specific: It does not cover every healthcare context or every item of health data. Analyze whether the organization is a covered entity or business associate, whether the function is covered, and whether the information is PHI.

The EU AI Act is actor- and use-specific: It reaches covered AI actors across sectors, but exclusions, territorial scope, operator role, intended purpose and Article 6 classification determine the duties. The same technical component can be treated differently in different products and deployments.

3. Enforcement mechanisms

Enforcement Comparison

HIPAA

Enforced by HHS OCR through complaint investigations and compliance audits. Enforcement has historically focused on breach response and egregious violations. Civil monetary penalties are tiered by culpability level (unknowing, reasonable cause, willful neglect). State attorneys general can also enforce.

EU AI Act

Enforced by national market surveillance authorities in each EU member state, with coordination by the EU AI Office. Enforcement includes product market access (CE marking required), operational restrictions, and administrative fines. The AI Office oversees General Purpose AI model compliance directly.

4. Extraterritorial application

HIPAA applies through the covered-entity and business-associate definitions and the regulated functions they perform. A contract label or the presence of health data alone does not settle status; cross-border arrangements require fact-specific jurisdiction and role analysis.

The EU AI Act has explicit extraterritorial reach similar to GDPR. It applies to any provider placing AI systems on the EU market or putting them into service in the EU, regardless of where the provider is located. It also applies when AI output is used within the EU, even if both provider and deployer are outside the EU.

Detailed control mapping

Despite their different focuses, HIPAA and the EU AI Act share some underlying control requirements. Organizations can leverage these overlaps to build efficient, unified governance.

Privacy and data governance

Privacy Controls Mapping

Control Area HIPAA Requirement EU AI Act Requirement Synergy
Data Minimization Minimum Necessary (45 CFR 164.502(b)) Article 10(3) – training data limited to what is necessary High
Data Quality 45 CFR 164.530(c) – reasonable accuracy Article 10(2) – training data must be relevant, representative, free of errors High
Data Governance Policies and procedures for PHI handling Article 10 – comprehensive data governance for training, validation, testing Medium
Individual Rights Access, amendment, accounting of disclosures Article 86 – right to explanation for high-risk AI decisions Medium
Consent/Authorization Authorization required for non-permitted uses Transparency required; consent handled under GDPR Low

Security controls

Security Controls Mapping

Control Area HIPAA Security Rule EU AI Act Technical Requirements Synergy
Access Controls 164.312(a)(1) – unique user IDs, emergency access Article 9(4)(b) – access controls for authorized personnel High
Audit Logging 164.312(b) – activity logging for PHI access Article 12 – automatic logging of system operation Medium
Integrity Controls 164.312(c)(1) – protect ePHI from alteration Article 15 – accuracy, robustness, cybersecurity High
Transmission Security 164.312(e)(1) – encryption in transit Article 15(4) – cybersecurity appropriate to risks High
Risk Assessment 164.308(a)(1)(ii)(A) – security risk analysis Article 9 – risk management system Medium

Documentation requirements

Documentation Requirements Mapping

Document Type HIPAA Requirement EU AI Act Requirement
Policies & Procedures Required for all safeguards (164.530(i)) Required as part of QMS (Article 17)
Risk Documentation Risk analysis and management (164.308(a)(1)) Risk management system documentation (Article 9)
Technical Documentation System documentation for security controls Comprehensive technical documentation per Annex IV
Training Records Workforce training documentation (164.530(b)) AI literacy training records (Article 4)
Vendor Agreements Business Associate Agreements (164.308(b)) Contracts with deployers/downstream providers (Article 25)
Retention Period 6 years from creation or last effective date Specified provider documentation generally 10 years under Article 18; deployer logs at least six months under Article 26(6), unless other law applies

Audit Trail Requirements

Both frameworks require audit trails, but with different focuses:

HIPAA Audit Controls

  • Who accessed PHI (user identification)
  • What PHI was accessed (records, data elements)
  • When access occurred (timestamps)
  • What action was taken (read, write, delete)
  • 6-year retention requirement

Article 12(3): additional fields for remote biometric identification

  • Duration of each use (start/stop times)
  • Reference database used for input data
  • Input data that triggered search/match
  • Natural persons involved in verification
  • Logs for market surveillance inspection

Key insight: The list above is not a universal Article 12 checklist for healthcare AI; Article 12(3) applies those additional fields to high-risk remote biometric identification systems. Other high-risk systems need automatic logging that supports traceability appropriate to their intended purpose. HIPAA audit controls and AI Act logging may produce complementary evidence, but scope must be designed system by system.

Gap analysis: what HIPAA does not cover (EU AI Act-specific)

Organizations with mature HIPAA compliance programs will find significant gaps when applying EU AI Act requirements. These are requirements with no HIPAA equivalent.

EU AI Act Requirements Not Covered by HIPAA

1. Risk Classification and Prohibited AI

HIPAA has no concept of AI risk tiers or prohibited AI practices. The EU AI Act’s Article 5 bans certain AI uses outright (social scoring, manipulative AI, untargeted facial recognition). HIPAA-compliant AI could be entirely prohibited under EU AI Act.

2. Conformity Assessment and CE Marking

HIPAA requires no third-party certification. The EU AI Act requires high-risk systems to undergo conformity assessment (internal control or notified body), maintain technical documentation per Annex IV, and affix CE marking before market placement.

3. Human Oversight Requirements

Article 14 requires high-risk AI systems to be designed for effective human oversight, including the ability to interrupt or override. HIPAA has no specific human oversight requirements for automated systems.

4. Transparency Disclosures

Article 13 requires instructions for use, intended purpose, capabilities and limitations, human oversight measures, and performance metrics. HIPAA’s Notice of Privacy Practices doesn’t cover AI-specific disclosures.

5. Post-Market Monitoring

Article 72 requires systematic post-market monitoring to collect and analyze data on AI system performance throughout its lifecycle. HIPAA has no equivalent ongoing monitoring requirement.

6. Fundamental Rights Impact Assessment

Article 27 requires deployers of high-risk AI to conduct fundamental rights impact assessments before deployment. HIPAA risk assessments focus on privacy and security, not broader rights impacts.

Gap analysis: what the EU AI Act does not cover (HIPAA-specific)

Conversely, organizations with mature EU AI Act compliance will find gaps when applying HIPAA requirements.

HIPAA Requirements Not Covered by EU AI Act

1. Protected Health Information Definition

HIPAA defines PHI through covered information and regulated entities. Its Safe Harbor de-identification route specifies identifiers to remove and a no-actual-knowledge condition; Expert Determination is an alternative. The AI Act does not replace GDPR’s separate personal-data rules.

2. Business Associate Agreements

HIPAA’s BAA requirements specify contractual obligations for PHI handling by vendors. The EU AI Act has provider-deployer contracts (Article 25) but not specific data processing agreements—those fall under GDPR.

3. Administrative Safeguards

HIPAA’s detailed administrative safeguards (security official, workforce clearance procedures, information access management, security awareness training) have no direct EU AI Act equivalent.

4. Physical Safeguards

HIPAA’s physical safeguards (facility access controls, workstation security, device and media controls) are not addressed in the EU AI Act, which focuses on system behavior rather than infrastructure.

5. Individual Rights Specific to Health Data

HIPAA provides specific rights: access to medical records, amendment of records, accounting of disclosures, restrictions on use. The EU AI Act’s Article 86 right to explanation is narrower than HIPAA’s health-specific rights.

6. Breach Notification Specifics

HIPAA’s breach-notification framework differs from the AI Act’s Article 73 trigger and 2-, 10-, or 15-day outer limits. Both may apply independently; determine the correct HIPAA clock for the affected people and breach category.

Evidence requirements comparison

Both frameworks require organizations to retain different forms of documentation and operational evidence. Understanding which records support which obligation—and what additional context remains necessary—helps reduce duplication without overstating sufficiency.

Evidence Requirements by Framework

Evidence Type HIPAA EU AI Act Unified Approach
Risk Assessments Security risk analysis documentation Risk management system outputs (Article 9) Integrated risk framework covering both data and AI risks
Policy Documentation Written policies and procedures QMS procedures per Article 17 Single policy set with framework-specific sections
Access Logs PHI access audit trails System operation logs per Article 12 Comprehensive logging covering both access and operations
Vendor Agreements Signed BAAs Provider-deployer contracts Combined agreements addressing both requirements
Training Records HIPAA training completion AI literacy training per Article 4 Combined training program with both modules
Incident Records Breach investigation documentation Serious incident reports per Article 73 Unified incident management with dual reporting paths
Technical Documentation System security documentation Annex IV technical file Shared repository with framework-specific technical documentation and cross-references

Compliance strategy for dual-jurisdiction operators

Organizations operating healthcare AI in both US and EU markets should adopt a unified approach rather than maintaining parallel compliance programs.

GLACIS logoGLACIS
Dual-Jurisdiction Strategy

Building a Unified Compliance Framework

1

Adopt a Base Framework

Start with ISO 42001 or NIST AI RMF as your foundational AI governance framework. These provide comprehensive structures that can accommodate both HIPAA and EU AI Act requirements. Map control requirements from both regulations to your base framework.

2

Implement the Stricter Requirement

Do not compare unlike record types as a single “stricter” retention rule. Article 18 generally gives providers a 10-year period for specified AI Act documentation, while Article 26(6) gives deployers a separate log-retention rule of at least six months unless other law applies. HIPAA documentation rules and organization-specific audit-log schedules require their own mapping.

3

Address Framework-Specific Requirements

Build additional controls for requirements unique to each framework. EU AI Act requires conformity assessment, human oversight design, and post-market monitoring. HIPAA requires BAAs, specific individual rights handling, and healthcare-specific breach notification. These don’t overlap—you need both.

4

Create Unified Documentation

Use a shared repository and consistent identifiers where useful, while maintaining the framework-specific material each review requires. Cross-references reduce duplication; they do not make one record set automatically sufficient for both regimes.

5

Establish Dual Reporting Paths

Implement incident management that can trigger both HIPAA breach notification and EU AI Act serious-incident reporting. Train the team on Article 73’s immediate-reporting trigger and 2-, 10-, or 15-day outer limits as well as the applicable HIPAA clocks. An AI incident involving PHI may trigger both pathways.

Strategic advantage: Organizations that build unified compliance frameworks position themselves for faster market entry in both jurisdictions, reduced audit burden, and more efficient ongoing governance. The investment in unified infrastructure pays dividends across all regulated markets.

How GLACIS can support both evidence programs

GLACIS creates cryptographically verifiable records of what a configured supervision step reported for a covered event. Those records can be mapped into HIPAA and EU AI Act evidence programs, but verification does not prove execution or establish that a control was correctly designed, clinically effective, or legally sufficient.

HIPAA Evidence

  • Access control verification for ePHI
  • Audit logging with tamper-evident records
  • Encryption status attestation
  • Record of a configured security-control decision

EU AI Act Evidence

  • Article 12 automatic logging attestation
  • Operational evidence for selected risk controls
  • Human oversight control verification
  • Post-market monitoring attestation

GLACIS connects an intended rule to a recorded control decision and makes the record independently verifiable. That evidence may support HIPAA audit-control review and an AI Act logging or monitoring program; it does not automatically satisfy either framework, guarantee control effectiveness, or replace the required policies, risk analysis, technical documentation and conformity work.

Frequently asked questions

Does HIPAA compliance satisfy EU AI Act requirements?

No. HIPAA and the EU AI Act have different focuses and requirements. HIPAA addresses privacy and security of Protected Health Information (PHI), while the EU AI Act addresses AI system safety, transparency, and fundamental rights. HIPAA compliance provides a foundation for some data governance and security requirements, but does not satisfy EU AI Act obligations for risk management, conformity assessment, technical documentation, human oversight, or transparency disclosures.

If my healthcare AI is FDA-cleared, do I still need EU AI Act compliance?

FDA clearance does not itself establish EU AI Act compliance. If an AI system qualifies as a medical device under EU product law, the applicable AI Act and product-law conformity pathways may be coordinated. Under the AI Omnibus, relevant Annex I product-embedded high-risk obligations apply from 2 August 2028. Confirm the system-specific pathway with EU counsel and the notified body.

What documentation is required for both frameworks?

Both frameworks require documentation, but with different scope and purposes. HIPAA documentation may include policies and procedures, risk analysis and management records, BAAs, training records, and audit-control evidence. The EU AI Act requires role- and system-specific technical documentation, risk management, data governance, QMS and conformity records. A shared repository can reduce duplication, but each framework still needs a separate applicability and sufficiency assessment.

How do logging requirements compare?

HIPAA’s Security Rule requires mechanisms that record and examine activity in systems containing or using ePHI. Article 12 requires automatic logging capabilities that support traceability appropriate to a high-risk system’s intended purpose, including risk-relevant events and post-market monitoring. It does not generally require every input, output, model detail, or decision trace; the additional minimum fields apply specifically to high-risk remote biometric identification systems.

Which framework has stricter penalties?

The EU AI Act has higher headline ceilings. Under HHS’s January 28, 2026 rule, current HIPAA figures reach $73,011 per violation and a $2,190,294 calendar-year cap for violations of an identical provision in applicable tiers; the tier and amount depend on the facts. EU AI Act ceilings reach €35 million or 7% of worldwide annual turnover for specified prohibited practices and €15 million or 3% for specified operator-duty infringements, with different ceiling treatment for SMEs.

Can I use a single governance framework for both?

A shared control and evidence program can reduce duplication, but applicability and sufficiency must be assessed separately. ISO 42001 or NIST AI RMF may help organize the work; neither establishes compliance with HIPAA or the AI Act, and a shared repository is not automatically a single source of legal truth.

One trail, two regimes

Unified evidence for dual-jurisdiction healthcare AI.

GLACIS can preserve a signed operational record that supports selected assertions in HIPAA audit-control review and an Article 12 logging design. It does not establish dual compliance in one capture. A scoped workflow review can identify evidence gaps.

Talk to us See an evidence pack →

Related guides

EU AI Act series hubArticles, penalty structure, GLACIS coverage map.
Full compliance guideRisk categories, Articles 9–15, GPAI, conformity assessment.
For CMIOsClinical AI overlay: MDR/IVDR, Annex III §5, Article 12, Article 50.
For General CounselLiability allocation, vendor and deployer contracts, extraterritorial scope.
HIPAA-compliant AIPHI handling, BAAs, the Security Rule.
ISO 42001 guideAI management-system standard.