The relationship between HIPAA and the EU AI Act
Understanding how HIPAA and the EU AI Act relate requires recognizing their fundamentally different origins and objectives. These frameworks emerged from different regulatory traditions to address different risks—yet both apply to healthcare AI systems operating across the Atlantic.
HIPAA: protecting health information
HIPAA, enacted in 1996 and substantially updated through the HITECH Act (2009), focuses on protecting the privacy and security of individually identifiable health information. Its core concern is preventing unauthorized access, use, and disclosure of Protected Health Information (PHI). HIPAA applies to “covered entities” (healthcare providers, health plans, clearinghouses) and their “business associates” who handle PHI on their behalf.
For AI systems, HIPAA asks: Is PHI adequately protected from unauthorized access, modification, or disclosure?
EU AI Act: ensuring AI safety and rights
The EU AI Act, enacted in 2024, focuses on ensuring AI systems are safe, respect fundamental rights, and operate transparently. Its core concern is preventing AI systems from causing harm to health, safety, or fundamental rights. The AI Act applies to providers and deployers of AI systems based on the risk level of the AI application, regardless of what data the AI processes.
For AI systems, the EU AI Act asks: Is this AI system designed and operated to prevent harm to individuals and society?
Complementary, not overlapping
These frameworks operate in different dimensions when their respective scope tests are met:
- HIPAA is entity- and information-specific: Its Privacy and Security Rules protect PHI maintained or handled by covered entities and business associates; health information outside that relationship is not automatically subject to HIPAA.
- EU AI Act is actor- and use-specific: It applies across sectors to covered providers, deployers and other operators, with different duties by role, intended purpose and risk classification.
Both regimes apply only when their separate triggers are satisfied—for example, a covered entity or business associate handles PHI and an AI provider or deployer is within the AI Act’s territorial and substantive scope. A patient’s EU location alone does not trigger HIPAA, and the presence of health information alone does not decide AI Act classification.
Side-by-side: ten dimensions
| Dimension | EU AI Act | HIPAA |
|---|---|---|
| Primary focus | Safety, transparency, and fundamental rights of AI systems | Privacy and security of Protected Health Information (PHI) |
| Jurisdiction | European Union (27 member states); extraterritorial — output used in the EU triggers obligations even where provider and deployer are outside the EU | US federal rules for covered entities and business associates with PHI in scope |
| Scope trigger | Provision or deployment of an AI system in the EU; provider/deployer status determined by Articles 3, 25 and 26 | Creation, receipt, maintenance or transmission of PHI by a covered entity or business associate in a covered function |
| Risk classification | Four-tier system: prohibited (Article 5), high-risk (Annex I or III), limited-risk (Article 50 transparency), minimal-risk | No AI risk tiers; covered PHI is subject to applicable Privacy, Security and Breach Notification Rules. Properly de-identified information is not PHI. |
| Enforcement bodies | National competent authorities in each member state plus the EU AI Office for GPAI; market surveillance under Article 74 | HHS Office for Civil Rights (OCR); state attorneys general; civil-monetary-penalty tiers by culpability |
| Penalty ceiling | €35M or 7% of global turnover (prohibited practices); €15M or 3% (other non-compliance); €7.5M or 1% (incorrect information) | Current figures under HHS’s January 28, 2026 rule reach $73,011 per violation and a $2,190,294 calendar-year cap per identical provision in applicable tiers; the tier and amount depend on culpability, correction, and the facts |
| Evidence requirement | Article 11 technical documentation per Annex IV; Article 12 automatic logging; Article 9 risk-management records; Article 14 human-oversight measures | 45 CFR §164.312(b) audit controls; §164.308(a)(1)(ii)(D) information system activity review; risk analysis under §164.308(a)(1)(ii)(A) |
| Conformity assessment | Article 43: internal control (most Annex III systems) or notified-body assessment (biometric ID, certain medical AI); EU declaration of conformity | No general conformity-assessment or certification pathway; regulated entities implement required safeguards and may face OCR complaint, audit, investigation, or enforcement processes |
| Documentation retention | Provider documentation generally retained for 10 years (Article 18); deployer logs under its control retained for an appropriate period of at least six months unless other EU or national law applies (Article 26(6)) | 6 years from creation or last effective date (whichever is later) under §164.530(j) |
| Breach / incident notification | Report immediately after the Article 73 causal trigger; general 15-day outer limit, 2 days for specified widespread/critical-infrastructure incidents, and 10 days where death occurs | Affected individuals without unreasonable delay and no later than 60 days; under-500 breaches to HHS within 60 days after year-end; 500+ to HHS contemporaneously with individual notice; media notice only when more than 500 residents of a state or jurisdiction are affected |
Key differences
While both frameworks aim to protect individuals, their approaches differ substantially in several critical areas.
1. Focus: data vs system
HIPAA: Data-Centric
HIPAA’s requirements center on PHI in the hands of covered entities and business associates. Safe-harbor de-identification requires removal of specified identifiers plus no actual knowledge that the remaining information can identify an individual; expert determination is a separate route. Entity, function and information all matter.
EU AI Act: System-Centric
The EU AI Act’s requirements depend on the actor, intended purpose, deployment context and classification route. A medical-device AI is high-risk under Article 6(1) only when both product-law coverage and the required third-party conformity-assessment trigger are met; the kind of data processed does not replace that analysis.
2. Sector specificity vs technology specificity
HIPAA is entity- and information-specific: It does not cover every healthcare context or every item of health data. Analyze whether the organization is a covered entity or business associate, whether the function is covered, and whether the information is PHI.
The EU AI Act is actor- and use-specific: It reaches covered AI actors across sectors, but exclusions, territorial scope, operator role, intended purpose and Article 6 classification determine the duties. The same technical component can be treated differently in different products and deployments.
3. Enforcement mechanisms
Enforcement Comparison
Enforced by HHS OCR through complaint investigations and compliance audits. Enforcement has historically focused on breach response and egregious violations. Civil monetary penalties are tiered by culpability level (unknowing, reasonable cause, willful neglect). State attorneys general can also enforce.
Enforced by national market surveillance authorities in each EU member state, with coordination by the EU AI Office. Enforcement includes product market access (CE marking required), operational restrictions, and administrative fines. The AI Office oversees General Purpose AI model compliance directly.
4. Extraterritorial application
HIPAA applies through the covered-entity and business-associate definitions and the regulated functions they perform. A contract label or the presence of health data alone does not settle status; cross-border arrangements require fact-specific jurisdiction and role analysis.
The EU AI Act has explicit extraterritorial reach similar to GDPR. It applies to any provider placing AI systems on the EU market or putting them into service in the EU, regardless of where the provider is located. It also applies when AI output is used within the EU, even if both provider and deployer are outside the EU.
Detailed control mapping
Despite their different focuses, HIPAA and the EU AI Act share some underlying control requirements. Organizations can leverage these overlaps to build efficient, unified governance.
Privacy and data governance
Privacy Controls Mapping
| Control Area | HIPAA Requirement | EU AI Act Requirement | Synergy |
|---|---|---|---|
| Data Minimization | Minimum Necessary (45 CFR 164.502(b)) | Article 10(3) – training data limited to what is necessary | High |
| Data Quality | 45 CFR 164.530(c) – reasonable accuracy | Article 10(2) – training data must be relevant, representative, free of errors | High |
| Data Governance | Policies and procedures for PHI handling | Article 10 – comprehensive data governance for training, validation, testing | Medium |
| Individual Rights | Access, amendment, accounting of disclosures | Article 86 – right to explanation for high-risk AI decisions | Medium |
| Consent/Authorization | Authorization required for non-permitted uses | Transparency required; consent handled under GDPR | Low |
Security controls
Security Controls Mapping
| Control Area | HIPAA Security Rule | EU AI Act Technical Requirements | Synergy |
|---|---|---|---|
| Access Controls | 164.312(a)(1) – unique user IDs, emergency access | Article 9(4)(b) – access controls for authorized personnel | High |
| Audit Logging | 164.312(b) – activity logging for PHI access | Article 12 – automatic logging of system operation | Medium |
| Integrity Controls | 164.312(c)(1) – protect ePHI from alteration | Article 15 – accuracy, robustness, cybersecurity | High |
| Transmission Security | 164.312(e)(1) – encryption in transit | Article 15(4) – cybersecurity appropriate to risks | High |
| Risk Assessment | 164.308(a)(1)(ii)(A) – security risk analysis | Article 9 – risk management system | Medium |
Documentation requirements
Documentation Requirements Mapping
| Document Type | HIPAA Requirement | EU AI Act Requirement |
|---|---|---|
| Policies & Procedures | Required for all safeguards (164.530(i)) | Required as part of QMS (Article 17) |
| Risk Documentation | Risk analysis and management (164.308(a)(1)) | Risk management system documentation (Article 9) |
| Technical Documentation | System documentation for security controls | Comprehensive technical documentation per Annex IV |
| Training Records | Workforce training documentation (164.530(b)) | AI literacy training records (Article 4) |
| Vendor Agreements | Business Associate Agreements (164.308(b)) | Contracts with deployers/downstream providers (Article 25) |
| Retention Period | 6 years from creation or last effective date | Specified provider documentation generally 10 years under Article 18; deployer logs at least six months under Article 26(6), unless other law applies |
Audit Trail Requirements
Both frameworks require audit trails, but with different focuses:
HIPAA Audit Controls
- • Who accessed PHI (user identification)
- • What PHI was accessed (records, data elements)
- • When access occurred (timestamps)
- • What action was taken (read, write, delete)
- • 6-year retention requirement
Article 12(3): additional fields for remote biometric identification
- • Duration of each use (start/stop times)
- • Reference database used for input data
- • Input data that triggered search/match
- • Natural persons involved in verification
- • Logs for market surveillance inspection
Key insight: The list above is not a universal Article 12 checklist for healthcare AI; Article 12(3) applies those additional fields to high-risk remote biometric identification systems. Other high-risk systems need automatic logging that supports traceability appropriate to their intended purpose. HIPAA audit controls and AI Act logging may produce complementary evidence, but scope must be designed system by system.
Gap analysis: what HIPAA does not cover (EU AI Act-specific)
Organizations with mature HIPAA compliance programs will find significant gaps when applying EU AI Act requirements. These are requirements with no HIPAA equivalent.
EU AI Act Requirements Not Covered by HIPAA
1. Risk Classification and Prohibited AI
HIPAA has no concept of AI risk tiers or prohibited AI practices. The EU AI Act’s Article 5 bans certain AI uses outright (social scoring, manipulative AI, untargeted facial recognition). HIPAA-compliant AI could be entirely prohibited under EU AI Act.
2. Conformity Assessment and CE Marking
HIPAA requires no third-party certification. The EU AI Act requires high-risk systems to undergo conformity assessment (internal control or notified body), maintain technical documentation per Annex IV, and affix CE marking before market placement.
3. Human Oversight Requirements
Article 14 requires high-risk AI systems to be designed for effective human oversight, including the ability to interrupt or override. HIPAA has no specific human oversight requirements for automated systems.
4. Transparency Disclosures
Article 13 requires instructions for use, intended purpose, capabilities and limitations, human oversight measures, and performance metrics. HIPAA’s Notice of Privacy Practices doesn’t cover AI-specific disclosures.
5. Post-Market Monitoring
Article 72 requires systematic post-market monitoring to collect and analyze data on AI system performance throughout its lifecycle. HIPAA has no equivalent ongoing monitoring requirement.
6. Fundamental Rights Impact Assessment
Article 27 requires deployers of high-risk AI to conduct fundamental rights impact assessments before deployment. HIPAA risk assessments focus on privacy and security, not broader rights impacts.
Gap analysis: what the EU AI Act does not cover (HIPAA-specific)
Conversely, organizations with mature EU AI Act compliance will find gaps when applying HIPAA requirements.
HIPAA Requirements Not Covered by EU AI Act
1. Protected Health Information Definition
HIPAA defines PHI through covered information and regulated entities. Its Safe Harbor de-identification route specifies identifiers to remove and a no-actual-knowledge condition; Expert Determination is an alternative. The AI Act does not replace GDPR’s separate personal-data rules.
2. Business Associate Agreements
HIPAA’s BAA requirements specify contractual obligations for PHI handling by vendors. The EU AI Act has provider-deployer contracts (Article 25) but not specific data processing agreements—those fall under GDPR.
3. Administrative Safeguards
HIPAA’s detailed administrative safeguards (security official, workforce clearance procedures, information access management, security awareness training) have no direct EU AI Act equivalent.
4. Physical Safeguards
HIPAA’s physical safeguards (facility access controls, workstation security, device and media controls) are not addressed in the EU AI Act, which focuses on system behavior rather than infrastructure.
5. Individual Rights Specific to Health Data
HIPAA provides specific rights: access to medical records, amendment of records, accounting of disclosures, restrictions on use. The EU AI Act’s Article 86 right to explanation is narrower than HIPAA’s health-specific rights.
6. Breach Notification Specifics
HIPAA’s breach-notification framework differs from the AI Act’s Article 73 trigger and 2-, 10-, or 15-day outer limits. Both may apply independently; determine the correct HIPAA clock for the affected people and breach category.
Evidence requirements comparison
Both frameworks require organizations to retain different forms of documentation and operational evidence. Understanding which records support which obligation—and what additional context remains necessary—helps reduce duplication without overstating sufficiency.
Evidence Requirements by Framework
| Evidence Type | HIPAA | EU AI Act | Unified Approach |
|---|---|---|---|
| Risk Assessments | Security risk analysis documentation | Risk management system outputs (Article 9) | Integrated risk framework covering both data and AI risks |
| Policy Documentation | Written policies and procedures | QMS procedures per Article 17 | Single policy set with framework-specific sections |
| Access Logs | PHI access audit trails | System operation logs per Article 12 | Comprehensive logging covering both access and operations |
| Vendor Agreements | Signed BAAs | Provider-deployer contracts | Combined agreements addressing both requirements |
| Training Records | HIPAA training completion | AI literacy training per Article 4 | Combined training program with both modules |
| Incident Records | Breach investigation documentation | Serious incident reports per Article 73 | Unified incident management with dual reporting paths |
| Technical Documentation | System security documentation | Annex IV technical file | Shared repository with framework-specific technical documentation and cross-references |
Compliance strategy for dual-jurisdiction operators
Organizations operating healthcare AI in both US and EU markets should adopt a unified approach rather than maintaining parallel compliance programs.
Building a Unified Compliance Framework
Adopt a Base Framework
Start with ISO 42001 or NIST AI RMF as your foundational AI governance framework. These provide comprehensive structures that can accommodate both HIPAA and EU AI Act requirements. Map control requirements from both regulations to your base framework.
Implement the Stricter Requirement
Do not compare unlike record types as a single “stricter” retention rule. Article 18 generally gives providers a 10-year period for specified AI Act documentation, while Article 26(6) gives deployers a separate log-retention rule of at least six months unless other law applies. HIPAA documentation rules and organization-specific audit-log schedules require their own mapping.
Address Framework-Specific Requirements
Build additional controls for requirements unique to each framework. EU AI Act requires conformity assessment, human oversight design, and post-market monitoring. HIPAA requires BAAs, specific individual rights handling, and healthcare-specific breach notification. These don’t overlap—you need both.
Create Unified Documentation
Use a shared repository and consistent identifiers where useful, while maintaining the framework-specific material each review requires. Cross-references reduce duplication; they do not make one record set automatically sufficient for both regimes.
Establish Dual Reporting Paths
Implement incident management that can trigger both HIPAA breach notification and EU AI Act serious-incident reporting. Train the team on Article 73’s immediate-reporting trigger and 2-, 10-, or 15-day outer limits as well as the applicable HIPAA clocks. An AI incident involving PHI may trigger both pathways.
Strategic advantage: Organizations that build unified compliance frameworks position themselves for faster market entry in both jurisdictions, reduced audit burden, and more efficient ongoing governance. The investment in unified infrastructure pays dividends across all regulated markets.
How GLACIS can support both evidence programs
GLACIS creates cryptographically verifiable records of what a configured supervision step reported for a covered event. Those records can be mapped into HIPAA and EU AI Act evidence programs, but verification does not prove execution or establish that a control was correctly designed, clinically effective, or legally sufficient.
HIPAA Evidence
- Access control verification for ePHI
- Audit logging with tamper-evident records
- Encryption status attestation
- Record of a configured security-control decision
EU AI Act Evidence
- Article 12 automatic logging attestation
- Operational evidence for selected risk controls
- Human oversight control verification
- Post-market monitoring attestation
GLACIS connects an intended rule to a recorded control decision and makes the record independently verifiable. That evidence may support HIPAA audit-control review and an AI Act logging or monitoring program; it does not automatically satisfy either framework, guarantee control effectiveness, or replace the required policies, risk analysis, technical documentation and conformity work.
Frequently asked questions
Does HIPAA compliance satisfy EU AI Act requirements?
No. HIPAA and the EU AI Act have different focuses and requirements. HIPAA addresses privacy and security of Protected Health Information (PHI), while the EU AI Act addresses AI system safety, transparency, and fundamental rights. HIPAA compliance provides a foundation for some data governance and security requirements, but does not satisfy EU AI Act obligations for risk management, conformity assessment, technical documentation, human oversight, or transparency disclosures.
If my healthcare AI is FDA-cleared, do I still need EU AI Act compliance?
FDA clearance does not itself establish EU AI Act compliance. If an AI system qualifies as a medical device under EU product law, the applicable AI Act and product-law conformity pathways may be coordinated. Under the AI Omnibus, relevant Annex I product-embedded high-risk obligations apply from 2 August 2028. Confirm the system-specific pathway with EU counsel and the notified body.
What documentation is required for both frameworks?
Both frameworks require documentation, but with different scope and purposes. HIPAA documentation may include policies and procedures, risk analysis and management records, BAAs, training records, and audit-control evidence. The EU AI Act requires role- and system-specific technical documentation, risk management, data governance, QMS and conformity records. A shared repository can reduce duplication, but each framework still needs a separate applicability and sufficiency assessment.
How do logging requirements compare?
HIPAA’s Security Rule requires mechanisms that record and examine activity in systems containing or using ePHI. Article 12 requires automatic logging capabilities that support traceability appropriate to a high-risk system’s intended purpose, including risk-relevant events and post-market monitoring. It does not generally require every input, output, model detail, or decision trace; the additional minimum fields apply specifically to high-risk remote biometric identification systems.
Which framework has stricter penalties?
The EU AI Act has higher headline ceilings. Under HHS’s January 28, 2026 rule, current HIPAA figures reach $73,011 per violation and a $2,190,294 calendar-year cap for violations of an identical provision in applicable tiers; the tier and amount depend on the facts. EU AI Act ceilings reach €35 million or 7% of worldwide annual turnover for specified prohibited practices and €15 million or 3% for specified operator-duty infringements, with different ceiling treatment for SMEs.
Can I use a single governance framework for both?
A shared control and evidence program can reduce duplication, but applicability and sufficiency must be assessed separately. ISO 42001 or NIST AI RMF may help organize the work; neither establishes compliance with HIPAA or the AI Act, and a shared repository is not automatically a single source of legal truth.