GDPR and HIPAA - How to achieve and manage both Compliance?
Narendra Sahoo
Director| PCI DSS| PCI SSF | SOC 2| GDPR | HIPAA | ISO 27001 Auditor / Consultant
GDPR and HIPAA are two Compliance Standards that have taken the industry by storm. Both the Standards have for long been a topic of discussion as organizations scramble around to ensure Compliance.?While the EU General Data Protection Regulation is a data security law that came into effect in 2018, the US Health Insurance Portability and Accountability Act is a health information security law that came into effect in 1996.?
GDPR and HIPAA share many common principles and overlapping standard requirements with the same goals of protecting an individual’s privacy.?Both regulate the way how personal information is secured when used, disclosed, maintained, and transmitted.?But, despite some similarities, there are significant differences between the two regulations. In today’s article, we have drawn out a comparative analysis of both GDPR VS HIPAA that will serve as a guide for organizations looking to achieve Compliance in both the regulation. Take a closer look at some of the similarities and differences mapped out in this article for a better understanding of Data Privacy Regulations.
GDPR VS HIPAA
Organizations looking to achieve Compliance in both standards should consider understanding GDPR and HIPAA Regulations, the process of implementation, including the scope of regulated entities, types of data regulated, and data that is permitted to use and disclosed. Given below are some key similarities and differences between GDPR and HIPAA (GDPR VS HIPAA)
1.Regulated Data
GDPR; GDPR Compliance? regulates not just Protected Health Information (PHI) but also extends to any kind of personally identifiable information (PII) and special category information as stated in the regulation.?
HIPAA: HIPAA Compliance specifically regulates Protected Health Information (PHI) and applies to people having access to such information.?
2.Applicability of Regulation
GDPR: GDPR Regulation applies to any Data Controllers (the entity who deals with or processes Personal Data) and Data Processors (the entity who deals or processes Personal Data on behalf of the Data Controller).?
HIPAA: HIPAA applies to organizations or Covered Entities including healthcare providers, health plans, and healthcare clearinghouses, and Business Associates which typically includes any entity working on behalf of a covered entity.?
3.Privacy Rights
GDPR: GDPR gives the citizens of EU the right?
HIPAA
HIPAA Privacy rights that are covered under consent and portability gives patients the right to access, update, and transfer healthcare information.
4.Consent
GDPR
GDPR Requires organizations to obtain explicit consent for processing personal health data. But in case the data may be processed without consent if it?falls under the?conditions of Processing?in?Article 9 of the GDPR.
HIPAA
HIPAA does not mention the requirement of explicit consent for processing or disclosure of PHI data for the purpose of treatment.?
5.Security Of Data
GDPR : GDPR requires organizations to take appropriate security measures for Personal data. With the specific mention of? Data protection by design and default implementing encryption.? HITRUST is one cybersecurity Framework that aligns closely with GDPR and data protection by design and by default.
HIPAA: HIPAA requires entities to take appropriate measures for ensuring the Security and Privacy of Personal Health Information. It provides guidance and outlines best practices for data security. Organizations often turn to HITRUST?since the security framework aligns with HIPAA Compliance Requirements.
6.Breach Notification
GDPR: As stated under GDPR Regulation organizations are required to disclose a data breach within?72 hours?of the breach discovered.?
HIPAA: As stated under HIPAA Regulation organizations are required to notify the public of a breach within 60 days. In case the number of individuals impacted is less than 500, the notification can be annual.
领英推荐
7.Penalties
GDPR: GDPR levies up to €10 million, or 2% of the worldwide annual revenue of the financial year, whichever is higher or on a high side may levy up to? €20 million, or 4% of the worldwide annual revenue of the financial year, whichever is higher.
HIPAA: HIPAA has outlined different levels of penalties for non-compliance. This includes-?
Individuals involved may also face potential criminal charges:?
8.Privacy or Data Protection Officer
GDPR: The organization needs to appoint a Data Protection Officer (DPO) who process sensitive Personal Data. The DPO is required to ensure data management and handling is in line with the GDPR Compliance. Their responsibilities would include enforcing the GDPR Regulation.?
HIPAA: HIPAA requires the appointment of a Privacy Officer and a Data Security Officer. The responsibility of the Privacy Officer is to oversee and ensure implementation of privacy policy in line with HIPAA regulation. It further includes ensuring maintenance of security policies and procedures to enforce Compliance.
9.Assessment
GDPR: GDPR requires organizations to perform Data Protection Impact Assessment every 3 years or when data processing is likely to result in a high risk to data subjects.
HIPAA: GDPR requires organizations to perform Data Protection Impact Assessment every 3 years or when data processing is likely to result in a high risk to data subjects. HIPAA requires entities to conduct Risk Assessment annually to ensure HIPAA Compliance.?
Conclusion
GDPR and HIPAA are both Compliance Standards that regulate Data Protection and Privacy. Organizations looking to achieve compliance in GDPR and HIPPA must as a part of their compliance process understand both the regulations and map out the requirements stated in both the Compliance.
This will highlight requirements that overlap in both regulations and make the process of compliance a lot easier.?We further suggested organizations conduct a thorough data assessment, identify risk exposure to the data, determine the current compliance status, and accordingly establish relevant policies and procedures to meet the requirements. Organizations should look to collaborate with a cyber-security consulting firm like us who possess the industry expertise and knowledge pertaining to various regulations and compliance standards.
Original Source:- GDPR vs HIPAA