The Expanding Regulatory Landscape
The global data protection landscape has grown remarkably complex. In 2018, the European Union's General Data Protection Regulation set a new benchmark for privacy rights. Since then, more than 140 countries have enacted or updated data protection legislation, many drawing explicit inspiration from the GDPR's consent mechanisms, data-subject rights, and cross-border transfer restrictions. For healthcare organisations operating internationally, this creates a dense mosaic of overlapping obligations.
Health data occupies a uniquely sensitive position in virtually every regulatory framework. The GDPR designates it as a "special category" requiring explicit consent or a specific legal basis for processing. HIPAA applies protected health information standards to covered entities and business associates in the United States. Brazil's LGPD, India's DPDP Act of 2023, and South Korea's PIPA each introduce their own definitions of sensitive health information, lawful processing grounds, and breach notification timelines.
The proliferation is not merely legislative. Enforcement is intensifying. The European Data Protection Board reported a 40 percent increase in cross-border enforcement actions between 2022 and 2023, with healthcare and pharmaceutical companies among the most frequently investigated sectors. In the US, the Office for Civil Rights settled HIPAA violation cases totalling over $4 million in the first half of 2024 alone. Organisations that treat compliance as a checkbox exercise rather than an operational discipline are increasingly exposed to financial penalties, reputational damage, and operational disruption.
GDPR Evolution: What Changed in 2025
The GDPR is not a static instrument. Over its seven years of enforcement, supervisory authorities have progressively clarified its application to health data through guidelines, decisions, and case law. In 2025, several developments reshaped the compliance landscape for healthcare technology providers.
First, the European Data Protection Board issued updated guidance on Data Protection Impact Assessments for AI-driven medical devices. The guidance mandates that DPIAs address algorithmic bias, model explainability, and the rights of data subjects to contest automated clinical decisions under Article 22. This has material implications for any SaaS platform embedding clinical decision support.
Second, enforcement of the EU-US Data Privacy Framework entered a more rigorous phase. While the framework provides an adequacy mechanism for transatlantic data transfers, supervisory authorities have scrutinised health-tech companies for inadequate supplementary measures, particularly when sub-processors operate in jurisdictions lacking equivalent protections. The Schrems III challenge, filed in late 2024, adds further uncertainty.
Third, the interplay between the GDPR and the European Health Data Space regulation is reshaping secondary use of health data. The EHDS introduces a mandatory framework for accessing anonymised and pseudonymised health data for research and innovation, but imposes strict conditions on data holders and access bodies. Healthcare SaaS providers must now architect their data pipelines to support both primary care obligations under the GDPR and secondary use requirements under the EHDS.
Organisations that have invested in granular consent management, robust pseudonymisation pipelines, and documented data lineage are best positioned to navigate these evolving requirements.
HIPAA Modernization and the US Framework
HIPAA, enacted in 1996, has undergone incremental modernisation to address contemporary threats and technologies. The most significant recent development is the proposed HIPAA Security Rule update published by HHS in late 2024, which introduces mandatory multifactor authentication, encryption at rest and in transit for all electronic protected health information, and 72-hour breach notification to the Secretary—aligning more closely with GDPR timelines.
The rule also addresses cloud computing explicitly for the first time, requiring covered entities to maintain an inventory of all ePHI stored in cloud environments and to conduct annual penetration testing of cloud-hosted systems. Business associate agreements must now specify data residency requirements and incident response coordination procedures.
Beyond HIPAA, the US regulatory landscape is fragmenting at the state level. Washington's My Health My Data Act, effective since March 2024, extends protection to consumer health data outside HIPAA's scope, including data collected by wellness apps, wearables, and direct-to-consumer health platforms. Similar laws have passed or been proposed in Connecticut, Nevada, and Oregon. For health-tech companies offering both clinical and consumer-facing products, navigating this patchwork demands a tiered compliance architecture.
The Federal Trade Commission has also increased scrutiny of health data practices under Section 5 of the FTC Act, pursuing enforcement actions against companies that share health information with advertising networks without adequate disclosure. The convergence of HIPAA modernisation, state-level consumer health privacy laws, and FTC enforcement creates a multi-layered compliance challenge that few organisations can afford to address in isolation.
Asia-Pacific Data Protection Frameworks
The Asia-Pacific region represents one of the fastest-growing healthcare markets and one of the most diverse regulatory environments for data protection. Understanding the key frameworks is essential for any organisation with cross-border ambitions.
Thailand's Personal Data Protection Act, fully enforced since June 2022, classifies health data as sensitive personal data requiring explicit consent. The PDPA grants data subjects rights broadly analogous to the GDPR, including access, rectification, erasure, and data portability. Enforcement by the Personal Data Protection Committee has focused on healthcare providers that failed to implement adequate consent mechanisms for patient record sharing across affiliated facilities.
China's Personal Information Protection Law is arguably the most restrictive major framework. It requires data localisation for health information, mandates government security assessments for cross-border transfers exceeding defined thresholds, and imposes personal liability on data protection officers for compliance failures. Healthcare companies operating in China typically maintain entirely separate data infrastructure to meet these requirements.
Japan's Act on the Protection of Personal Information, amended in 2022, introduced stricter rules for "specially-required care information," including medical records, genomic data, and disability status. The amendment also enhanced cross-border transfer restrictions, requiring that foreign recipients provide protections equivalent to APPI standards.
Australia's Privacy Act reform, expected to be finalised in 2025, proposes a statutory tort for serious privacy invasions and enhanced protections for health information. South Korea's PIPA continues to evolve with strong enforcement, including substantial fines for data breaches involving medical records.
The common thread across these frameworks is the recognition that health data warrants heightened protection, but the mechanisms—consent models, transfer restrictions, localisation requirements, and enforcement approaches—vary significantly.
Building a Unified Compliance Strategy
Attempting to comply with each regulation independently is unsustainable. Organisations processing health data across multiple jurisdictions need a unified compliance architecture that satisfies the strictest applicable requirements while remaining adaptable to local variations.
Privacy by design is the foundational principle. Data minimisation, purpose limitation, and storage limitation should be embedded in system architecture from inception, not retrofitted as regulatory afterthoughts. Pseudonymisation and encryption must be applied consistently across all data layers, with key management practices that support jurisdiction-specific requirements for data residency and sovereign access.
Consent management requires particular sophistication in healthcare. A unified consent platform should capture, store, and honour granular consent preferences across care delivery, research, and analytics use cases. It must accommodate the varying legal bases recognised by different frameworks—explicit consent under the GDPR, authorisation under HIPAA, and legitimate interest where applicable—while presenting a coherent experience to the end user.
Cross-border data transfer mechanisms demand careful structuring. Standard contractual clauses, binding corporate rules, adequacy decisions, and government security assessments each serve different jurisdictional corridors. A transfer impact assessment methodology, applied systematically to each data flow, ensures that supplementary measures are proportionate and documented.
Audit trails are the connective tissue of compliance. Every access, modification, and transfer of health data should be logged immutably with sufficient context to reconstruct the full lifecycle of any record. These logs serve dual purposes: demonstrating accountability to regulators and supporting internal governance through continuous monitoring.
Finally, compliance is not a technology problem alone. It requires cross-functional collaboration among legal, clinical, engineering, and information security teams, supported by regular training, tabletop exercises, and executive accountability. Organisations that invest in this infrastructure are not merely avoiding penalties—they are building the trust that underpins sustainable growth in digital health.