Skip to content

Health data privacy laws

9 regulations worldwide that deal with health data, with every phased deadline and the official source for each.

Upcoming deadlines

October 20261 deadline

  1. PA 26-64 (SB 4) amendments take effect

    Prohibits controllers and third parties from selling precise geolocation data and enacts data broker and other consumer protection provisions.

    Takes effectin 7 daysSource

January 20271 deadline

  1. Data broker registration required

    Data brokers may not sell or license brokered personal data in Connecticut unless registered with the Department of Consumer Protection ($2,500 initial fee).

    Compliance deadlinein 3 monthsSource

March 20271 deadline

  1. EHDS general application date

    The regulation applies generally from 26 Mar 2027, subject to the phased exceptions below (final article).

    Takes effectin 6 monthsSource

April 20272 deadlines

  1. Discretionary 60-day cure period ends

    The Division's discretionary notice-and-cure (at least 60 days) applies only to violations occurring on or before April 1, 2027 (Com. Law 14-4614).

    Enforcementin 6 monthsSource
  2. GDPR

    GDPR Procedural Regulation applies

    Harmonised rules for cross-border complaint admissibility, rights to be heard and access to preliminary findings, and investigation timelines apply to DPAs from 2 April 2027 (Regulation (EU) 2025/2518, final article).

    Enforcementin 6 monthsSource

January 20281 deadline

  1. Vermont Data Privacy and Online Surveillance Act takes effect

    All obligations under Act 145 apply (sec. 4).

    Takes effectin 15 monthsSource

October 20281 deadline

  1. Data brokers must process state deletion mechanism requests

    Registered data brokers must access the DCP accessible deletion mechanism at least every 45 days and process deletion requests.

    Compliance deadlinein 2 yearsSource

March 20291 deadline

  1. Primary use for first data categories; secondary use framework applies

    Patient rights and EHR rules apply to patient summaries, ePrescriptions and eDispensations (Art 14(1)(a)-(c)). Chapter IV secondary-use rules (data permits, Health Data Access Bodies) apply.

    Compliance deadlinein 2.5 yearsSource

June 20291 deadline

  1. Mandatory 60-day cure period expires

    The AG's duty to issue a cure notice before enforcement ends June 30, 2029 (Act 145 sec. 3).

    Enforcementin 2.8 yearsSource

March 20311 deadline

  1. Primary use for second data categories; EHR systems in service; extra secondary-use categories

    Primary-use rules extend to medical images, lab results and discharge reports (Art 14(1)(d)-(f)). Chapter III applies to EHR systems put into service under Art 26(2). Additional secondary-use categories in Art 51(1)(b),(f),(g),(m),(p) apply.

    Compliance deadlinein 4.5 yearsSource

March 20351 deadline

  1. Third-country participation in secondary use

    Art 75(5) applies from 26 Mar 2035.

    Takes effectin 8.5 yearsSource

Past deadlines

August 20261 deadline

  1. Profiling impact assessments apply

    Impact assessment requirements apply to profiling activities created or generated on or after Aug 1, 2026 (Conn. Gen. Stat. 42-522 as amended).

    Compliance deadline54 days agoSource

July 20261 deadline

  1. PA 25-113 (SB 1295) amendments take effect

    Thresholds drop to 35,000 consumers or any sensitive-data processing or data sale; expanded sensitive data, minors' protections, and LLM-training disclosure in privacy notices.

    Takes effect3 months agoSource

April 20261 deadline

  1. MODPA applies to personal data processing

    The act applies to personal data processing activities from April 1, 2026 (Section 2 of ch. 455).

    Compliance deadline6 months agoSource

February 20261 deadline

  1. HIPAA

    Notice of Privacy Practices updates (Part 2 alignment)

    Covered entities must update Notices of Privacy Practices under 45 CFR 164.520 for the 2024 Part 2 (substance use disorder records) changes; this NPP piece survived the Purl vacatur.

    Compliance deadline7 months agoSource

January 20261 deadline

  1. GDPR

    GDPR Procedural Regulation enters into force

    Regulation (EU) 2025/2518, published in the OJ on 12 December 2025, enters into force on the twentieth day after publication.

    Transition9 months agoSource

November 20251 deadline

  1. GDPR

    GDPR Procedural Regulation adopted

    Regulation (EU) 2025/2518 laying down additional procedural rules for cross-border GDPR enforcement signed by Parliament and Council.

    Transition10 months agoSource

October 20252 deadlines

  1. DOJ Bulk Data Rule

    Due diligence, audit and reporting obligations apply

    Subpart J (data compliance program, due diligence and audits for restricted transactions) and reporting requirements in 202.1103 and 202.1104 apply.

    Compliance deadline12 months agoSource
  2. MODPA takes effect

    Act takes effect; data protection assessments apply to processing activities on or after Oct 1, 2025.

    Takes effect12 months agoSource

April 20251 deadline

  1. DOJ Bulk Data Rule

    Prohibitions and restrictions take effect

    Core prohibitions on covered data transactions and security requirements for restricted transactions apply.

    Takes effect18 months agoSource

March 20252 deadlines

  1. EHDS enters into force

    Regulation (EU) 2025/327, published 5 Mar 2025, enters into force on the twentieth day following publication.

    Takes effect18 months agoSource
  2. HIPAA

    Security Rule NPRM comment period closed

    Comments closed on the proposed HIPAA Security Rule update (90 FR 898); OCR has not issued a final rule.

    Transition19 months agoSource

January 20251 deadline

  1. Universal opt-out preference signals required

    Controllers must honor opt-out preference signals for targeted advertising and sale (effective Jan 1, 2025).

    Compliance deadline21 months agoSource

December 20242 deadlines

  1. Mandatory 60-day cure period expires

    After Dec 31, 2024, the AG is no longer required to offer a 60-day cure before enforcement; cure becomes discretionary.

    Enforcement21 months agoSource
  2. HIPAA

    Reproductive health privacy compliance date (vacated)

    Original compliance date for the reproductive health care privacy provisions, including the attestation requirement; these provisions no longer apply after the June 2025 vacatur.

    Compliance deadline21 months agoSource

July 20241 deadline

  1. 2024 amendments effective

    Amendments clarifying health app coverage, unauthorized disclosure as breach, email notice and FTC notice timing took effect.

    Takes effect2.2 years agoSource

June 20242 deadlines

  1. Small businesses must comply

    Sections 4-9 apply to small businesses.

    Compliance deadline2.2 years agoSource
  2. HIPAA

    Reproductive health care privacy rule effective (later vacated)

    The HIPAA Privacy Rule to Support Reproductive Health Care Privacy (89 FR 32976) took effect; it was vacated nationwide on June 18, 2025 in Purl v. HHS (N.D. Tex.).

    Takes effect2.2 years agoSource

March 20241 deadline

  1. Regulated entities must comply

    Sections 4-9 (privacy policy, consent, consumer rights, sale authorization) apply to regulated entities.

    Compliance deadline2.5 years agoSource

July 20232 deadlines

  1. Geofencing ban (Section 10) effective

    Ban on geofencing around health care facilities applies to all persons.

    Takes effect3.2 years agoSource
  2. CTDPA takes effect

    Core consumer rights and controller obligations apply.

    Takes effect3.2 years agoSource

April 20231 deadline

  1. HB 1155 signed

    Governor signs My Health My Data Act.

    Transition3.4 years agoSource

May 20181 deadline

  1. GDPR

    GDPR applies

    All GDPR obligations apply from 25 May 2018 (Art 99(2)), replacing Directive 95/46/EC.

    Takes effect8.3 years agoSource

May 20161 deadline

  1. GDPR

    GDPR enters into force

    Regulation entered into force on the twentieth day after publication in OJ L 119 of 4 May 2016 (Art 99(1)).

    Takes effect10.3 years agoSource

February 20101 deadline

  1. Full compliance with original Rule

    Full compliance with the 2009 Health Breach Notification Rule was required.

    Compliance deadline16.6 years agoSource

When the rules change: new data, privacy and AI laws and deadlines, the next morning.