← All Insights/HealthTech2026-08-26

Running clinical AI under HIPAA and GDPR at the same time

Health projects arrive with both regimes attached. It is cheaper to treat that as one architecture question.

By Windmill Editorial Team, Product and delivery

Running clinical AI under HIPAA and GDPR at the same time

Health projects tend to arrive with both regimes attached. The client is European, the data is patient data, and somewhere in the chain there is a US partner. Teams often treat that as two compliance exercises. It is cheaper to treat it as one architecture question.

Two constraints settle most of it. Where the data physically sits: we run these workloads in Swiss and EU cloud isolation, which removes the transfer argument before it starts rather than documenting a justification for it afterwards. What the model is allowed to retain: zero training on client data, contractually, across every model vendor in the chain. This is the clause people assume is standard and frequently is not.

Sprints run on sanitised data with no connection to live patient records, which is covered separately.

None of this is exotic. It is ordinary architecture applied early, which is considerably less expensive than the same architecture applied after a risk review has already said no.

Continue

Working on a related product or operating question?

Explore the four ways Windmill can help shape direction, prove value, build for production or evaluate a live system.