Offshoring Healthcare Finance and RCM: What HIPAA Actually Requires

The rumour arrives the same way every time. A conference room gets booked for a “transition planning” call with a vendor nobody recognises. New logins appear in the practice management system for people whose names nobody can place. By Thursday the finance floor has decided the whole accounting department is being moved offshore, and nobody senior will say anything on the record. Three floors up, somebody actually is holding a proposal, quoting a blended rate for AR follow-up that makes the internal cost look indefensible on a spreadsheet, and that person does not know whether signing it is even legal.

So here is the answer both of those people need, stated plainly. HIPAA does not prohibit sending protected health information offshore, and there is no federal regulation banning the offshoring of healthcare administrative work. But HIPAA does not stop applying at the border. The same business associate agreements, the same Security Rule risk analysis, the same minimum necessary limits and the same breach liability follow the data wherever the work sits. What changes offshore is not the rule. It is how hard the rule is to enforce, and how much of the operational scaffolding around it quietly breaks.

So it is a control question, not a legal one with a yes or no answer. The organisations that get burned are rarely the ones who asked whether they were allowed. They are the ones who assumed the vendor’s marketing page had handled it.

What HIPAA actually requires when PHI leaves the country

Start with the document everyone signs and almost nobody reads. Under 45 CFR 164.502(e) a covered entity may disclose PHI to a business associate only with satisfactory assurances that it will be safeguarded, and the Security Rule imposes the parallel obligation at 45 CFR 164.308(b). The required contents sit at 45 CFR 164.504(e): describe the permitted uses and disclosures, bar use beyond those terms, require compliance with applicable Security Rule requirements, and require the associate to report security incidents, including breaches, back to you. Three consequences of that matter more offshore than onshore.

The chain does not end at your vendor. HHS is explicit that a business associate must have a BAA with its subcontractor before disclosing PHI to it, and that subcontractors are themselves business associates with direct obligations. Offshore RCM vendors subcontract more than domestic ones: a coding partner in a second city, a data entry bench rented at month-end, a cloud or VDI provider, sometimes a staffing agency supplying the actual people. Every link needs its own agreement. Ask for the map. A vendor who cannot produce a current list of downstream entities touching your PHI has not given you a compliance programme, only a hope.

The risk analysis has to account for where the work is. The Security Rule requires an accurate and thorough assessment of risks to ePHI at 45 CFR 164.308(a)(1)(ii)(A). HHS addressed the offshore case directly in its guidance on cloud providers storing ePHI outside the United States: it is permitted, but outsourcing storage or other services for ePHI overseas “may increase the risks and vulnerabilities,” and those risks must be considered in the risk analysis and risk management required by 164.308(a)(1)(ii)(A) and (B). The destination is a variable in your analysis. A risk analysis that predates the offshore arrangement and was never updated is a finding waiting to happen.

Liability does not transfer. Business associates are directly liable for certain provisions of the HIPAA Rules, so the vendor carries real exposure. Your own obligations stay put. Know of a material breach of the BAA and you are expected to take reasonable steps to cure it and, failing that, to terminate. “The vendor told us it was fine” is not a defence.

The Medicare layer most provider groups forget

This is the part that surprises people, because it is not HIPAA at all and it lives in a different corner of the internet.

CMS requires Medicare Advantage organisations and Part D sponsors to track offshore subcontracting. The CY 2024 Parts C and D readiness checklist tells sponsoring organisations to keep the HPMS Offshore Subcontracting module current within 30 calendar days of signing an offshore contract, and defines an offshore subcontractor as a first tier, downstream or related entity located outside the 50 states, DC or a US territory. It points back to HPMS memoranda dated 23 July 2007, 20 September 2007 and 26 August 2008. The 2007 memo, “Sponsor Activities Performed Outside of the United States (Offshore Subcontracting),” is the origin of the attestation that circulates in the industry: sponsors report the subcontractor’s identity, the functions performed, what beneficiary PHI is shared and why it is necessary, and attest to both safeguards and annual audits of the arrangement.

If you are a health plan, that obligation is yours and it is a filing, not a philosophy. If you are a provider group or billing company, you are not the one filing, but you are very likely sitting in somebody’s FDR chain. That is why offshore attestation forms arrive from payers and PBMs with no explanation attached. When a plan asks whether any of your subcontractors perform Medicare-related functions outside the United States, the honest answer includes your RCM vendor and your RCM vendor’s subcontractors. Answering that form wrongly is a faster route to trouble than anything in the Privacy Rule, because it is a contractual representation with a date on it.

State restrictions exist, but there are fewer than the rumour mill suggests

“You can’t offshore Medicaid work” gets repeated confidently in finance departments and it is mostly wrong, with a real kernel inside it.

The HHS Office of Inspector General examined this in a 2014 report on offshore outsourcing by state Medicaid agencies. Its finding was blunt: there are no federal regulations prohibiting the offshore outsourcing of Medicaid administrative functions. Of 56 agencies surveyed, 15 had state-specific requirements on offshore outsourcing; of those, four prohibited it outright and 11 permitted it. The other 41 reported neither requirements nor offshore outsourcing. That report is over a decade old and state policy moves, so treat the counts as historical. The structural point holds: restrictions on offshoring healthcare data in the US are mostly contractual and state-programme-specific, not a federal ban.

So the work is reading your actual contracts: the state Medicaid provider or managed care agreement, commercial payer agreements that may carry data residency or offshore notification clauses nobody in finance has opened, and the cyber liability policy with its territorial conditions. Those documents, not a general principle, are where a real prohibition lives if one exists.

One newer item belongs on the checklist. The Justice Department’s Data Security Program, codified at 28 CFR Part 202 and in effect since 8 April 2025, restricts certain transactions giving countries of concern or covered persons access to bulk US sensitive personal data, and personal health data is a covered category. The countries named in 28 CFR 202.601 are China, Cuba, Iran, North Korea, Russia and Venezuela. India is not among them, so the programme does not bar the arrangement most healthcare organisations are contemplating. It does mean “where exactly, and through whose infrastructure” now has a national security dimension as well as a HIPAA one, and a vendor with staff in a listed country needs a closer look.

What actually moves offshore, and what doesn’t

Strip away the panic and the sales deck and the split is consistent across health systems, provider groups and medical supply companies. Work moves when it is rule-driven, high volume and checked against a document. It stays when the judgement carries legal or clinical weight, or when it means talking to a patient about money.

Commonly moved:

  • Charge entry and charge capture reconciliation
  • Claim scrubbing, electronic submission and clearinghouse rejection rework
  • Payment posting, including ERA exceptions and manual EOB posting
  • Insurance AR follow-up on aged claims, worked from worklists
  • Eligibility and benefits verification, prior authorisation status chasing
  • Denials triage: categorising, routing and refiling high-volume administrative denials
  • Credit balance research, refund packet preparation
  • Coding, usually under a US-credentialed supervisor with audit sampling
  • Accounting back office: AP processing, reconciliations, journal entry preparation, month-end schedules

Usually stays:

  • Patient-facing collections and financial counselling, where tone, state collection rules and charity care policy collide
  • Clinical appeals and medical necessity arguments that require reading a chart with clinical judgement
  • Payer contract negotiation and escalation with named payer reps
  • Compliance sign-off, coding audit conclusions, refund determinations with self-disclosure implications
  • Anything requiring a licensed or credentialed individual to attest in their own name
  • Final control ownership: who approves, who signs, who is accountable in an audit

The line between those lists is not nationality or skill. It is accountability. A denials analyst offshore can be better at reading a 277CA rejection than anyone you have ever employed. What they cannot be is the person who signs the refund letter or decides a coding pattern needs self-disclosure. Vendors who blur that line in a proposal have priced the accountability out.

The operational things that break first

Compliance failures in offshore RCM rarely start with a hacker. They start with a workaround that made one Tuesday easier.

Payer portal access is the classic one. Many portals issue credentials to a named individual, tie them to your organisation and prohibit sharing; some challenge or block logins from non-US IP ranges. The result is predictable. A US employee’s login gets shared so the work can continue, and now your audit trail says one person ran 900 eligibility checks in a day and your portal terms are breached. The fix is unglamorous: named accounts per offshore user where the payer allows it, written into the vendor contract, plus a routed connection so access originates where it should.

Audit trails need to identify humans. Shared service accounts in the EHR or practice management system destroy your ability to answer the only question that matters after an incident: who saw this record. Insist on one named account per person, joiner-mover-leaver notifications within a defined window, and a quarterly check of the leaver list against active accounts. Offshore vendors have real attrition. Orphaned accounts are how that attrition becomes your problem.

Minimum necessary is a configuration, not a promise. If your AR team can open clinical notes and imaging because that is how the role template shipped, you have granted far more than claim follow-up requires. Scope the role to the fields the task needs, then have someone screenshot what an offshore user actually sees. It is usually more than the contract implies.

Clearinghouse and banking access are not the same thing. Claim submission access is one matter; remittance files, lockbox images and bank portals are another, and the accounting side of these projects is where that gets waved through. Reconciliation work can move. Authority to move money should not.

Handoffs cost hours the rate card does not show. A twelve-hour offset gives you overnight processing on rule-driven work, a real benefit for submission and posting. It also means every question needing a US answer costs a day. Measure the saving at the hourly rate instead of the cycle time and you will be surprised when days in AR do not move for two quarters.

If you are the employee whose team is affected

The uncomfortable truth first. When finance work is offshored, the roles that disappear are the ones defined entirely by executing a documented process. The roles that survive, and often improve, are defined by exception handling, control ownership, vendor management and judgement. That is not comfort. It is a map.

What that means in the next 90 days. Learn the exceptions nobody has written down, because a transition exposes every one of them and somebody has to own them. Get your name on controls: reconciliations you approve, entries you review, the denial categories that need a decision rather than a resubmission. Volunteer for knowledge transfer instead of avoiding it, because the person who documents a process usually ends up governing it. If your organisation takes Medicare Advantage business, learn the FDR and offshore attestation process. It is a small, specific, transferable competence that almost nobody in a finance department has.

On the rumour itself: unverified reports of whole-department offshoring circulate constantly in healthcare finance, and are usually wrong in the detail even when directionally right. A vendor evaluation is not a signed contract, and a signed contract for AR follow-up is not the accounting department. Ask a manager directly.

Questions to ask a vendor before you sign

Bring these to the second meeting, not the fifth. They separate operators from resellers fast.

  • List every downstream subcontractor that will touch our PHI, give us each executed BAA, and tell us how we are notified when the list changes.
  • Where physically will our data be processed and stored, and does any of it transit or rest in a jurisdiction named in 28 CFR 202.601?
  • Show us your most recent risk analysis and access control policy, not a certificate summary.
  • Does any offshore staff member have local storage, USB, printing or personal device access in the delivery area, and how is that enforced rather than merely prohibited?
  • How are named user accounts provisioned and deprovisioned, and what is your contractual notification window for a departure?
  • Which functions run offshore, named individually, and which stay onshore? Put that list in the contract, not the SOW narrative.
  • If we do Medicare Advantage work, will you complete our offshore subcontractor attestation, and have you done one before?
  • What is your breach notification timeline to us in hours, and who makes the initial determination?
  • Who supervises coding, what credentials do they hold, and what are the audit sample rate and error threshold?
  • What happens on day one of termination: data return and destruction, access revocation timing, and whether you run in parallel during transition back?

A vendor that answers eight of those crisply is worth a pilot. One that answers any of them by describing itself as “HIPAA compliant”, as though that were a certificate, has told you something useful. HHS does not certify HIPAA compliance. There are audits, attestations and controls, and they are all specific.

Questions people ask next

If our vendor encrypts everything and holds no key, do we still need a BAA? Yes. HHS has addressed this for cloud providers: an entity maintaining ePHI on behalf of a covered entity is a business associate even if it only stores encrypted ePHI and lacks the decryption key. Encryption is a safeguard, not an exemption from the relationship.

Who is liable if the breach happens in an overseas office? Both parties, differently. The business associate is directly liable for the HIPAA Rule provisions that apply to it. Your organisation remains responsible for its own obligations, including acting on known material breaches of the BAA, and it is the one that notifies patients and appears in the news. That is why the breach notification clause and the indemnity language deserve legal review, not a procurement redline.

Does the CMS offshore attestation apply to a physician group? The filing obligation sits with the Medicare Advantage organisation or Part D sponsor, but sponsors push the question down their first tier, downstream and related entity chain. That is how practices and billing companies end up completing the forms. Know your answer before one arrives.

Can offshore staff do the coding? Nothing in HIPAA prohibits it and it is common. The controls that matter are supervision by a credentialed coder accountable to you, a defined audit sample with a documented error threshold, and a final compliance determination on questionable patterns that stays onshore. Ask for coder credentials by name, not a claim about the team.

If you are weighing this up, the useful conversation is not about rates. It is about which functions can move with their controls intact and which have to stay where the accountability sits. AB7 Solutions runs healthcare support, medical scribing, and billing and RCM teams alongside broader BPO and KPO work, and we are happy to walk through that function-by-function split with you, including the subcontractor map and access model questions above, before anyone talks pricing. Call +1 321 341 7733, email ab@ab7solutions.com or director@ab7solutions.com, or start at www.ab7solutions.com.

Sources: HHS Office for Civil Rights, Business Associates and FAQ 2083 on storing ePHI outside the United States; HHS, Security Rule and FAQ 2076; CMS, CY 2024 Parts C and D Readiness Checklist, offshore subcontracting section; HHS Office of Inspector General, Offshore Outsourcing of Administrative Functions by State Medicaid Agencies (OEI-09-12-00530, 2014); US Department of Justice, Data Security Program and 28 CFR 202.601.

Leave a Comment

Your email address will not be published. Required fields are marked *