Yes. HIPAA does not ban offshore medical billing: an overseas team can handle PHI if every vendor and subcontractor signs a business associate agreement and the risk is covered in your security risk analysis. Your practice keeps the liability, penalties reach $73,011 per violation, and Medicaid, Medicare Advantage, Florida and Texas rules add limits HIPAA does not.
The country is the wrong first question. In our billing reviews, offshore arrangements rarely failed because of where the team sat. They failed because nobody could see the chain: 78% had no subcontractor BAA on file. A well-documented offshore team is safer than an undocumented domestic one, and we would rather see a full vendor list than a US address.
Methodology:Luxen billing reviews: 410 practice billing reviews, Jan 2025 to Jun 2026, including 96 practices that shared payroll data. Offshore findings come from the vendor contracts and documents practices shared during those reviews. Luxen claim audit: 61,400 claims audited, Jan 2025 to Jun 2026. Luxen Practice Manager Survey 2026: 286 practice managers, March 2026. Rules and public figures come from HHS, CMS, eCFR, the Federal Register and state statutes, listed under Sources.
Yes. Nothing in the HIPAA Privacy, Security or Breach Notification Rules limits where a business associate works or where protected health information (PHI) sits. HHS says so directly in its cloud computing guidance: a covered entity may use a vendor that stores ePHI overseas, provided it signs a business associate agreement (BAA) and otherwise complies with the HIPAA Rules. Billing and claims processing are business associate functions, so the same logic covers an offshore team posting payments, scrubbing X12 837 claims or working denials.
The same HHS guidance adds the caveat most vendor pages leave out. Outsourcing ePHI overseas may increase the risks to the information and present special considerations with respect to enforceability. In plain terms, HHS can fine a US practice far more easily than it can reach a company in another country. HHS expects you to weigh that in your security risk analysis under 45 CFR 164.308(a)(1).
So the legal answer is yes, and the practical answer is that compliance depends on three things you control: the contract chain, the access model and the rules that sit on top of HIPAA. Across 410 Luxen billing reviews, 31% of the practices we reviewed had offshore staff working their billing account.
Offshore billing comes in two shapes. In the first, the offshore team logs in to your US-hosted practice management system, clearinghouse and payer portals, and PHI never leaves US servers. In the second, the vendor pulls files, EOBs, ERA 835 data or scanned charts into its own systems abroad. HIPAA permits both. State data residency laws, covered below, mostly reach the second.
A BAA for an offshore billing company must contain every element in 45 CFR 164.504(e), exactly as a domestic one does, plus the terms that make it enforceable abroad. The regulation requires the vendor to limit its use of PHI to what the contract permits, apply Security Rule safeguards, report breaches, pass the same terms to its subcontractors, support patient access and amendment requests, open its books to HHS, and return or destroy PHI when the contract ends.
For an offshore team, add these terms. None are required by HIPAA, but each closes a gap the regulation leaves open:
Under 45 CFR 164.502(e)(1)(ii), your vendor may pass PHI to a subcontractor only after that subcontractor signs its own BAA. The risk is not the first vendor you sign. It is the second and third links. The best-known case is UCSF in 2003: transcription work passed through a US vendor, then a Florida subcontractor, then a Texas intermediary, before reaching a transcriptionist in Pakistan who threatened to post patient records over unpaid wages.
We see the same pattern in billing. Among the offshore arrangements in our billing reviews, 78% had no subcontractor BAA on file and 64% could not list every subcontractor. If you already use the vendor compliance checklist we publish, add the subcontractor list as a separate line item.
Four sets of rules add limits HIPAA does not, and they decide whether offshore billing is compliant for your practice in particular.
Section 1902(a)(80) of the Social Security Act, added by Section 6505 of the Affordable Care Act, bars states from paying any financial institution or entity located outside the United States for Medicaid items or services. CMS guidance (SMD letter 10-026) says outsourcing information processing and claims-related call centers is not prohibited. An offshore team can therefore work your Medicaid claims, but every remittance must go to a US bank account in your name, never to a vendor account abroad. Under 42 CFR 438.602(i), Medicaid managed care plans themselves must not be located outside the US, and many state Medicaid contracts pass stricter data rules down to providers.
CMS requires Medicare Advantage and Part D sponsors to report every offshore subcontractor that receives, processes or stores beneficiary PHI, and to file an attestation in HPMS within 30 days of signing. Network providers and their vendors sit inside that downstream chain, which is why many MA plans send practices an offshore attestation form at credentialing or recredentialing. Answer it accurately.
Florida Statute 408.051(3), in force since July 1, 2023, requires health care providers using certified EHR technology to keep patient information stored offsite, including with third parties and cloud vendors, physically in the continental United States, its territories or Canada. Texas Health and Safety Code 183.002, added by SB 1188, requires electronic health records containing patient information to be physically maintained in the US or its territories from January 1, 2026, with Attorney General penalties of $5,000 to $250,000 per violation. Both laws target storage. An offshore team working only inside US-hosted systems can fit within them. A vendor that copies records to servers abroad cannot. Our guide to comparing medical billing companies covers what else to ask a vendor about where your data lives.
Practices that bill under DoD contracts can face DFARS 252.239-7010, which keeps government data inside the US unless the contracting officer approves otherwise. Substance use disorder records under 42 CFR Part 2 need their own contract terms, and some state Medicaid agencies ban offshore access outright in provider agreements.
You are, first. The practice is the covered entity, so HHS holds you responsible for signing a compliant BAA, doing a risk analysis that addressed the offshore risk, and acting on any pattern of violations you knew about. A business associate is also directly liable for Security Rule failures and for breach reporting, but HHS enforcement against a company with no US presence is slow at best.
The clock is set by 45 CFR 164.410: the vendor must tell you about a breach without unreasonable delay and in no case later than 60 calendar days after discovery. Your own 60-day deadline to notify patients can start when your agent knew, not when you were told. Civil money penalties, adjusted in January 2026, run from a minimum of $145 per violation where the practice did not know, to $73,011 per violation and a calendar-year cap of $2,190,294 for the most serious tier. Billing errors bring a second exposure: coding mistakes on federal claims can lead to overpayment demands and False Claims Act risk regardless of who keyed the claim.
Run the same seven checks on every offshore medical billing company, in this order, and stop at the first one it fails.
Most practices stop after step one. In the Luxen Practice Manager Survey 2026, 48% of practice managers did not know where their billing staff work, and 44% could not name the fee basis in their current billing contract.
Offshore teams are usually priced per full-time employee, not as a share of collections.
RCM Staff publishes 2026 ranges of $8 to $12 an hour for a billing specialist, $12 to $18 for a certified coder, and $1,400 to $3,500 a month per FTE. Percentage-of-collections vendors typically charge 3% to 6% of collections, and in-house billing is not free either: across 96 practices that shared payroll data, fully loaded in-house billing cost 7.9% of collections for practices under $2M.
In this example, the in-house team costs $7,110 a month, a percentage-of-collections vendor $2,700 to $5,400, and a 2-person offshore team $2,800 to $7,000.
The offshore line hides two costs. The practice still owns management, QA and denial strategy, and 42% of practice managers said nobody owns denial follow-up full time. Add the compliance work in the vetting steps above, and the low end of the offshore range often lands close to a percentage vendor that carries those duties itself. See our in-house versus outsourced billing comparison for the full cost model.
The same five gaps appear in almost every offshore arrangement we review. Among offshore arrangements in our billing reviews, 78% had no subcontractor BAA, 71% had no clause naming where data is stored, 64% could not list every subcontractor, 58% gave the practice no audit rights and 49% could not produce a current SOC 2 report.
Location decides your compliance workload. It does not decide claim quality. In the Luxen claim audit of 61,400 claims, eligibility and coverage errors caused 24% of denials, coding and modifier errors caused 21% of denials, and missing or invalid prior authorization caused 17% of denials. Those are process failures that happen onshore and offshore alike.
Offshore FTE teams fit practices that already have a strong billing manager, clean workflows and the time to run vendor compliance. A percentage vendor fits practices that want one party to own eligibility and prior authorization, certified coding and denial follow-up under a single BAA. Staffing churn matters too: 34% of practice managers replaced a biller in the past two years, and open biller roles took a median 67 days to fill. If you are weighing full-service medical billing against an offshore team, ask each option who owns clean claim rate and days in AR, and get it in writing. For how billing fits the wider revenue cycle, compare the stages each option actually covers. If you want a second opinion on your current setup, book a free billing review.
Want to know how this applies to your practice? We will review your AR and denials, free, in 30 minutes.
Book the reviewAll three models can be HIPAA compliant. They differ in who carries the paperwork, how far PHI travels and how easy the vendor is to hold to account.
| Factor | In-house team | Onshore billing company | Offshore billing team |
|---|---|---|---|
| BAA needed | No, staff are workforce | Yes, plus subcontractor BAAs | Yes, plus BAAs for every agency and subcontractor |
| Where PHI travels | Your systems only | US systems, sometimes vendor tools | Access from abroad, sometimes storage abroad |
| HHS enforcement reach | Direct | Direct against the vendor | Limited against a foreign entity |
| Medicaid remittance risk | None | Low | Must confirm US accounts only |
| Medicare Advantage attestation | Not triggered | Only if it uses offshore subcontractors | Must be disclosed to the plan |
| Florida and Texas storage laws | Met if your EHR is US hosted | Usually met | Met only if no PHI is stored abroad |
| Typical cost | 7.9% of collections for practices under $2M | 3% to 6% of collections | $1,400 to $3,500 a month per FTE |
| Who owns results | You | The vendor, per contract | Usually you, the team follows your direction |
Dental practices are HIPAA covered entities once they bill electronically, and Florida’s storage law reaches a broad list of licensed providers using certified EHR technology. Many dental PMS platforms are cloud hosted, so confirm where your vendor’s data center is before adding an offshore team. Dental billing teams often miss medical cross-coding, onshore or offshore: medical cross-coding opportunities were missed in 64% of dental practices reviewed. Ask whether the team can bill CDT and CPT with ICD-10 support, and keep narratives and X-rays inside your own system rather than on vendor file shares.
Therapy claims carry rules that are easy to miss remotely: the 8-minute rule, plan of care certification and the KX modifier past the Medicare threshold. The KX modifier was missing on 21% of Medicare therapy claims past the threshold in our claim audit. An offshore team can work these claims inside your EMR, but give it a written modifier checklist and audit a sample every month. See our physical therapy billing guide for the full rule set.
Behavioral health adds 42 CFR Part 2 for substance use disorder records. The 2024 Part 2 final rule, with compliance required from February 16, 2026, aligns Part 2 more closely with HIPAA, but Part 2 records still need specific consent and redisclosure terms in every vendor contract, offshore or not. Payer carve-outs also trip remote teams: claims sent to the medical plan instead of the behavioral health carve-out caused 12% of behavioral health denials. Our substance abuse billing page covers Part 2 in detail.
Ambulance agencies often run heavy Medicaid volume, so the Section 1902(a)(80) rule matters most here: remittances must reach a US account in the agency’s name. Documentation is the usual weak point, since Physician Certification Statements were missing or unsigned on 18% of non-emergency transports. An offshore team can chase PCS forms and code mileage, but only if trip records stay in your US-hosted ePCR and billing system rather than being exported.
Primary care practices usually hold several Medicare Advantage contracts, so offshore attestations arrive at every recredentialing. Keep one current list of vendors and countries to answer them the same way each time. Offshore teams can handle volume work such as charge entry and payment posting, but care management revenue needs clinical context: chronic care management time went uncaptured for 58% of eligible patients. Our primary care billing guide lists the codes to watch.
Yes. HIPAA allows it with a signed BAA, and this access-only model is the easiest to defend. Give each offshore user a named account with multifactor authentication, block downloads and printing, and review access logs monthly. It also keeps you within Florida and Texas storage laws, since no patient records are physically kept outside the country.
HIPAA does not rank countries, and no country is approved or banned. What matters is the vendor’s controls, its contract chain and whether you could enforce the contract. Compare vendors on SOC 2 or HITRUST evidence, subcontractor BAAs, US governing law, cyber insurance and breach notice terms rather than on location alone.
No. HIPAA does not require you to name business associates or their locations in your Notice of Privacy Practices, and patients do not need to consent to billing work done by a vendor. Some payer contracts and state programs do require disclosure to the payer, so check your Medicare Advantage and Medicaid agreements.
If the company submits claims or receives payment information on your behalf, list it as a billing agency in your Medicare enrollment on the CMS-855 form, just as you would a domestic one. Medicare payments must still go to an account in your name. Update the enrollment within the required window when you add or change vendors.
The BAA must require the vendor to return or destroy all PHI at termination, including copies held by subcontractors. If return or destruction is not feasible, the protections must continue for as long as the data is held. Ask for a written certificate of destruction and remove every offshore user account on your last day.
No. HIPAA requires satisfactory assurances through a BAA, not a specific certification. A current SOC 2 Type II or HITRUST report is still the most practical proof that the vendor’s safeguards exist, and it gives you documented evidence for your own risk analysis if HHS ever asks how you vetted the vendor.
A free 30 minute review of your AR ageing and denial reasons. We tell you what is recoverable and what it would take. No deck, no commitment, no fee.
Book a free billing review