Home/Research/Is it HIPAA compliant to use an offshore medical billing team?
Offshore billing compliance

Is it HIPAA compliant to use an offshore medical billing team?

Short answer

Yes. HIPAA does not ban offshore medical billing: an overseas team can handle PHI if every vendor and subcontractor signs a business associate agreement and the risk is covered in your security risk analysis. Your practice keeps the liability, penalties reach $73,011 per violation, and Medicaid, Medicare Advantage, Florida and Texas rules add limits HIPAA does not.

Key takeaways
  • HIPAA has no geographic limit, so an offshore billing team is legal when every link in the chain has a signed BAA.
  • HHS warns that offshore work raises enforceability risk and expects it in your security risk analysis.
  • Medicaid remittances must go to US accounts, and Medicare Advantage plans track offshore subcontractors that touch PHI.
  • Florida and Texas require patient records to be stored in North America or the US, which limits vendors that copy data abroad.
  • Among offshore arrangements in our billing reviews, 78% had no subcontractor BAA on file.
Luxen's take

The country is the wrong first question. In our billing reviews, offshore arrangements rarely failed because of where the team sat. They failed because nobody could see the chain: 78% had no subcontractor BAA on file. A well-documented offshore team is safer than an undocumented domestic one, and we would rather see a full vendor list than a US address.

Shivam Pujara,Founder, Luxen Talent

What our billing data shows

31%
31% of the practices we reviewed had offshore staff working their billing account, across 410 Luxen billing reviews.
78%
Among offshore arrangements in our billing reviews, 78% had no subcontractor BAA on file (Luxen billing reviews).
48%
In the Luxen Practice Manager Survey 2026, 48% of practice managers did not know where their billing staff work.

Methodology:Luxen billing reviews: 410 practice billing reviews, Jan 2025 to Jun 2026, including 96 practices that shared payroll data. Offshore findings come from the vendor contracts and documents practices shared during those reviews. Luxen claim audit: 61,400 claims audited, Jan 2025 to Jun 2026. Luxen Practice Manager Survey 2026: 286 practice managers, March 2026. Rules and public figures come from HHS, CMS, eCFR, the Federal Register and state statutes, listed under Sources.

Cite thisLuxen,Is it HIPAA compliant to use an offshore medical billing team?(luxentalent.com)

Does HIPAA allow an offshore medical billing team to handle PHI?

Yes. Nothing in the HIPAA Privacy, Security or Breach Notification Rules limits where a business associate works or where protected health information (PHI) sits. HHS says so directly in its cloud computing guidance: a covered entity may use a vendor that stores ePHI overseas, provided it signs a business associate agreement (BAA) and otherwise complies with the HIPAA Rules. Billing and claims processing are business associate functions, so the same logic covers an offshore team posting payments, scrubbing X12 837 claims or working denials.

The same HHS guidance adds the caveat most vendor pages leave out. Outsourcing ePHI overseas may increase the risks to the information and present special considerations with respect to enforceability. In plain terms, HHS can fine a US practice far more easily than it can reach a company in another country. HHS expects you to weigh that in your security risk analysis under 45 CFR 164.308(a)(1).

So the legal answer is yes, and the practical answer is that compliance depends on three things you control: the contract chain, the access model and the rules that sit on top of HIPAA. Across 410 Luxen billing reviews, 31% of the practices we reviewed had offshore staff working their billing account.

Access versus storage: why the distinction matters

Offshore billing comes in two shapes. In the first, the offshore team logs in to your US-hosted practice management system, clearinghouse and payer portals, and PHI never leaves US servers. In the second, the vendor pulls files, EOBs, ERA 835 data or scanned charts into its own systems abroad. HIPAA permits both. State data residency laws, covered below, mostly reach the second.

What must a HIPAA BAA cover when the billing team is offshore?

A BAA for an offshore billing company must contain every element in 45 CFR 164.504(e), exactly as a domestic one does, plus the terms that make it enforceable abroad. The regulation requires the vendor to limit its use of PHI to what the contract permits, apply Security Rule safeguards, report breaches, pass the same terms to its subcontractors, support patient access and amendment requests, open its books to HHS, and return or destroy PHI when the contract ends.

For an offshore team, add these terms. None are required by HIPAA, but each closes a gap the regulation leaves open:

  • A named list of every subcontractor and country that touches PHI, with 30 days notice before any change.
  • A data location clause stating whether PHI is only accessed from abroad or also stored there.
  • US governing law and venue, so a dispute is heard in a court you can use.
  • Audit rights, including remote review of access logs and a current SOC 2 Type II or HITRUST report.
  • Indemnity backed by cyber liability insurance that names your practice.
  • Breach notice in days, not the 60-day regulatory ceiling.

The subcontractor chain is where offshore billing breaks

Under 45 CFR 164.502(e)(1)(ii), your vendor may pass PHI to a subcontractor only after that subcontractor signs its own BAA. The risk is not the first vendor you sign. It is the second and third links. The best-known case is UCSF in 2003: transcription work passed through a US vendor, then a Florida subcontractor, then a Texas intermediary, before reaching a transcriptionist in Pakistan who threatened to post patient records over unpaid wages.

We see the same pattern in billing. Among the offshore arrangements in our billing reviews, 78% had no subcontractor BAA on file and 64% could not list every subcontractor. If you already use the vendor compliance checklist we publish, add the subcontractor list as a separate line item.

Which rules restrict offshore medical billing beyond HIPAA?

Four sets of rules add limits HIPAA does not, and they decide whether offshore billing is compliant for your practice in particular.

Medicaid payments must land in US accounts

Section 1902(a)(80) of the Social Security Act, added by Section 6505 of the Affordable Care Act, bars states from paying any financial institution or entity located outside the United States for Medicaid items or services. CMS guidance (SMD letter 10-026) says outsourcing information processing and claims-related call centers is not prohibited. An offshore team can therefore work your Medicaid claims, but every remittance must go to a US bank account in your name, never to a vendor account abroad. Under 42 CFR 438.602(i), Medicaid managed care plans themselves must not be located outside the US, and many state Medicaid contracts pass stricter data rules down to providers.

Medicare Advantage plans track offshore subcontractors

CMS requires Medicare Advantage and Part D sponsors to report every offshore subcontractor that receives, processes or stores beneficiary PHI, and to file an attestation in HPMS within 30 days of signing. Network providers and their vendors sit inside that downstream chain, which is why many MA plans send practices an offshore attestation form at credentialing or recredentialing. Answer it accurately.

Florida and Texas require US data storage

Florida Statute 408.051(3), in force since July 1, 2023, requires health care providers using certified EHR technology to keep patient information stored offsite, including with third parties and cloud vendors, physically in the continental United States, its territories or Canada. Texas Health and Safety Code 183.002, added by SB 1188, requires electronic health records containing patient information to be physically maintained in the US or its territories from January 1, 2026, with Attorney General penalties of $5,000 to $250,000 per violation. Both laws target storage. An offshore team working only inside US-hosted systems can fit within them. A vendor that copies records to servers abroad cannot. Our guide to comparing medical billing companies covers what else to ask a vendor about where your data lives.

Federal contracts and other programs

Practices that bill under DoD contracts can face DFARS 252.239-7010, which keeps government data inside the US unless the contracting officer approves otherwise. Substance use disorder records under 42 CFR Part 2 need their own contract terms, and some state Medicaid agencies ban offshore access outright in provider agreements.

Who is liable if an offshore billing vendor has a breach?

You are, first. The practice is the covered entity, so HHS holds you responsible for signing a compliant BAA, doing a risk analysis that addressed the offshore risk, and acting on any pattern of violations you knew about. A business associate is also directly liable for Security Rule failures and for breach reporting, but HHS enforcement against a company with no US presence is slow at best.

The clock is set by 45 CFR 164.410: the vendor must tell you about a breach without unreasonable delay and in no case later than 60 calendar days after discovery. Your own 60-day deadline to notify patients can start when your agent knew, not when you were told. Civil money penalties, adjusted in January 2026, run from a minimum of $145 per violation where the practice did not know, to $73,011 per violation and a calendar-year cap of $2,190,294 for the most serious tier. Billing errors bring a second exposure: coding mistakes on federal claims can lead to overpayment demands and False Claims Act risk regardless of who keyed the claim.

How do you vet offshore medical billing companies for HIPAA compliance?

Run the same seven checks on every offshore medical billing company, in this order, and stop at the first one it fails.

  1. Get the access model in writing. Confirm whether staff only log in to your systems or also store PHI abroad.
  2. Collect the full chain. Ask for every subcontractor, country and staffing agency, each with its own signed BAA.
  3. Read the BAA against 164.504(e). Check each required element, then the six offshore terms above.
  4. Ask for evidence, not claims. A current SOC 2 Type II or HITRUST report, the vendor’s own HIPAA risk analysis and its workforce training records.
  5. Check the controls. Named user accounts in your PM system, multifactor authentication, no local downloads, locked-down devices and session logging.
  6. Map it to your payers and state. Medicaid remittance to US accounts, MA offshore attestations, and Florida or Texas storage rules if they apply.
  7. Document your decision. Add the offshore risk and your mitigations to your security risk analysis and keep it for six years.

Most practices stop after step one. In the Luxen Practice Manager Survey 2026, 48% of practice managers did not know where their billing staff work, and 44% could not name the fee basis in their current billing contract.

What do offshore medical billing services cost once compliance is included?

Offshore teams are usually priced per full-time employee, not as a share of collections.

Medical billing outsourcing to India and the Philippines: typical rates

RCM Staff publishes 2026 ranges of $8 to $12 an hour for a billing specialist, $12 to $18 for a certified coder, and $1,400 to $3,500 a month per FTE. Percentage-of-collections vendors typically charge 3% to 6% of collections, and in-house billing is not free either: across 96 practices that shared payroll data, fully loaded in-house billing cost 7.9% of collections for practices under $2M.

Worked example: 3 providers, $90,000 a month in collections

  • In-house team: $90,000 x 7.9% = $7,110 a month, or $85,320 a year.
  • Percentage-of-collections vendor at 3% to 6%: $2,700 to $5,400 a month, or $32,400 to $64,800 a year.
  • Offshore FTE team, 2 full-time staff at $1,400 to $3,500 each: $2,800 to $7,000 a month, or $33,600 to $84,000 a year.

In this example, the in-house team costs $7,110 a month, a percentage-of-collections vendor $2,700 to $5,400, and a 2-person offshore team $2,800 to $7,000.

Monthly billing cost, $90,000 practice Monthly billing cost, $90,000 practice. Low: In-house team $7,110, % of collections $2,700, Offshore FTE team $2,800; High: In-house team $7,110, % of collections $5,400, Offshore FTE team $7,000. Source: Luxen billing reviews, 96 practices; RCM Staff 2026 FTE ranges. Monthly billing cost, $90,000 practice Low High $0 $2,000 $4,000 $6,000 $8,000 $7,110 $7,110 In-house team $2,700 $5,400 % of collections $2,800 $7,000 Offshore FTEteam Source: Luxen billing reviews, 96 practices; RCM Staff 2026 FTE ranges
Source: Luxen billing reviews, 96 practices; RCM Staff 2026 FTE ranges

The offshore line hides two costs. The practice still owns management, QA and denial strategy, and 42% of practice managers said nobody owns denial follow-up full time. Add the compliance work in the vetting steps above, and the low end of the offshore range often lands close to a percentage vendor that carries those duties itself. See our in-house versus outsourced billing comparison for the full cost model.

What HIPAA mistakes do practices make with offshore billing teams?

The same five gaps appear in almost every offshore arrangement we review. Among offshore arrangements in our billing reviews, 78% had no subcontractor BAA, 71% had no clause naming where data is stored, 64% could not list every subcontractor, 58% gave the practice no audit rights and 49% could not produce a current SOC 2 report.

Gaps in offshore billing contracts Gaps in offshore billing contracts. Subcontractor BAA: 78%; Data location clause: 71%; Named subcontractors: 64%; Audit rights: 58%; Current SOC 2 report: 49%. Gaps in offshore billing contracts Share of offshore arrangements missing each item Subcontractor BAA 78% Data location clause 71% Named subcontractors 64% Audit rights 58% Current SOC 2 report 49%
  • Treating the BAA as the whole answer. A signed BAA with the first vendor says nothing about the staffing agency behind it.
  • Sharing logins. One shared PM system account for an offshore team breaks the Security Rule’s unique user identification standard and makes audit logs useless.
  • Letting remittances route abroad. Medicaid payments must reach a US account in the practice’s name.
  • Answering MA attestations from memory. Check the vendor chain before you sign one.

Is offshore billing the right choice, or is outsourcing to a percentage vendor safer?

Location decides your compliance workload. It does not decide claim quality. In the Luxen claim audit of 61,400 claims, eligibility and coverage errors caused 24% of denials, coding and modifier errors caused 21% of denials, and missing or invalid prior authorization caused 17% of denials. Those are process failures that happen onshore and offshore alike.

Where denials come from Where denials come from. Eligibility and coverage: 24%; Coding and modifiers: 21%; Prior authorization: 17%; All other causes: 38%. Source: Luxen claim audit, 61,400 claims, Jan 2025 to Jun 2026. Where denials come from Share of denials by cause 24% 21% 17% 38% 100% Eligibility andcoverage 24% (24%) Coding andmodifiers 21% (21%) Priorauthorization 17% (17%) All other causes 38% (38%) Source: Luxen claim audit, 61,400 claims, Jan 2025 to Jun 2026
Source: Luxen claim audit, 61,400 claims, Jan 2025 to Jun 2026

Offshore FTE teams fit practices that already have a strong billing manager, clean workflows and the time to run vendor compliance. A percentage vendor fits practices that want one party to own eligibility and prior authorization, certified coding and denial follow-up under a single BAA. Staffing churn matters too: 34% of practice managers replaced a biller in the past two years, and open biller roles took a median 67 days to fill. If you are weighing full-service medical billing against an offshore team, ask each option who owns clean claim rate and days in AR, and get it in writing. For how billing fits the wider revenue cycle, compare the stages each option actually covers. If you want a second opinion on your current setup, book a free billing review.

Want to know how this applies to your practice? We will review your AR and denials, free, in 30 minutes.

Book the review

How do offshore, onshore and in-house billing compare on HIPAA risk?

All three models can be HIPAA compliant. They differ in who carries the paperwork, how far PHI travels and how easy the vendor is to hold to account.

FactorIn-house teamOnshore billing companyOffshore billing team
BAA neededNo, staff are workforceYes, plus subcontractor BAAsYes, plus BAAs for every agency and subcontractor
Where PHI travelsYour systems onlyUS systems, sometimes vendor toolsAccess from abroad, sometimes storage abroad
HHS enforcement reachDirectDirect against the vendorLimited against a foreign entity
Medicaid remittance riskNoneLowMust confirm US accounts only
Medicare Advantage attestationNot triggeredOnly if it uses offshore subcontractorsMust be disclosed to the plan
Florida and Texas storage lawsMet if your EHR is US hostedUsually metMet only if no PHI is stored abroad
Typical cost7.9% of collections for practices under $2M3% to 6% of collections$1,400 to $3,500 a month per FTE
Who owns resultsYouThe vendor, per contractUsually you, the team follows your direction

How the answer changes by specialty

Dental

Dental practices are HIPAA covered entities once they bill electronically, and Florida’s storage law reaches a broad list of licensed providers using certified EHR technology. Many dental PMS platforms are cloud hosted, so confirm where your vendor’s data center is before adding an offshore team. Dental billing teams often miss medical cross-coding, onshore or offshore: medical cross-coding opportunities were missed in 64% of dental practices reviewed. Ask whether the team can bill CDT and CPT with ICD-10 support, and keep narratives and X-rays inside your own system rather than on vendor file shares.

Physical therapy

Therapy claims carry rules that are easy to miss remotely: the 8-minute rule, plan of care certification and the KX modifier past the Medicare threshold. The KX modifier was missing on 21% of Medicare therapy claims past the threshold in our claim audit. An offshore team can work these claims inside your EMR, but give it a written modifier checklist and audit a sample every month. See our physical therapy billing guide for the full rule set.

Behavioral health

Behavioral health adds 42 CFR Part 2 for substance use disorder records. The 2024 Part 2 final rule, with compliance required from February 16, 2026, aligns Part 2 more closely with HIPAA, but Part 2 records still need specific consent and redisclosure terms in every vendor contract, offshore or not. Payer carve-outs also trip remote teams: claims sent to the medical plan instead of the behavioral health carve-out caused 12% of behavioral health denials. Our substance abuse billing page covers Part 2 in detail.

Ambulance and EMS

Ambulance agencies often run heavy Medicaid volume, so the Section 1902(a)(80) rule matters most here: remittances must reach a US account in the agency’s name. Documentation is the usual weak point, since Physician Certification Statements were missing or unsigned on 18% of non-emergency transports. An offshore team can chase PCS forms and code mileage, but only if trip records stay in your US-hosted ePCR and billing system rather than being exported.

Primary care

Primary care practices usually hold several Medicare Advantage contracts, so offshore attestations arrive at every recredentialing. Keep one current list of vendors and countries to answer them the same way each time. Offshore teams can handle volume work such as charge entry and payment posting, but care management revenue needs clinical context: chronic care management time went uncaptured for 58% of eligible patients. Our primary care billing guide lists the codes to watch.

Frequently asked questions

Can offshore billers work in my EHR if all data stays on US servers?

Yes. HIPAA allows it with a signed BAA, and this access-only model is the easiest to defend. Give each offshore user a named account with multifactor authentication, block downloads and printing, and review access logs monthly. It also keeps you within Florida and Texas storage laws, since no patient records are physically kept outside the country.

Is India or the Philippines safer for HIPAA compliance?

HIPAA does not rank countries, and no country is approved or banned. What matters is the vendor’s controls, its contract chain and whether you could enforce the contract. Compare vendors on SOC 2 or HITRUST evidence, subcontractor BAAs, US governing law, cyber insurance and breach notice terms rather than on location alone.

Do I have to tell patients that my billing team is offshore?

No. HIPAA does not require you to name business associates or their locations in your Notice of Privacy Practices, and patients do not need to consent to billing work done by a vendor. Some payer contracts and state programs do require disclosure to the payer, so check your Medicare Advantage and Medicaid agreements.

Do I report an offshore billing company to Medicare?

If the company submits claims or receives payment information on your behalf, list it as a billing agency in your Medicare enrollment on the CMS-855 form, just as you would a domestic one. Medicare payments must still go to an account in your name. Update the enrollment within the required window when you add or change vendors.

What happens to PHI when I end an offshore billing contract?

The BAA must require the vendor to return or destroy all PHI at termination, including copies held by subcontractors. If return or destruction is not feasible, the protections must continue for as long as the data is held. Ask for a written certificate of destruction and remove every offshore user account on your last day.

Does HIPAA require a SOC 2 or HITRUST report from an offshore vendor?

No. HIPAA requires satisfactory assurances through a BAA, not a specific certification. A current SOC 2 Type II or HITRUST report is still the most practical proof that the vendor’s safeguards exist, and it gives you documented evidence for your own risk analysis if HHS ever asks how you vetted the vendor.

Sources

Shivam Pujara
About the author
Shivam Pujara
Founder, Luxen Talent|Leads Luxen's billing and revenue cycle team

Shivam founded Luxen to run the revenue cycle for independent medical practices, from eligibility checks to zero balance, inside the systems they already use. He writes from what the team sees in client AR, denials and billing reviews every week.

LinkedIn profile

Get a straight answer for your practice

A free 30 minute review of your AR ageing and denial reasons. We tell you what is recoverable and what it would take. No deck, no commitment, no fee.

Book a free billing review