PogoWasRight.org

Menu
  • About
  • Privacy
Menu

US healthcare offshoring: Navigating patient data privacy laws and regulations

Posted on July 3, 2025 by Dissent

From a post by Spencer Green and  Stephen Page of McDermott Will  & Emery:

HIPAA’s Extraterritorial Flexibility

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is the primary federal law that protects patients’ health information. HIPAA establishes standards for the privacy and security of a patient’s health and related information, known as protected health information or PHI, by healthcare providers, health plans, and healthcare clearinghouses and their subcontractors who provide services on behalf of healthcare providers or health plans involving PHI. These subcontractors, known as “business associates”, are required to enter in Business Associate Agreements that contain provisions designed to protect PHI, and have independent obligations to protect PHI under HIPAA.

HIPAA doesn’t prohibit PHI from being accessed or stored outside the US, despite the potential risks. If a foreign vendor violates HIPAA or experiences a data breach, there is limited recourse unless there are strong, binding, international arbitration provisions, or the foreign vendor maintains a substantial US-based presence.

But here’s what we need to remember:

If a foreign vendor violates HIPAA or experiences a data breach, there is limited recourse.

In light of this risk, many US state governments, healthcare providers, and health plans have sought to limit or prohibit the offshoring of US patient data.

Read more at JDSupra.

Related posts:

  • BULLETIN: HIPAA Privacy and Novel Coronavirus — from HHS OCR
  • “Out Of Control”: Dozens of Telehealth Startups Sent Sensitive Health Information to Big Tech Companies
  • California fines hospitals for breaches of medical privacy
  • The Biden-Harris Administration Issues New Rule to Support Reproductive Health Care Privacy Under HIPAA
Category: BreachesHealthcareLaws

Post navigation

← Data breach reveals Catwatchful ‘stalkerware’ is spying on thousands of phones
Ninth Circuit Reviews Website Tracking Class Actions and the Reach of California’s Privacy Law →

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Now more than ever

Search

Contact Me

Email: [email protected]

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

Categories

Recent Posts

  • Department of Justice Subpoenas Doctors and Clinics Involved in Performing Transgender Medical Procedures on Children
  • Google Settles Privacy Class Action Over Period Tracking App
  • ICE Is Searching a Massive Insurance and Medical Bill Database to Find Deportation Targets
  • Franklin, Tennessee Resident Sentenced to 30 Months in Federal Prison on Multiple Cyber Stalking Charges
  • On July 7, Gemini AI will access your WhatsApp and more. Learn how to disable it on Android.
  • German court awards Facebook user €5,000 for data protection violations
  • Record-Breaking $1.55M CCPA Settlement Against Health Information Website Publisher

RSS Recent Posts on DataBreaches.net

  • Avantic Medical Lab hacked; patient data leaked by Everest Group
  • Integrated Oncology Network victim of phishing attack; multiple locations affected (2)
  • HHS’ Office for Civil Rights Settles HIPAA Privacy and Security Rule Investigation with Deer Oaks Behavioral Health for $225k and a Corrective Action Plan
  • HB1127 Explained: North Dakota’s New InfoSec Requirements for Financial Corporations
  • Credit reports among personal data of 190,000 breached, put for sale on Dark Web; IT vendor fined
©2025 PogoWasRight.org. All rights reserved.