Does HIPAA let protected health information be accessed from outside the United States?
Yes — and the same federal answer that grants the permission attaches a caution that belongs in the same breath. HHS answers the question in OCR’s FAQ 2083, written about a cloud service provider (CSP) that stores electronic protected health information (ePHI) on servers outside the United States:
Yes, provided the covered entity (or business associate) enters into a business associate agreement (BAA) with the CSP and otherwise complies with the applicable requirements of the HIPAA Rules. However, while the HIPAA Rules do not include requirements specific to protection of electronic protected health information (ePHI) processed or stored by a CSP or any other business associate outside of the United States, OCR notes that the risks to such ePHI may vary greatly depending on its geographic location. In particular, outsourcing storage or other services for ePHI overseas may increase the risks and vulnerabilities to the information or present special considerations with respect to enforceability of privacy and security protections over the data.
That is the whole federal position in three sentences. The HIPAA Rules contain no geography requirement: nothing in them says protected health information (PHI) must stay on US soil, and OCR says so plainly — the Rules “do not include requirements specific to” ePHI handled outside the United States.
Two things the answer is not. It is not an endorsement of offshore staffing: the FAQ is literally about a CSP storing ePHI on servers abroad, and its reach comes from its own wording — “a CSP or any other business associate outside of the United States” — not from any HHS statement about overseas teams. And it is not an unconditional yes. The defensible reading is narrow: HIPAA does not require PHI to stay in the United States, and an offshore arrangement is permitted provided a business associate agreement is in place and the offshore risk is addressed in the risk analysis the Security Rule requires. A page that quotes the “Yes” without the caution is quoting half the answer — which is why the caution appears here, and again below, every time the permission does.
“Accessed” vs “stored”: why a remote offshore team still counts
An outsourced dental verification team can do something narrower than the scenario FAQ 2083 describes. A CSP stores ePHI on its own servers abroad. A verification team may instead work inside the practice’s own practice management system (PMS) through remote accounts: on that arrangement the system of record stays the practice’s, and what crosses the border is access — a signed-in team member verifying coverage and writing the full benefits breakdown back into the PMS.
Does the narrower arrangement escape the rule? No — and it does not need a loophole, because the rule is not a prohibition. The law firm McDermott Will & Schulte, in a July 1, 2025 analysis of US healthcare offshoring, states the extension plainly: “HIPAA doesn’t prohibit PHI from being accessed or stored outside the US, despite the potential risks.” Note the pairing — accessed or stored. HHS’s own wording covers ePHI “processed or stored” by any business associate outside the United States; the reading that pure remote access sits on the same footing is healthcare counsel’s, and McDermott states it without hedging. Either way the same two conditions apply.
The practical consequence cuts in both directions. A vendor cannot argue that “we only access, we never store” places the arrangement outside the offshore question — the BAA and the risk analysis are owed regardless. And a practice evaluating a vendor should treat “where is our data stored?” and “from where is our data accessed?” as two separate questions deserving two separate written answers, because a vendor can truthfully say “your data stays in your system” while its team reads that system from another country every working day. Both facts belong in the vendor file, in writing.
The condition HHS attaches: a signed BAA, and the offshore location treated as a risk factor
The permission comes with two named conditions, and both predate any question about geography.
The first is the business associate agreement. A verification vendor that touches PHI is a HIPAA business associate, and HHS’s Summary of the HIPAA Security Rule sets the order of operations: “Before permitting a business associate to create, receive, maintain, or transmit ePHI, a regulated entity must have in place a contract or other written arrangement” — the business associate agreement. An overseas team does not change that status or that order. Offshore is not a separate legal category under HIPAA; it is the same business associate relationship with more distance in it, and the agreement comes before the access in every case.
The second is the risk analysis. FAQ 2083 directs covered entities and business associates to “take these risks into account when conducting the risk analysis and risk management required by the Security Rule,” citing 45 CFR §§ 164.308(a)(1)(ii)(A) and (a)(1)(ii)(B). OCR even supplies a worked example: if ePHI is maintained in a country with documented increased hacking or malware attempts, those threats belong in the analysis, and reasonable and appropriate technical safeguards must answer them. The offshore location, in other words, is not a disqualifier — it is a required line item in a document, with safeguards attached to it.
For a dental practice the two conditions convert a legal question into a due-diligence one. “Is this legal?” is answered by HHS. “Has this vendor signed a BAA, and has it treated its own geography as a risk it documents and mitigates?” is answered by the vendor — in writing, or not at all.
Why “permitted” is not “risk-free”: what OCR actually warns about
OCR’s caution names two distinct problems, and they deserve to be read separately rather than blurred into general unease.
The first is the security surface: overseas outsourcing “may increase the risks and vulnerabilities to the information.” Different countries carry different documented threat environments, and OCR’s hacking-attempts example makes clear this is an empirical question about the specific location, to be answered inside the risk analysis — not a blanket verdict on every offshore arrangement.
The second is legal reach: “special considerations with respect to enforceability of privacy and security protections over the data.” A US practice’s leverage over a US vendor runs through US courts and OCR enforcement. Distance complicates both. McDermott is blunter about the consequence: “If a foreign vendor violates HIPAA or experiences a data breach, there is limited recourse unless there are strong, binding, international arbitration provisions, or the foreign vendor maintains a substantial US-based presence.”
Note what that sentence does not say. It does not say offshore vendors fail more often, and it does not say recourse is impossible. It says the recourse is contractual — built into the agreement before the engagement begins, not discovered after a breach. That is why the requirements in the next section put so much weight on what is signed and written down, and why one of them exists purely to give the contract enforcement reach.
A dental practice choosing an offshore verification vendor accepts a real enforceability consideration. The honest posture — for the vendor and for the practice — is to name that consideration and contract for it, not to bury it under a compliance badge.
State law, Medicaid/Medicare, and payer or PMS contracts can restrict it even when HIPAA doesn’t
HIPAA is the federal floor, not the whole map. Above it sit three more layers that can restrict offshore PHI access even where HIPAA permits it: state law, public-program requirements, and the practice’s own contracts. McDermott Will & Schulte’s July 2025 analysis maps that landscape; the rows below are its findings, quoted or summarized, not Dental Revenue Desk’s legal determination.
| Restriction source | What it does, per McDermott Will & Schulte |
|---|---|
| Wisconsin | Prohibits contractors and subcontractors "from performing work outside the US that involves access to or disclosure of patient health and related information." |
| Texas — Uniform Managed Care Contract | Requires managed care organizations to provide all services within the US and keep information "stored and maintained within the United States." |
| Florida — Electronic Health Records Exchange Act | Requires patient information in qualified electronic health records kept in offsite environments to be "physically maintained in the continental US, its territories, or Canada." |
| Arizona, Ohio, Missouri, New Jersey | Offshoring restrictions imposed through regulation or executive order. |
| Medicare Advantage | CMS requires attestations covering the safeguards of offshore subcontractors in Medicare Advantage arrangements, with audit authority behind them. |
| Carrier and network contracts | "Payers and provider networks may include terms that prohibit PHI from leaving US territory or accessing PHI outside the US, or require that subcontractors meet specific additional security requirements." |
Read the table for what it is: none of these rows is a dental-specific rule, and none makes offshore verification broadly illegal. Wisconsin’s bar reaches state contracting; the Texas and Medicare Advantage rows reach managed-care arrangements; Florida’s reaches where qualified electronic health records are physically kept. Whether any row reaches your practice depends on your state, the programs you participate in, and the contracts you have signed — including participation agreements with carriers and the license terms of your own PMS vendor.
That is a question for your compliance reviewer, and Dental Revenue Desk’s published posture says exactly that: state law and your PMS vendor’s agreement may add restrictions of their own; Dental Revenue Desk gives no legal advice and expects your reviewer to check both. A vendor that tells you “HIPAA allows it, so you’re covered” has answered the federal layer and skipped the other three.
What a dental practice should require of an offshore verification vendor
The law above reduces to a short list of things to require in writing — of any offshore vendor, Dental Revenue Desk included. Each item traces to a condition HHS attaches or a gap McDermott documents.
- A business associate agreement signed before any PHI access — trials and pilots included. The BAA is HHS’s non-negotiable condition, not a formality to finish during onboarding. The Security Rule’s order is agreement first, access second.
- Access geography disclosed in writing. Where the team works belongs in your vendor file as a stated fact — not something discovered later. A vendor that will not put its geography in writing has failed the cheapest test on this list.
- A documented access-control design. The Security Rule requires authorizing access to ePHI only when it is appropriate for the user’s role. Ask which account types and permissions are used, who approves them, how activity is logged, and how access is revoked; require evidence for the answers.
- Breach terms with a named clock. Who notifies whom, and how fast, documented in the BAA — the federal notification rule is a floor the agreement can commit to beating.
- Data return, destruction, and permitted-retention terms at termination. The end of the engagement is a PHI event, and the disposition of patient data belongs in the reviewed BAA and service terms.
- Contract reach that survives the distance. McDermott’s best practices for offshore arrangements include binding international arbitration provisions and cyber liability insurance requirements — the contractual answer to the limited-recourse problem above. Ask for both, and ask for the coverage limits in writing.
- An annual review of the arrangement. McDermott recommends auditing offshore subcontracts at least annually; a standing engagement deserves a standing check, not a one-time approval.
Every item converts to a question you can put to a vendor on a discovery call — the call-script version, including what to ask about access scoping, covers the same ground in the order a first conversation actually runs.
How Dental Revenue Desk handles access from outside the US
Dental Revenue Desk is the offshore party this page describes, so the evidence boundary matters. The owner discloses that the delivery team works remotely from Pakistan during US business hours and states that a business associate agreement will be signed before PHI is exchanged. The owner also commits to access controls, MFA, device policies, training, audit logs, and breach procedures. Those are commitments, not proof of implementation. The account model, provisioning and revocation workflow, breach clock, storage, retention, return or destruction terms, contract enforcement, and review cadence remain pending legal and security review before PHI. Our BAA process and access-geography disclosure keeps those open items visible.
This guide states the general law; the security page carries Dental Revenue Desk’s owner-stated commitments and the evidence still missing, so your reviewer can check the one against the other. The proposed controls exist for the sake of the service this protects: the full benefits breakdown a practice receives before the patient reaches the chair.