Security
What to actually ask about offshore data security
HIPAA does not prohibit offshore work. What it requires is specific, and most vendor security pages answer a different question.
The short answer
HIPAA contains no geographic restriction. A covered entity may use a business associate outside the United States, provided a Business Associate Agreement is in place and the required safeguards are met.
Some state laws and some individual payer contracts do restrict it. Those are worth checking, and they are a different question from whether HIPAA permits it.
There is no such thing as HIPAA certification
No government body certifies anyone against HIPAA. There is no register, no audit body, no badge. A vendor showing you a HIPAA certificate has bought a logo from a training company.
That matters beyond the badge itself: you have just watched them present something unverifiable as evidence. Assume the same standard applies to their other claims.
Questions that produce a real answer
Will you sign a BAA before anyone gets a login? Before, not after the first week.
Does each person have a named individual account in our system? A shared login means an audit trail that cannot name a person, which is not an audit trail.
Is any of our data copied to your systems? The only genuinely safe answer is no. If they mirror data, ask where it is stored, who administers it, and what happens to it when you leave.
What happens the day somebody leaves your company? Access should end that day and be confirmed in writing, and you should be able to revoke it yourself because the credential is yours.
What are the physical controls? Phones at the desk, removable media, printing, personal email. Ask specifically. Vague answers here are answers.
The honest limit
No vendor, onshore or offshore, can promise that a determined person cannot memorise a screen. Anyone who claims otherwise is selling. What a good vendor can promise is that accounts are named, access is minimal, the floor is supervised, and every change is recorded — so that if something did go wrong you could prove who, when and what. That is what an auditor asks for.
Where this connects
More from the same desk
- Twelve questions to ask any offshore billing vendor
- Days in AR: what the number hides and how to move it
- How to write an appeal letter that actually gets a claim reopened
- Stop Gastroenterology Revenue Leakage Before It Hurts Your Bottom Line
- Provider Enrollment & Revalidation Calendar
- Underpayment Recovery & Contract Variance
Next step
One seat. One month. Cancel any time.
Twenty minutes on a call is enough to tell whether this fits. If it does not, I will say so.
Or write to ops@softhomeglobal.com

