The question everybody asks second
Is offshore medical billing safe?
It can be, and where it is not, the reason is almost never the one people fear. Here is what HIPAA actually says, and the ten questions to ask any offshore vendor — including us.
The short answer
HIPAA does not prohibit offshore processing. It requires that anybody handling protected health information on a practice’s behalf is a business associate under a signed agreement, and applies the same safeguards a US vendor would. Where offshore work is restricted, the restriction is usually contractual — a payer agreement or a state Medicaid programme — rather than a HIPAA rule, and it has to be checked for your payers rather than assumed either way.
Compliance is a property of how an organization operates, not of where it sits. The controls that decide whether your data is safe are identical onshore and offshore, and so are the ways they fail.
The risk people expect, and the real one
The fear is an attacker in another country. The characteristic failure is far more ordinary: a shared login that makes the audit trail useless, an account still active a month after somebody left, or a screenshot pasted into a chat by a person trying to help a colleague.
Every one of those happens onshore too, at the same rate, for the same reason. Which is why the questions below are about access hygiene rather than about geography.
Ten questions to ask any offshore vendor
Useful whoever you end up buying from. Our own answers are below each one, so you can hold us to the same standard you would hold anybody else.
1. Is there a signed BAA, and does it exist before access?
What a good answer sounds like: Signed before a single credential is issued, never after. A vendor who says "we will get that over to you" while your login is already working has told you what their compliance is worth.
Ours: Before access, always. Access without a BAA is an impermissible disclosure by the practice and a direct violation by us.
2. Does every person have their own login, or does a team share one?
What a good answer sounds like: One account per person. A shared credential destroys the audit trail, which means an investigation can never rule anybody out — including the innocent.
Ours: Named individual logins, always. We will refuse a shared login even when a client offers one to save time.
3. What is the narrowest role that covers the work, and is that what you are asking for?
What a good answer sounds like: A vendor should ask for less access than you expect, and should be able to say which queue each permission is for.
Ours: We ask for the narrowest role that covers the queue. An AR caller needs the claim, the payer and the balance — not the clinical note.
4. How quickly is access removed when somebody leaves?
What a good answer sounds like: Same day, with a written checklist covering every system. In our experience this is the finding that comes up most often in security reviews, and it is entirely within a vendor’s control.
Ours: Same day, against a leaver checklist signed off by IT and HR jointly.
5. Can data leave the building, and what stops it?
What a good answer sounds like: Ask specifically about USB storage, personal email, personal cloud sync and phones at working positions. Most PHI that escapes an organization leaves through a helpful person, not an attacker.
Ours: No personal devices on client systems, no removable storage, and no client data on anything that leaves the floor. Screenshots are the single biggest leak on any BPO floor and are prohibited.
6. Is multi-factor authentication on, and where is it not?
What a good answer sounds like: The honest answer names the systems where it is not available, rather than claiming universal coverage.
Ours: On everywhere it is offered. Where a client system does not support it, that is recorded as a known risk rather than passed over silently.
7. Who is accountable, by name?
What a good answer sounds like: A person, not a department. Ask who you would ring at 2am about a suspected breach.
Ours: Ibtesam Asif, founder, whose profile is public.
8. What happens in the first hour of a suspected breach?
What a good answer sounds like: Report within the hour, contain without destroying evidence, and a four-factor risk assessment documented every time — including when the conclusion is that nothing was compromised.
Ours: Exactly that, and the client hears it from us on the timeline in the BAA. A client who finds out from anybody else does not stay a client, and should not.
9. Are you HIPAA certified?
What a good answer sounds like: This is a trick question, and the right answer is no. No body certifies an organization as HIPAA compliant — there is no such certification. A vendor who claims one has either misunderstood the rule or is hoping you have.
Ours: No, and nobody is. What we can show you is the safeguards, the training records and the BAA.
10. Is offshore processing permitted for my payers and my state?
What a good answer sounds like: A vendor should raise this before you do. HIPAA does not prohibit offshore processing, but some contracts and some state Medicaid programmes restrict it, and it is a per-client question with no general answer.
Ours: We check it before go-live rather than after a denial, and we will tell you if the answer is no.
The one we will not answer for you
Whether your notice of privacy practices requires you to tell patients that billing is handled by a business associate abroad is a question for your own counsel. A vendor who answers it definitively is answering a legal question they are not qualified to answer, and we are not going to be that vendor.
Where we are, said plainly
Soft Home Global operates from Rawalpindi, Pakistan. We say so on the first call rather than at contract stage, because a practice that discovers offshore delivery after signing has been misled whatever the paperwork says — and because being straightforward about it is the only thing that makes the rest of this page worth reading.
Questions
Is offshore medical billing legal in the US?
Yes. HIPAA does not prohibit processing protected health information outside the United States. What it requires is that the offshore party is under a business associate agreement and applies the same safeguards. Separately, some individual payer contracts and some state Medicaid programmes do restrict offshore access to claims data — that is a contractual restriction rather than a HIPAA one, and it has to be checked per client.
Is offshore medical billing HIPAA compliant?
It can be, and compliance is a property of how an organization operates rather than of where it sits. The controls that matter are the same onshore or offshore: a signed BAA before access, named individual logins, least privilege, same-day deprovisioning, encryption, training records and a written risk analysis.
Is there a HIPAA certification an offshore vendor can hold?
No. No government body or accreditor certifies an organization as HIPAA compliant, and there is no such certificate to hold. Any vendor advertising one is describing something that does not exist. What a vendor can show you is its safeguards, its training records, its risk analysis and its BAA.
What is the biggest real risk with offshore billing?
Not what most people fear. The characteristic failure is not an attacker abroad — it is ordinary access hygiene: a shared login that makes the audit trail useless, an account left active after somebody left, or a screenshot pasted into a chat by a person trying to be helpful. Those are the same risks an onshore vendor has, and the same controls fix them.
Should I tell my patients their billing is done offshore?
Your notice of privacy practices governs what you must disclose, and a business associate relationship does not normally require patient-level notification. That is a question for your own counsel rather than for a vendor — and a vendor who answers it definitively is answering a legal question they are not qualified to answer.
Sources
- HHS — Business Associates — What a business associate is, and what the agreement must contain
- HHS — HIPAA Security Rule — Administrative, physical and technical safeguards
- HHS — Breach Notification Rule — The 60-day clock, the 500 threshold and the four-factor assessment
- HHS — Minimum Necessary Requirement
Sources checked September 2026.
Next step
Ask us all ten on a call
Twenty minutes. If an answer is no, we would rather say so before you sign than after.
Or write to ops@softhomeglobal.com

