Resources

Client Alerts, News Articles, Blog Posts, & Multimedia

Everything you need to know about BMD and the industry.

The Risks of Outsourcing Medical Billing and the Importance of State-Law Compliance

Client Alert

Offshoring medical billing and other administrative functions can reduce costs, but it also raises significant compliance, operational, and contractual risks. Although HIPAA does not explicitly prohibit protected health information from being accessed or stored outside the United States, healthcare providers and their vendors remain responsible for safeguarding patient information and complying with state-specific restrictions that may limit or prohibit offshore subcontracting. 

For healthcare organizations, outsourcing billing can create exposure far beyond routine vendor-management issues. If an offshore billing company mishandles protected health information, submits inaccurate claims, or fails to follow applicable payer requirements, the provider, not just the vendor, may face delayed reimbursement, audit scrutiny, breach-response costs, contractual disputes, and reputational harm. 

HIPAA considerations

HIPAA protects protected health information (PHI), including individually identifiable health information maintained or transmitted by covered entities and business associates. Vendors that create, receive, maintain, or transmit PHI on behalf of a covered entity generally qualify as business associates and must comply with HIPAA’s applicable privacy and security obligations. 

At a minimum, organizations should confirm that outsourcing arrangements address:

  • appropriate access controls and role-based permissions;
  • encryption and other reasonable safeguards for PHI;
  • workforce training and documented compliance policies;
  • a compliant Business Associate Agreement (BAA);
  • audit rights, monitoring, and recordkeeping; and
  • clear breach reporting and notification procedures.

State-law and program requirements

HIPAA is only part of the analysis. State Medicaid rules, managed care agreements, provider manuals, executive orders, and other state authorities may impose additional restrictions on offshore subcontracting. In some jurisdictions, these restrictions can require that certain services be performed in the United States or that patient data remain within the country. As a result, a provider may be compliant with HIPAA yet still violate contract or state-specific requirements. 

This risk is especially important because enforcing contractual and privacy obligations against an offshore vendor may be incredibly difficult. When a foreign subcontractor experiences a breach or other compliance failure, the healthcare provider often bears the immediate burden of investigation, remediation, patient notification, and regulator response. 

Practical takeaways

Before outsourcing billing or related administrative functions overseas, providers should:

  • review state statutes, administrative codes, Medicaid guidance, and managed care contract requirements that may apply to the services at issue;
  • confirm whether any payer or provider agreement restricts subcontracting or offshore access to PHI;
  • conduct diligence on the vendor’s technical, administrative, and legal safeguards;
  • negotiate a BAA and service agreement with audit rights, indemnification, reporting obligations, and clear data-security requirements; and
  • implement ongoing monitoring to verify compliance after the arrangement begins.

For questions regarding the individualized risk requirements or assistance with compliance and implementation, please contact Amanda Waesch at alwaesch@bmdllc.com


Update on Temporary Protected Status (TPS) for Haiti and Related Countries

USCIS has temporarily extended Employment Authorization Documents (EADs) for certain Temporary Protected Status (TPS) beneficiaries from Haiti and several other countries following recent court action. Employers and TPS recipients should review EAD expiration dates, monitor ongoing developments, and ensure compliance with Form I-9 and E-Verify requirements.

HHS Accessibility Requirements for Medical Diagnostic Equipment: What Health Care Providers Need to Know

Health care providers that receive federal financial assistance are now subject to updated HHS accessibility requirements for medical diagnostic equipment under Section 504 of the Rehabilitation Act. With the July 8, 2026, compliance deadline in effect, covered providers should ensure they have the required accessible equipment, train staff, and review operational practices to reduce compliance risk and provide accessible care for patients with disabilities.

Florida Super Lawyers® Recognizes Brennan Manna Diamond Attorneys to the 2026 Lists

BRENNAN, MANNA & DIAMOND is proud to announce that three of our attorneys have been designated to the 2026 Florida Super Lawyers® and Florida Rising Stars® lists. Super Lawyers is based on multiple categories of independent research and peer evaluation to identify outstanding lawyers.

Supreme Court Clears Path for TPS Terminations: What Employers Need to Know

The U.S. Supreme Court's June 25, 2026 decision in Mullin v. Doe and Trump v. Miot removed legal obstacles that had delayed the termination of Temporary Protected Status (TPS) for Haiti and Syria. The ruling also reinforces the administration's authority to terminate other TPS designations currently under review. Employers should immediately identify workers whose employment authorization is tied to affected TPS programs, review Form I-9 records, and prepare for forthcoming USCIS guidance before taking any employment action.

Risks of Using AI-Generated, Implied Celebrity Endorsements in Advertising

Businesses using AI-generated celebrity images, videos, or voice simulations in advertising may face significant legal risks if the content falsely implies an endorsement, affiliation, or sponsorship. This article discusses potential exposure under false advertising, right of publicity, consumer protection, and professional conduct laws, and explains why disclaimers may not be enough to avoid liability.