Resources

Client Alerts, News Articles, Blog Posts, & Multimedia

Everything you need to know about BMD and the industry.

The Risks of Outsourcing Medical Billing and the Importance of State-Law Compliance

Client Alert

Offshoring medical billing and other administrative functions can reduce costs, but it also raises significant compliance, operational, and contractual risks. Although HIPAA does not explicitly prohibit protected health information from being accessed or stored outside the United States, healthcare providers and their vendors remain responsible for safeguarding patient information and complying with state-specific restrictions that may limit or prohibit offshore subcontracting. 

For healthcare organizations, outsourcing billing can create exposure far beyond routine vendor-management issues. If an offshore billing company mishandles protected health information, submits inaccurate claims, or fails to follow applicable payer requirements, the provider, not just the vendor, may face delayed reimbursement, audit scrutiny, breach-response costs, contractual disputes, and reputational harm. 

HIPAA considerations

HIPAA protects protected health information (PHI), including individually identifiable health information maintained or transmitted by covered entities and business associates. Vendors that create, receive, maintain, or transmit PHI on behalf of a covered entity generally qualify as business associates and must comply with HIPAA’s applicable privacy and security obligations. 

At a minimum, organizations should confirm that outsourcing arrangements address:

  • appropriate access controls and role-based permissions;
  • encryption and other reasonable safeguards for PHI;
  • workforce training and documented compliance policies;
  • a compliant Business Associate Agreement (BAA);
  • audit rights, monitoring, and recordkeeping; and
  • clear breach reporting and notification procedures.

State-law and program requirements

HIPAA is only part of the analysis. State Medicaid rules, managed care agreements, provider manuals, executive orders, and other state authorities may impose additional restrictions on offshore subcontracting. In some jurisdictions, these restrictions can require that certain services be performed in the United States or that patient data remain within the country. As a result, a provider may be compliant with HIPAA yet still violate contract or state-specific requirements. 

This risk is especially important because enforcing contractual and privacy obligations against an offshore vendor may be incredibly difficult. When a foreign subcontractor experiences a breach or other compliance failure, the healthcare provider often bears the immediate burden of investigation, remediation, patient notification, and regulator response. 

Practical takeaways

Before outsourcing billing or related administrative functions overseas, providers should:

  • review state statutes, administrative codes, Medicaid guidance, and managed care contract requirements that may apply to the services at issue;
  • confirm whether any payer or provider agreement restricts subcontracting or offshore access to PHI;
  • conduct diligence on the vendor’s technical, administrative, and legal safeguards;
  • negotiate a BAA and service agreement with audit rights, indemnification, reporting obligations, and clear data-security requirements; and
  • implement ongoing monitoring to verify compliance after the arrangement begins.

For questions regarding the individualized risk requirements or assistance with compliance and implementation, please contact Amanda Waesch at alwaesch@bmdllc.com


OAAPN | Year In Review: 2026 Ohio Board of Nursing and Ohio Law Rules

Find out key changes to Ohio law and the Ohio Board of Nursing rules that have directly impacted APRN practice over the past year, including Psychiatric Inpatient Documents, Intimate Examinations, Signature Authority, Duties Related to Fetal Death, Retail IV Therapy Clinics, Release from Permanent Restrictions, Disciplinary Action, Course on Drugs and Prescriptive Authority, Overdose Reversal Drugs, Office Based Opioid Treatment, Withdrawal Management for Substance Use Disorder, Safe Haven Program, and more.

Ohio House Bill 537: Proposed Regulations for Midwives and Birthing Centers

House Bill 537, introduced in the Ohio House of Representatives, proposes a comprehensive regulatory framework for certified nurse-midwives, certified midwives, licensed midwives, and traditional midwives. The legislation would clarify scope of practice, establish licensure standards, and impose new requirements for freestanding birthing centers and home births. Healthcare providers and facilities should be aware of the proposed changes and their potential operational impact.

Proposed Health Information Privacy Reform Act Expands Protections Beyond HIPAA

The Health Information Privacy Reform Act (HIPRA) seeks to extend privacy protections to health data not covered under HIPAA, including data collected by apps and wearables. HIPRA introduces broader definitions of protected health information, strengthens privacy and security requirements, establishes patient notification rights, and sets national de-identification standards. Companies processing health data should monitor developments to ensure compliance.

Medicare Updates on Skin Substitutes: LCDs Withdrawn, Payment Changes Take Effect

Medicare’s planned Final Local Coverage Determinations (LCDs) for skin substitutes were withdrawn in late December 2025, meaning previous coverage rules remain in effect. The 2026 Medicare Physician Fee Schedule introduces a single payment rate of approximately $127.14 for these products. Providers should review implications for diabetic foot and venous leg ulcer treatments.

Understanding the Seven Core Elements of an Effective Healthcare Compliance Program

The Affordable Care Act requires healthcare providers participating in Medicare, Medicaid, and CHIP to maintain an effective compliance program. Guidance from the Department of Health and Human Services and the Office of Inspector General outlines seven core elements that form the foundation of these programs, from written policies and compliance oversight to auditing, training, and corrective action. This alert highlights each element and explains how practices can tailor compliance programs to their size and risk profile while meeting federal expectations.