Resources

Client Alerts, News Articles, Blog Posts, & Multimedia

Everything you need to know about BMD and the industry.

The Risks of Outsourcing Medical Billing and the Importance of State-Law Compliance

Client Alert

Offshoring medical billing and other administrative functions can reduce costs, but it also raises significant compliance, operational, and contractual risks. Although HIPAA does not explicitly prohibit protected health information from being accessed or stored outside the United States, healthcare providers and their vendors remain responsible for safeguarding patient information and complying with state-specific restrictions that may limit or prohibit offshore subcontracting. 

For healthcare organizations, outsourcing billing can create exposure far beyond routine vendor-management issues. If an offshore billing company mishandles protected health information, submits inaccurate claims, or fails to follow applicable payer requirements, the provider, not just the vendor, may face delayed reimbursement, audit scrutiny, breach-response costs, contractual disputes, and reputational harm. 

HIPAA considerations

HIPAA protects protected health information (PHI), including individually identifiable health information maintained or transmitted by covered entities and business associates. Vendors that create, receive, maintain, or transmit PHI on behalf of a covered entity generally qualify as business associates and must comply with HIPAA’s applicable privacy and security obligations. 

At a minimum, organizations should confirm that outsourcing arrangements address:

  • appropriate access controls and role-based permissions;
  • encryption and other reasonable safeguards for PHI;
  • workforce training and documented compliance policies;
  • a compliant Business Associate Agreement (BAA);
  • audit rights, monitoring, and recordkeeping; and
  • clear breach reporting and notification procedures.

State-law and program requirements

HIPAA is only part of the analysis. State Medicaid rules, managed care agreements, provider manuals, executive orders, and other state authorities may impose additional restrictions on offshore subcontracting. In some jurisdictions, these restrictions can require that certain services be performed in the United States or that patient data remain within the country. As a result, a provider may be compliant with HIPAA yet still violate contract or state-specific requirements. 

This risk is especially important because enforcing contractual and privacy obligations against an offshore vendor may be incredibly difficult. When a foreign subcontractor experiences a breach or other compliance failure, the healthcare provider often bears the immediate burden of investigation, remediation, patient notification, and regulator response. 

Practical takeaways

Before outsourcing billing or related administrative functions overseas, providers should:

  • review state statutes, administrative codes, Medicaid guidance, and managed care contract requirements that may apply to the services at issue;
  • confirm whether any payer or provider agreement restricts subcontracting or offshore access to PHI;
  • conduct diligence on the vendor’s technical, administrative, and legal safeguards;
  • negotiate a BAA and service agreement with audit rights, indemnification, reporting obligations, and clear data-security requirements; and
  • implement ongoing monitoring to verify compliance after the arrangement begins.

For questions regarding the individualized risk requirements or assistance with compliance and implementation, please contact Amanda Waesch at alwaesch@bmdllc.com


DHS Ends All Employment Authorization Auto-Extensions

Effective October 30, 2025, DHS ends all automatic work authorization renewals. The 540-day extension applies only to renewals filed before this date, and there is no grace period for expired EADs filed on or after October 30. Employers must audit EADs, train staff, ensure I-9 compliance, and plan for work authorization gaps. Penalties for noncompliance can be severe.

CMS’s Rural Health Funding Announcement

CMS has announced a $50 billion Rural Health Transformation (RHT) Program to improve healthcare access, quality, and outcomes in rural communities. All states are eligible to apply for funding by November 5, 2025. Half of the funds will be distributed equally, with the remainder based on state-specific factors. The program supports evidence-based initiatives, workforce recruitment, and access to treatment services, with awards assessed annually

Expanding Access to Care: Ohio’s Effort to Modernize APRN Practice Through Ohio SB 258 and HB 508

Ohio is moving to expand access to healthcare through Senate Bill 258 and House Bill 508, which would modernize APRN practice by removing the outdated requirement for a physician contract. This change would allow nurse practitioners, nurse midwives, and clinical nurse specialists to provide care more efficiently, especially in underserved areas, while maintaining high-quality, cost-effective care.

Cleveland Joins the Pay Transparency Movement: What Employers Need to Know

Beginning October 27, 2025, all Cleveland employers with 15 or more employees will be prohibited from asking applicants about their pay history and will be required to include reasonable pay ranges in all job postings where the position will be performed, solicited, considered, or processed in Cleveland. The ordinance is intended to help close the gender wage gap and promote greater pay equity across the city.

New $100,000 Fee on H-1B Petitions – Legal Immigration

President Trump issued an Executive Order (EO) imposing a $100,000 payment to accompany any new H-1B visa petitions submitted after 12:01 a.m. eastern time on September 21, 2025 and will remain in place for 12 months (unless extended).