HIPAA and offshore dental billing: what's actually required
HIPAA does not prohibit offshore vendors. It does make you responsible for choosing one that can prove its controls.
The short version
A vendor handling protected health information on your behalf is a business associate. That triggers a specific set of requirements, and those requirements do not change based on which country the vendor sits in. What changes is how carefully you should verify them.
What is required
A signed Business Associate Agreement
Non-negotiable and legally required before any PHI is shared. It defines permitted uses, safeguard obligations, breach notification duties, and what happens to data at termination. A vendor that hesitates here has answered your question.
Technical safeguards
- Encryption in transit and at rest
- Unique user identification — no shared logins, ever
- Role-based access, so each person sees only what their job requires
- Audit logging on records accessed, retained and reviewable
- Automatic session termination
Administrative safeguards
- Documented policies and procedures
- Workforce HIPAA training, with records proving it happened
- A named security officer
- A written breach notification procedure with defined timelines
- Access revocation on staff departure, executed promptly
Physical safeguards
- Controlled access to the work floor
- A clean-desk policy and restrictions on personal devices
- Device and media controls
What offshore adds
Nothing legally, but two things practically. First, enforcement across borders is harder, so the contractual and technical controls carry more weight. Second, some payer or DSO contracts impose their own restrictions on offshore handling — check yours before assuming HIPAA is the only constraint.
Questions to ask any vendor
- Will you sign our BAA, or do you require yours? Can our counsel review it?
- Is every user uniquely identified, and can you produce an access log for a specific patient record?
- How quickly is access revoked when someone leaves?
- What is your breach notification timeline, in writing?
- Has any third party assessed your controls?
- What happens to our data when we terminate?
A vendor that answers these crisply has thought about it. One that answers vaguely is telling you something useful.
Questions
Is offshore dental billing HIPAA compliant?
It can be. HIPAA does not restrict geography — it restricts how PHI is handled. A compliant offshore vendor with documented controls is safer than a domestic one without them. The burden is on you to verify rather than assume.
Do we need a BAA even for a small vendor?
Yes. The requirement follows the PHI, not the size of the vendor.
What does BDG do here?
Signed BAA with every client, encryption in transit and at rest, role-based access, audit logging on every record touched, documented breach procedure, and staff training with records. Full detail on our Security & HIPAA page.