General Surgery Coding Alert - 2020 Issue 8
Reader Questions: Does HIPAA Apply to Contractor Outside US?
Subscribe or sign in to view the full article.
Article Overview
This brief reader question and answer addresses HIPAA compliance considerations for a business arrangement with a cloud services provider based in Canada. It explains the general regulatory context for electronic protected health information, business associate agreements, and the privacy, security, breach notification, and enforcement rule framework referenced by HHS OCR. The article is aimed at organizations and compliance staff evaluating vendor relationships that involve health information and cross-border hosting or processing.
Why This Topic Matters
It helps covered entities and their partners understand that location alone does not remove HIPAA-related responsibilities and that vendor oversight remains important when ePHI may be processed or stored outside the United States.
What You Will Learn
- How HIPAA applies in a vendor arrangement involving a non-U.S. cloud provider
- Why business associate agreements are part of the discussion for cloud vendors handling health information
- What general oversight concerns arise when ePHI is stored or processed outside the United States
- Which HIPAA rule categories are referenced in the compliance discussion
Who Should Read This
- Covered entities
- Business associates
- Healthcare compliance staff
- Privacy and security officers
- Healthcare administrators
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com