Outpatient Facility Coding Alert - 2019 Issue 3
Reader Question: What Happens to HIPAA When Information Spans Borders?
Subscribe or sign in to view the full article.
Article Overview
This reader Q&A addresses whether HIPAA continues to apply when a practice stores information with a cloud services provider based in another country. It is aimed at healthcare practices, compliance staff, and billing or privacy professionals who need a high-level understanding of cross-border vendor relationships, business associate agreements, and OCR guidance related to privacy, security, breach notification, and enforcement expectations.
Why This Topic Matters
Cross-border storage and processing of health information can create compliance and security concerns even when a vendor is outside the U.S. The article helps readers understand the general regulatory framework and the importance of vendor agreements and federal guidance for handling electronic protected health information.
What You Will Learn
- How HIPAA can apply to vendor relationships involving services hosted outside the United States.
- Why business associate agreements remain relevant in cross-border cloud arrangements.
- What types of federal guidance are mentioned for privacy, security, breach notification, and enforcement topics.
- Why cloud-based handling of electronic protected health information raises compliance attention.
Who Should Read This
- Healthcare practices
- Compliance professionals
- Privacy officers
- Billing staff
- Health information management professionals
- Cloud vendor administrators
Subscribe or sign in to view the full article.



Quick, Current, Complete - www.findacode.com