Full Scale named to the Inc. 5000 for the 5th time

    HIPAA-Compliant Software Development: Offshore Compliance Concerns

    Matt Watson
    By Matt Watson · CEO of Full Scale, 4x Founder, Author of Product Driven
    11 min read
    A comparison chart contrasts ineffective HIPAA certification questions with effective questions about handling PHI and working in specific environments, highlighting practical assessment over certification.
    In this article

    QUICK ANSWER

    No government body certifies a HIPAA-compliant software development company, so a vendor’s compliance badge is self-graded. What matters is the engagement structure. Offshore engineers working under your direct control count as your workforce, which means your compliance program governs them. At Full Scale, the controls are set by the client, not by us.

    Health and Human Services will not certify anyone as HIPAA compliant. Not a hospital, not a software company, not us. There is no federal registry, no seal, no audit that ends with a certificate you can hang on a wall.

    That single fact should change how you shop for an offshore development partner, because the badge you’re being sold is a company grading its own homework.

    Full Scale isn’t HIPAA certified either, and that isn’t modesty. The certificate doesn’t exist.

    You’re not buying a compliant vendor, you’re extending your own compliance program to people in another country.

    Nobody certifies a HIPAA-compliant software development company

    HHS says this in writing. Its guidance on misleading marketing claims states that the department does not endorse or recognize private organizations’ certifications, and adds the part that should worry you more: those certifications “do not absolve covered entities of their legal obligations.”

    Read that again with your buyer hat on. You can hire the most decorated vendor on the internet, get breached, and still be the one the Office for Civil Rights investigates.

    There are real security artifacts. A SOC 2 Type II report and a HITRUST certification are genuine third-party audits, and plenty of good vendors hold them. But neither one is a HIPAA certification, because no such thing exists. They’re evidence about a company’s controls, not a legal shield for yours.

    I had Darren Gallop, the CEO of Carbide, on Startup Hustle a while back to talk about security for growing companies, and he gave the best explanation of enforcement I’ve heard. After a breach there’s mandatory reporting and an investigation. It’s like a car accident, he said. If you were driving the speed limit, your car was inspected, you had your papers, and you weren’t texting, it still stinks, but you walk out of it looking very different than if you’d had seven beers and your car wasn’t inspected.

    Nobody certifies your driving. After the crash, they look at what you were actually doing.

    Three myths about HIPAA compliance badges paired with the facts. HHS certifies nobody, so a badge is self-graded. OCR investigates the covered entity, not the vendor. SOC 2 is a real audit but it is not HIPAA certification.

    Two ways to hire offshore engineers, two completely different answers

    Before you evaluate a single vendor, work out which of these two things you’re actually buying, because it decides everything else.

    When you bring on offshore engineers who work under your direction, on your systems, in your sprints, they aren’t an outside company touching your data. They’re your workforce. HIPAA defines workforce as employees, volunteers, trainees, “and other persons whose conduct, in the performance of work for a covered entity or business associate, is under the direct control of such covered entity or business associate, whether or not they are paid.”

    Whether or not they are paid by you. That clause is doing a lot of work. A contractor in Cebu taking direction from your engineering manager sits inside the same definition as the developer at the desk down the hall from you, which means your training, your access policies, your audit logs, and your sanctions policy govern them both.

    Now compare that to handing a project to a firm that builds it on their own laptops, in their own cloud, and hands you a finished product. That firm creates, receives, and maintains PHI on your behalf. It’s a business associate, and since the 2013 HIPAA Omnibus Rule implemented HITECH, business associates are directly liable for the Security Rule. Their program matters enormously, because their program is the one running.

    You could hire the same engineers in the same country at the same hourly rate and land in a completely different compliance position depending on which of those two you signed. That’s why the difference between staff augmentation and outsourcing stops being a vocabulary argument the moment PHI is involved.

    Most buyers never make this distinction, which is how you end up interrogating a staff augmentation provider about their internal compliance program when the honest answer is that your program is the one that applies. If you’re not sure which model you’re buying, the difference between staff augmentation and a scoped SOW project is the cleanest place to sort it out, and it maps almost exactly onto the workforce-versus-business-associate line.

    Definition card for workforce under 45 CFR 160.103: employees, volunteers, trainees, and other persons whose conduct, in the performance of work for a covered entity, is under the direct control of such covered entity, whether or not they are paid.

    What HIPAA actually requires from the software

    None of the above means the technical work is optional. The Security Rule’s requirements are the floor for any product that stores or moves PHI, and they’re the same whether the engineer writing the code lives in Kansas or Cebu. Every team we staff on healthcare software builds against this list.

    RequirementWhat it means in the codebase
    Access controlUnique user IDs, role-based permissions, least privilege by default
    AuthenticationMFA on anything that reaches PHI, plus automatic session logoff
    EncryptionTLS in transit, strong encryption at rest, including backups
    Audit controlsLogs of who accessed which record and when, retained six years
    IntegrityDetection of improper alteration or destruction of records
    Transmission securityNo PHI in URLs, logs, analytics payloads, or error trackers
    Risk analysisA living assessment, not a template someone filled out once

    That last row is the one teams fake most often. A risk analysis you did in 2023 and never touched again is worse than useless, because it documents that you knew to do it and then stopped.

    The one that quietly burns healthcare startups is transmission security, specifically PHI leaking into places nobody thinks of as storage: application logs, error monitoring, product analytics, and the screenshots people paste into support tickets. Whether your engineers are local or offshore has nothing to do with any of that, but code review discipline does.

    Checklist of what the HIPAA Security Rule requires from software: access control, authentication, encryption, audit controls, integrity, transmission security, and risk analysis.

    The controls that matter belong to the client, not the vendor

    Here’s what our healthcare engagements actually look like at Full Scale, and it’s the answer I’d want if I were the one buying.

    There is no Full Scale HIPAA setup. There’s no standard package, no compliance module we bolt onto an engagement. It varies from client to client, every single time.

    Some clients put our engineers on remote desktops so nothing ever lands locally. Some run everything through a VPN into their environment. Some push us through their own SSO with their own conditional access rules. Some keep production data out of reach entirely and give the team synthetic or de-identified data to develop against, which is the cleanest answer available and the one I’d push for first. And some ship physical equipment to the Philippines with an extremely specific security build already installed, because their security team wants to control the machine down to the disk image.

    Our IT manager works directly with the client’s security people to implement whatever they require. That’s the whole model. We don’t arrive with a compliance program and ask the client to trust it. The client’s program is the program, and our job is to make our people fit inside it. That’s true whether the team is building a telemedicine platform or maintaining a claims pipeline nobody outside the company will ever see.

    Building an offshore team?

    Full Scale staffs senior engineers in the Philippines who work as part of your team — not a vendor.

    The real question is whether PHI ever touches their laptop.

    If the answer is no, because the work happens on a remote desktop inside the client’s environment, most of the offshore anxiety on the internet evaporates. If the answer is yes, the passport of the person holding the laptop is far less interesting than what’s configured on it.

    The workforce framing has a second consequence people miss: your compliance program now covers people you didn’t personally hire or vet. That’s a real gap, and it’s why our vetting isn’t a marketing line. Every Full Scale employee goes through a detailed background check run by an independent Philippine investigations firm, not a self-attested questionnaire we grade ourselves.

    Sign the BAA anyway

    Full Scale has signed BAAs. I’d recommend you ask for one even after everything above.

    The reason isn’t that a Business Associate Agreement makes anyone compliant. It doesn’t, and a vendor who implies otherwise is telling you something about themselves. The reason is that “direct control” is a legal test, not a bright line, and reasonable privacy officers land on different sides of it depending on how an engagement is actually run. The document costs nothing, and it forces both sides to write down who is responsible for what before there’s an incident to argue about.

    We had a client that absolutely required us to be SOC 2 certified. We didn’t pursue it, because our engagements sit inside our clients’ security scope and that’s where the controls were already being enforced. That’s the honest version of this argument, cost included, rather than me telling you certifications are worthless from a company that happens not to have one.

    If you want the wider version of this conversation, the terms worth pinning down before any engagement starts are in our breakdown of staff augmentation contract terms.

    HIPAA is silent on geography, but CMS and Medicaid are not

    Here’s the trap that catches sophisticated buyers.

    HIPAA itself contains no offshore prohibition. There’s no clause banning PHI from crossing a border, no approved-country list, nothing. On the federal privacy statute alone, a developer in Manila and a developer in Minneapolis are treated identically, which is worth knowing before you pay a premium for nearshore over offshore on compliance grounds that don’t exist.

    Your other obligations may not be so relaxed.

    If you’re a Medicare Advantage or Part D plan, or a downstream entity for one, CMS requires an offshore subcontractor attestation filed through the Health Plan Management System within 30 days of signing. It has to describe what PHI goes offshore, the safeguards protecting it, and your audit arrangements. It also asks you to explain why the offshore arrangement was necessary and what alternatives you rejected, which is a question worth having an answer to before you’re typing it into a federal system.

    State Medicaid programs set their own terms, and a few of them are stricter. When HHS’s Office of Inspector General surveyed all 56 Medicaid agencies about offshore outsourcing, it confirmed there is no federal regulation prohibiting the practice, and found that only 15 agencies had any offshore-specific requirement at all. Four banned it outright. The other 52 did not.

    That’s worth sitting with, because it’s the opposite of the impression you’d get from the average vendor page. Offshore restrictions on health data are the exception, not the rule, and they live in specific contracts rather than in the statute. The OIG review is from 2014 and covers administrative functions rather than development work, so don’t treat it as a current list. Treat it as a reason to read your own state agreement instead of assuming a ban that probably isn’t there.

    You can be perfectly HIPAA-correct and still in breach of your CMS or Medicaid obligations. Check the contract, not just the statute.

    OCR fines you, not your vendor.

    Statistic card. 52 of 56 state Medicaid agencies have no offshore ban. HHS OIG surveyed all 56 agencies and just 4 banned offshore outright.

    What to actually ask an offshore vendor

    Swap the certification question for these. They’re the ones that produce useful answers, and a vendor who can’t answer them quickly has told you something.

    • Which model am I buying, staff augmentation or an outsourced project? Everything else depends on it. If they can’t say cleanly, assume they’ll pick whichever answer is convenient for them after a breach.
    • Will PHI ever exist on an engineer’s local machine? Push for no, and ask how it’s enforced rather than promised.
    • Can these engineers work inside my environment, on my SSO, with my access rules? This is the single most useful question on the list.
    • Can we develop against synthetic or de-identified data? Frequently yes, and frequently nobody asks.
    • Who vets these people, and how? Ask whether the check is third-party or self-reported.
    • How fast does access get revoked when someone rolls off? Same-day is the only good answer, and it’s a question about their process, not their paperwork.
    • Will you sign a BAA? Not because it confers compliance. Because a hesitation here is informative.
    • Do my CMS or state Medicaid contracts restrict offshore PHI access? That one’s for your counsel, not the vendor, and it’s the one people skip.

    Notice that none of these ask whether the vendor is compliant. Compliance isn’t a property a company has. It’s a set of controls somebody operates, and in staff augmentation, that somebody is you.

    For what it’s worth, offshore has never been the blocker in a healthcare deal for us. By the time a company is seriously evaluating offshore engineers for a product with PHI in it, they generally understand their own security obligations well. The controls get identified, they get implemented, and the team gets to work. The hard part is always the operational detail, never the geography.

    If you’re staffing a team for regulated healthcare work, Full Scale places senior engineers who have shipped under exactly these constraints, including EHR and EMR systems and patient-facing apps. We’ve been staffing US software companies since 2018, and our engineers work under your leadership, inside your environment, on your rules. If you want to talk through what that would look like against your own security requirements, book a call and bring your security team.

    Frequently asked questions

    Does HIPAA allow offshore development resources?

    Yes. HIPAA contains no geographic restriction on where protected health information may be accessed or stored, and no prohibition on offshore contractors. Other obligations can restrict it, though: CMS requires offshore subcontractor attestations for Medicare Advantage and Part D, and a small number of state Medicaid agencies prohibit offshore outsourcing through their own contract terms. When HHS’s Office of Inspector General surveyed all 56 Medicaid agencies, only four had an outright ban.

    Can HIPAA PHI be stored offshore?

    Under HIPAA itself, yes, provided the Security Rule safeguards are in place. The stronger approach is to avoid the question entirely by keeping PHI inside your own environment and having offshore engineers work through remote desktops or VPN access, so nothing is ever stored on their machines.

    Is there a HIPAA certification for offshore employees?

    No. HHS does not certify any person, company, or product as HIPAA compliant, and it states that private certifications do not absolve covered entities of their legal obligations. Individual HIPAA training certificates exist and are worth having, but they certify that someone completed a course, not that an organization is compliant.

    Do you need a BAA with an offshore development vendor?

    Full Scale has signed BAAs, and it’s worth requesting one. If the engineers work under your direct control they may qualify as your workforce rather than a business associate, but “direct control” is a legal test rather than a bright line, so the agreement is cheap insurance that also forces both parties to document responsibilities up front.

    What are the HIPAA restrictions on offshore contractors?

    HIPAA imposes none specific to offshore contractors. The restrictions that actually bite come from elsewhere: CMS offshore subcontractor attestation requirements for Medicare Advantage and Part D plans, state Medicaid contract terms, and your own customer agreements, which frequently contain data-residency clauses stricter than any federal rule.

    Ready to add senior engineers to your team?

    Book a 15-minute call. Tell us your stack and where the gaps are, and we'll show you the engineers we'd put on your team.