Compliance & Legal16 min read

Outsourcing for Healthcare: What US Providers Can Delegate — and the HIPAA Spine That Governs It

A neutral guide to the administrative and revenue-cycle functions US healthcare organizations commonly outsource, the HIPAA and Business Associate Agreement obligations that govern every arrangement, the extra rules that apply offshore, and the clinical work that cannot be delegated.

Published August 2026 · RSW Editorial

What This Guide Covers

Outsourcing is deeply established in US healthcare, but it is unusually constrained: almost every function that can be delegated touches protected health information (PHI), which means HIPAA, the Business Associate Agreement, and — for offshore work — a layer of CMS and payer rules sit on top of any staffing decision. This is a neutral, educational overview for US providers, physician groups, hospitals, and health systems weighing outsourced or remote support.

It maps the administrative and revenue-cycle functions that are commonly delegated, sizes the market with cited sources, walks through the compliance spine (HIPAA, BAAs, PHI safeguards, HITECH), covers the extra requirements that attach offshore, and — critically — draws the line at clinical work that cannot be outsourced. It does not recommend any provider or model; it is meant to help you ask the right questions.

What Healthcare Functions Are Commonly Outsourced

The functions US providers most often delegate are administrative and revenue-cycle roles — labor-intensive, rules-heavy work that does not require a US clinical license. Revenue cycle management (RCM) is consistently the largest single category within healthcare business-process outsourcing.

  • Medical billing and claims submission — preparing, scrubbing, and filing claims to payers
  • Medical coding — translating clinical documentation into ICD-10, CPT, and HCC risk-adjustment codes
  • Revenue cycle management (RCM) — eligibility and benefits verification, charge capture, denial management, appeals, payment posting, and patient collections
  • Medical virtual assistants and virtual scribes — administrative support, EHR data entry, inbox and referral management, and drafting clinical notes for a clinician to review and sign
  • Patient scheduling and front-desk phone support — booking, reminders, and intake
  • Medical transcription — converting dictated notes into text
  • Insurance claims processing, prior authorization, and benefits verification
  • Telehealth coordination — scheduling, intake, and technical support around virtual visits

Market Context

The healthcare BPO market is large and growing, though published estimates vary widely by firm and by how each defines the market. Precedence Research valued the global healthcare BPO market at about $466.64 billion in 2025; MarketsandMarkets projects it rising from roughly $417.68 billion in 2025 to about $694.35 billion by 2030 (~10.7% CAGR). Treat any single figure as one firm’s estimate rather than a settled number.

Revenue cycle management is the standout segment. Fortune Business Insights valued the global RCM market at about $163.72 billion in 2025, projecting growth to roughly $472.42 billion by 2034 (~12.75% CAGR), with North America holding about a 49% revenue share in 2025 — consistent with the US being the center of demand.

One documented driver is administrative burden. Reporting on ambient AI scribes at Mass General Brigham found an associated 21.2 percentage-point absolute reduction in clinician burnout (from 52.6% to 30.7%), underscoring how much clinician time documentation consumes — the kind of work practices increasingly move to virtual scribes and assistants.

The Compliance Spine: HIPAA, BAAs, PHI, and HITECH

Any vendor that creates, receives, maintains, or transmits PHI on your behalf is a "business associate" under HIPAA, and you must have a signed Business Associate Agreement (BAA) in place before PHI changes hands. The required contents of a BAA are set out at 45 CFR 164.504(e): it must limit how the vendor uses and discloses PHI, require appropriate safeguards, mandate security-incident and breach reporting, bind subcontractors to equivalent protections, permit HHS oversight, and give you termination rights for material breach.

The business-associate definition (45 CFR 160.103) turns on the function performed, not on geography, so it captures offshore vendors just as it does domestic ones. Under HITECH, business associates — and their subcontractors — carry direct HIPAA liability, not merely contractual exposure to you.

Beyond the paperwork, the covered entity retains real responsibility. HIPAA provides that a covered entity is out of compliance if it knew of a pattern of conduct that materially breached the BAA and failed to take reasonable steps to cure it or terminate. In practice the BAA is a floor, not a substitute for vetting the vendor’s actual safeguards: access controls, encryption, minimum-necessary access, workforce training, and audit rights.

Extra Rules When Work Goes Offshore

HIPAA does not ban sending PHI outside the United States — OCR guidance is that the Privacy and Security Rules simply follow the PHI wherever it is accessed or stored. But offshore arrangements carry additional obligations and practical risks.

For Medicare Advantage, Part D, and many Medicaid lines of business, CMS requires plan sponsors to report offshore-subcontractor details and file a PHI-protection attestation through the HPMS Subcontractor Data module, generally within 30 days of signing the offshore subcontract. "Offshore" means any country other than the 50 states and the US territories. The attestation typically must describe the functions performed, the types of PHI accessed, why the arrangement is necessary, and confirm that safeguards, breach-termination procedures, and annual audits are in place. These payer requirements often flow down to providers through contract terms.

Enforcement reach is the softer spot: while HITECH extends liability to offshore business associates, regulators’ practical ability to pursue an entity with no US presence is limited. That shifts weight onto your own contractual controls, audit rights, and diligence. Several states and payer contracts also impose stricter limits on offshoring Medicaid or beneficiary data — check state Medicaid provider agreements before any PHI leaves the country.

What Cannot Be Outsourced

The bright line is clinical judgment. Diagnosis, treatment selection, prescribing, and the exercise of medical judgment must remain with clinicians who hold the appropriate US state license and practice within their scope. State licensure and scope-of-practice laws, plus corporate-practice-of-medicine doctrines in many states, keep those acts with credentialed professionals and cannot be contracted away to a non-licensed vendor, onshore or offshore.

This shapes how the delegable roles work. A virtual scribe or ambient AI tool can draft a note, but a clinician must review and attest to it. An offshore coder can assign codes, but accountability for accurate billing and the underlying documentation stays with the practice. Prior-authorization staff can gather and submit information, but the clinical rationale originates with the treating provider. The rule of thumb: administrative and information-handling tasks are delegable with a BAA; medical decisions are not.

How to Do It Safely

The following is a neutral checklist of controls US healthcare buyers commonly put in place. None of it substitutes for review by your own privacy officer and counsel.

  • Execute a compliant BAA meeting all 45 CFR 164.504(e) elements before any PHI is shared, and flow equivalent terms down to subcontractors
  • Apply the minimum-necessary principle — give the vendor access to the least PHI required for the task
  • Verify technical safeguards independently: encryption in transit and at rest, role-based access controls, logging, and multi-factor authentication
  • For offshore work, confirm CMS offshore-attestation obligations, file within required timelines, and check state Medicaid and payer-contract restrictions
  • Reserve and exercise audit rights; require security-incident and breach notification within defined timeframes
  • Keep clinical decision-making with licensed clinicians and require clinician review/sign-off on any documentation a vendor drafts
  • Confirm workforce HIPAA training and background-check practices on the vendor side
  • Build in material-breach termination rights and a data-return/destruction plan at contract end

Cost Context

Cost is a common motivation, but published figures are largely vendor estimates rather than independent data, so treat them cautiously. Industry blogs put fully-loaded offshore coding FTEs at roughly $14,000–$22,000 per year in India and $18,000–$26,000 in the Philippines, versus US-based certified coders quoted at $5,000–$7,500+ per month fully loaded, with claimed total savings of 55–65% — figures published by outsourcing firms and not independently verified here.

The durable point is not the exact percentage but the trade-off: any cost advantage has to be weighed against the compliance overhead (BAAs, attestations, audits), the added enforcement risk of offshore data handling, and the reputational cost of a PHI breach. A cheaper arrangement that fails a HIPAA audit or triggers a breach can erase the savings many times over.

By the Numbers

The figures below carry their named source; market-size estimates vary by firm and definition, so treat any single number as directional.

  • Global healthcare BPO market valued at ~$466.64 billion in 2025. (Precedence Research, 2025)
  • Healthcare BPO projected to grow from ~$417.68B (2025) to ~$694.35B by 2030 (~10.7% CAGR). (MarketsandMarkets, 2025)
  • Global revenue cycle management market ~$163.72B in 2025, projected ~$472.42B by 2034 (~12.75% CAGR); North America ~49% share in 2025. (Fortune Business Insights, 2025)
  • A BAA meeting the elements of 45 CFR 164.504(e) is required before a business associate handles PHI. (HHS.gov, 2024)
  • CMS requires plan sponsors to submit offshore-subcontractor info and a PHI attestation via the HPMS module within 30 days of signing an offshore subcontract; "offshore" = any country other than the 50 states and US territories. (CMS offshore attestation requirements, 2025)
  • Ambient AI scribe use at Mass General Brigham was associated with a 21.2 percentage-point absolute reduction in clinician burnout (52.6% → 30.7%). (Medscape / reported study, 2025)
  • ESTIMATE (vendor-published): fully-loaded offshore coding FTEs ~$14k–$22k/yr (India) and ~$18k–$26k/yr (Philippines) vs US certified coders ~$5k–$7.5k+/mo, with claimed 55–65% savings. (Staffingly (vendor blog), 2026)

A medical virtual assistant or scribe is really a specialized virtual assistant operating inside a HIPAA perimeter — the tasks-to-outsource-to-a-virtual-assistant guide covers the delegation and security fundamentals that still apply. For the compliance vocabulary, see statutory benefits and BPO.

Frequently Asked Questions

Can US healthcare providers legally outsource work that involves patient data?
Yes. HIPAA permits sharing PHI with a vendor to perform administrative, billing, or operational functions, provided you sign a Business Associate Agreement (BAA) meeting 45 CFR 164.504(e) before any PHI changes hands and the vendor implements appropriate safeguards. The covered entity remains responsible for oversight.
Is it legal to send PHI offshore?
HIPAA does not prohibit processing PHI outside the US — the Privacy and Security Rules continue to apply wherever the PHI is accessed. However, offshore work triggers additional obligations: for Medicare Advantage, Part D, and many Medicaid programs, CMS requires an offshore-subcontractor filing and PHI attestation (generally within 30 days of signing), and some states and payer contracts restrict offshoring beneficiary data. Enforcement reach against purely offshore entities is also limited, which raises the importance of your own contractual and audit controls.
What healthcare work cannot be outsourced?
Clinical decision-making — diagnosis, treatment selection, prescribing, and the exercise of medical judgment — must stay with clinicians holding the appropriate US state license and practicing within their scope. State licensure, scope-of-practice, and corporate-practice-of-medicine rules prevent delegating those acts to a non-licensed vendor. A vendor can draft a note or assign codes, but a licensed clinician must review and take responsibility.
What is a Business Associate Agreement (BAA) and why does it matter?
A BAA is the HIPAA-required contract between a covered entity and any vendor handling PHI on its behalf. Under 45 CFR 164.504(e) it must limit how the vendor uses and discloses PHI, require safeguards, mandate breach and security-incident reporting, bind subcontractors to equivalent terms, permit HHS oversight, and give termination rights for material breach. It is the legal foundation of compliant healthcare outsourcing — but a floor, not a substitute for vetting the vendor’s actual security.
Which healthcare functions are most commonly outsourced?
Revenue cycle management (the largest category), medical billing and coding, medical virtual assistants and scribes, patient scheduling and front-desk phone support, medical transcription, claims processing, and prior-authorization/benefits verification. These are administrative and information-handling tasks that do not require a US clinical license — unlike diagnosis and treatment, which cannot be delegated.
How reliable are the cost-savings figures for offshore medical outsourcing?
Treat them cautiously. Most published figures come from outsourcing vendors’ own marketing rather than independent research. Commonly cited numbers put offshore coding FTEs at roughly $14,000–$26,000 per year versus US certified coders at $5,000–$7,500+ per month, with claimed savings of 55–65% — but these are vendor estimates. Any cost advantage should be weighed against compliance overhead, offshore enforcement risk, and the potentially large cost of a PHI breach.