Texas Protects Your Medical Records. Your Job's Insurance Doesn't.
Somewhere outside the United States, a man with administrative access to an American health insurer's systems is looking at a screen full of patient records. Names. Dates of birth. Member identification numbers. Diagnoses. Years of claims.
He may be at his kitchen table, on home wifi, with his phone beside him. He may be in a windowless facility that took a badge and a fingerprint to enter, where the phone cameras are taped over and nothing reaches the outside internet.
No federal rule distinguishes between those two rooms. None has ever been written.
For nearly three decades, the Health Insurance Portability and Accountability Act has been the public's shorthand for medical privacy, invoked at every pharmacy counter and on every clipboard. What the law says about the physical circumstances in which health
records are actually viewed amounts to a single sentence, and that sentence requires almost nothing.
The provision is 45 CFR 164.310(b). It obliges a covered organization to maintain
policies describing "the physical attributes of the surroundings" of any workstation
that can reach electronic health information. It does not say what those attributes should be. It sets no minimum. It names no control. A secured operations center and a laptop on a sofa satisfy the requirement equally, so long as a document somewhere describes each arrangement.
The rule was written in 2003, when remote access to a health plan's production systems was rare and mostly stationary. It was last substantively amended in 2013. It has not been revisited since the work of maintaining American health data became something that can be done from anywhere on earth with a broadband connection.
What federal law does not require is easier to state than what it does. There is no
requirement for multi-factor authentication on systems holding patient records. No requirement for a controlled or supervised workspace. No restriction on access from a private residence, or from outside the United States, or on privileged administrative access from a foreign country. No prohibition on cameras in the room where records are displayed. And no obligation to tell patients, or even the insurer's own corporate customers, that their records can be reached from abroad.
Each of those decisions belongs entirely to the company. Some organizations impose all of them. Others impose none. Under current law, both are in compliance.
Nor does it matter, legally, who employs the person at the keyboard. Much of the
oversight that does exist was designed around outside vendors: the written agreements a hospital or insurer must sign with a business associate, the assessments it performs before hiring one, the attestations required when a Medicare plan hands work to a subcontractor abroad. None of that machinery engages when the person is on the company's
own payroll.
American insurers and health technology firms have spent two decades building wholly owned subsidiaries overseas, employing tens of thousands of engineers directly. Those engineers are workforce, not business associates. No agreement is required between a company and its own staff. The nationality of the employee is irrelevant to the law, as it should be. What is not irrelevant, and what no rule addresses, is that the entire apparatus of third-party scrutiny simply does not apply to the arrangement that has become the most common one.
There is one exception, and its origin is telling. The strictest rule anywhere in the
country governing where American health records may be handled was not written by a privacy regulator. It was written by a state purchasing office.
Texas requires, through the contract every managed care organization must sign to do business with its health and human services agency, that work be performed and information maintained inside the United States. The same contract bars remote access to the state's systems and data from offshore locations. It does not ask a company to describe its safeguards. It tells the company where the work may happen.
A handful of other states have reached similar conclusions by different routes, several of them through governors' executive orders barring state agencies and their subcontractors from sending work abroad. The restrictions are real, they are enforceable as contract terms, and they demonstrate that the question is neither novel nor unanswerable.
They also reveal the shape of the gap. These rules exist because a state was buying something and could set its terms. They protect the residents of those states, in those programs, and nobody else. A Texan enrolled in Medicaid is covered by a rule that a Texan with employer insurance is not, over the same records, in the same city, held by the same company. The protection follows the contract, not the patient.
There is one federal mechanism that touches the question, and it is regularly mistaken for supervision. Since a series of memoranda issued in 2007 and 2008, Medicare Advantage and prescription dr-g plan sponsors that use offshore subcontractors with access to
beneficiary health information have been required to file an attestation with the
Centers for Medicare and Medicaid Services. The form is more demanding than most people assume. A sponsor must describe the information involved, explain why sending it is necessary, and state what alternatives it considered and why it rejected them.
Then the form is filed, and nothing happens. The agency does not approve it. There is no review, no license, no conditions, and no authority to refuse. A company decides, and then reports what it decided. The requirement also reaches only Medicare plans. For commercial insurance, covering most working Americans, no comparable notification exists at all.
That the government is capable of writing a firmer rule is not in question, because it
recently did, on the same data, in a fraction of the time.
In February 2024, an executive order directed the Justice Department to restrict foreign access to Americans' bulk sensitive personal information. The resulting regulation took effect in April 2025 and became enforceable that July. It names the countries it covers. It sets numerical thresholds: health information on more than 10,000 Americans,
or genetic information on more than 100. It reaches employment and vendor arrangements explicitly, and one of its own published examples treats foreign technical staff with access to encrypted health data as a prohibited transaction. Records stripped of identifying details under HIPAA can still fall within its scope.
Fourteen months, from executive order to binding rule.
The distinction was never the data. It was the framing. Asked whether foreign
adversaries might obtain American medical records, the government wrote an enforceable prohibition in a little over a year. Asked whether patients' medical records are handled carefully, it has produced, in twenty-eight years, one form that nobody reviews.
If any event was going to change that, it should have been what happened at Change Healthcare.
The company processes a substantial share of the nation's medical claims. On February 12, 2024, intruders logged into a remote access portal using stolen credentials. The portal did not require a second form of authentication. They moved through the network
for nine days before anyone noticed. By the time the company confirmed that data had been taken, it was March.
Pharmacies could not fill prescriptions. Physician practices went months without being paid. Congressional committees convened hearings, and the chief executive of the parent company testified that security procedures had not been updated after the 2022 acquisition. The company reported to federal regulators that approximately 192.7 million
people were affected, close to two thirds of the United States population. It is the
largest medical data breach ever recorded.
Two details from the aftermath have drawn less attention than they deserve.
Before the breach, Change Healthcare held a HITRUST certification for its enterprise
infrastructure, an assessment the industry treats as evidence that an organization's
security is sound. The company had publicized it. It was certified, and the portal still
had no second factor of authentication. Certification is the principal way American
health care organizations satisfy themselves that a vendor's environment is adequate, including vendors operating overseas. It did not detect the failure that brought down a third of the nation's claims traffic.
And no federal penalty has been announced. For scale, the largest fine in the history of the medical privacy law remains a $16 million settlement reached in 2018 over a breach affecting 78.8 million people, about twenty cents a record. In the first part of this year, federal regulators closed six enforcement matters with penalties totaling roughly
$1.3 million across all of them.
The formal response to the largest breach in the sector's history was a proposal. In
January 2025, regulators published a draft update to the security rule that would, among other things, require multi-factor authentication. Public comment closed that March. The proposal has not been finalized. The federal regulatory agenda now lists July 2027 as
the target. A second initiative, a set of cybersecurity performance goals, is voluntary.
More than two years on, the missing control that caused the breach is still not required by law.
There is a structural reason none of this has generated sustained pressure, and it is
not indifference. Nobody is counting.
No law obliges a vendor to disclose that it permits access from outside the country, or from employees' homes. A hospital or insurer must have a contract with its business associates, but is not required to know, and often does not know, which country a subcontractor's subcontractor is working from, or what that room looks like. Patients cannot find out. Regulators do not collect the information outside the Medicare program.
Researchers cannot measure what is not recorded. The result is a category of risk that produces no statistics, and policy in the United States rarely moves against risks that produce no statistics.
Every legal obligation in American medical privacy law attaches to the information. Not one attaches to the room.
A health plan is fully responsible for records that an employee of a subsidiary, or a contractor three tiers below it, may be reading on a personal laptop in a country nobody
at the plan could name. No rule requires the plan to know this, to prevent it, or to
tell anyone that it is so.
The law punishes the theft after it happens. About the conditions that would make it easy, it says nothing at all, and has said nothing since 2003.