• videocam Live Webinar with Live Q&A
  • calendar_month October 27, 2026 @ 1:00 PM ET/10:00 AM PT
  • signal_cellular_alt Intermediate
  • card_travel Health
  • schedule 90 minutes

Offshoring Patient Health Data: Navigating Complex Federal and State Privacy Regulation, Mitigating Client Risk

About the Course

Introduction

This CLE webinar will guide practitioners through federal and state regulations governing the offshoring of patient data in the healthcare industry. The expert panel will discuss how offshoring is being used in the industry and how this may create conflicts with privacy regulations and material contractual arrangements. The panel will also offer best practices for guiding clients through the maze of privacy regulations so they may remain compliant.

Description

Healthcare companies are increasingly contracting with third-party vendors to provide software and a variety of support services, such as claims processing, call center staffing, and technical support, for cost savings. Often this involves offshoring mass amounts of patient data to subcontractors.

Offshoring occurs when a party contracts with another party located outside of the U.S. and its territories. With federal and state privacy laws governing patient data becoming more stringent and offshoring becoming more common, counsel should be aware of how to help their clients navigate the complex and often inconsistent interplay of laws, regulations, and guidance to ensure compliance.

In addition to federal regulations, such as HIPAA and ACA, and CMS guidance that impact the offshoring of patient data, several states have taken steps to limit this practice as well. For example, the Florida Electronic Health Records Exchange Act effectively prohibits certain covered healthcare providers from storing electronic health records offshore themselves and from relying on third-party offshore vendors to store such records. Other states have issued executive orders prohibiting the offshoring of certain activities that are paid for by state agencies.

Listen as our expert panel discusses the compliance challenges facing healthcare counsel and their clients who must decide whether and to what extent to use offshore third-party vendors for support while maintaining their obligations to protect patient data. The panel will discuss the network of federal and state regulations and guidance governing the offshoring of patient data and best practices for helping clients remain compliant.

Presented By

Carolyn V. Metnick
Partner
Sheppard

Ms. Metnick advises healthcare organizations and digital health companies on regulatory and data governance challenges at the intersection of privacy, security and artificial intelligence. She focuses on HIPAA, other health information laws, data strategy and security incident response—helping clients deploy innovative technologies while managing compliance risks across federal and state privacy frameworks. As the founder and leader of Sheppard Healthy AI, Ms. Metnick brings together a cross-disciplinary team dedicated to the compliant development, deployment and use of AI in healthcare. The initiative guides stakeholders through governance, vendor contracting, notice/consent and risk allocation—aligning emerging technologies with evolving laws, regulations and industry best practices. Ms. Metnick counsels hospitals, health systems, physician organizations, payors and technology companies on the full life cycle of health information and all related issues. Her work includes structuring data-sharing collaborations, developing privacy and security programs, responding to security incidents and navigating federal and state privacy laws. She is a Certified Information Privacy Professional/United States and a Certified Information Privacy Professional/Europe.

Michael D. Sutton
Attorney
Sheppard

Mr. Sutton specializes in health care privacy, digital health and related regulatory compliance and transactional matters. With a deep understanding of HIPAA, data usage and emerging health care technologies, he helps clients navigate complex legal landscapes as they leverage the latest innovations in the health care space. Mr. Sutton focuses on HIPAA and privacy related regulations and their interplay with technological developments both inside and outside of the healthcare and consumer spaces. He is well versed in negotiations centered on data usage and derivative ownership rights. Mr. Sutton maintains significant experience in guiding clients seeking to market or integrate technological innovations, such as ordering and support platforms, remote patient monitoring tools, electronic medical record systems, artificial intelligence, and other offerings centered on collecting, storing, and transmitting patient data to support care, reimbursement, and related activities.

Credit Information
  • This 90-minute webinar is eligible in most states for 1.5 CLE credits.


  • Live Online


    On Demand

Date + Time

  • event

    Tuesday, October 27, 2026

  • schedule

    1:00 PM ET/10:00 AM PT

I. Introduction to offshoring

A. How offshoring is being used in the healthcare industry

II. Federal regulations and guidance impacting offshoring in healthcare

A. HIPAA

B. ACA

C. CMS guidance

III. State laws and actions affecting offshoring

A. FL

B. OH

C. Others

IV. Contractual arrangements

V. Penalties for noncompliance

VI. Best practices for compliance

VII. Practitioner takeaways

The panel will review these and other key considerations:

  • What federal laws impact the offshoring of patient data? How?
  • What are notable state laws and/or actions that limit or prohibit the offshoring of patient data?
  • What are best practices for assisting clients in deciding whether and in what manner to use third-party vendors that require offshoring?