F
,

5 min read

Federal and State Data Restrictions Are Forcing Health Systems to Re-Examine Where Clinical Documentation Is Produced

–

A confluence of a federal national security regulation, an expanding patchwork of state laws, and escalating physician documentation fatigue is reshaping the landscape.

The key takeaway for health systems is that these are distinct mandates with their own specific triggers.”— James Maisel, MD, Founder & CEO of ZyDocNEW YORK, NY, UNITED STATES, September 16, 2026 /EINPresswire.com/ — For the past twenty years, the financial incentives of U.S. medical transcription have consistently pointed overseas. A substantial portion of American clinical documentation has been generated outside the country’s borders, and for the majority of that period, no federal regulation prohibited this practice. While HIPAA establishes standards for safeguarding protected health information, it has never dictated where that data must be stored or processed.

That dynamic has shifted, prompting health systems to revisit and reassess their long-held operational strategies.

Understanding the New Regulatory Landscape

Two distinct sets of legal frameworks are driving this significant change.

On the federal front, the Department of Justice’s Data Security Program (28 C.F.R. Part 202), which was issued under Executive Order 14117, became effective on April 8, 2025. This rule prohibits and restricts transactions that grant access to bulk U.S. sensitive personal data—including personal health information—to countries of concern or covered persons. Analysts point out that even data de-identified under HIPAA could fall under this rule’s jurisdiction if it satisfies the bulk thresholds. The associated due diligence, auditing, and reporting requirements have been implemented on a staggered timetable, and the DOJ has strongly advised organizations to have a complete understanding of both their data flows and their third-party vendors.

State-level mandates are more direct, with two states having codified requirements into law.

Florida’s Senate Bill 264, which went into effect on July 1, 2023, mandates that providers using certified electronic health record technology keep all patient information physically located within the continental United States, its territories, or Canada. This requirement extends to third-party facilities, subcontractors, and cloud providers, and licensees must certify compliance during the initial licensure process and at every subsequent renewal.

Texas followed with Senate Bill 1188. While most of its provisions took effect on September 1, 2025, the data localization requirement became effective on January 1, 2026. This mandates that electronic health records under a covered entity’s control be physically maintained within the United States or a U.S. territory. The law applies to records regardless of when they were created, extends to third-party vendors and cloud providers, and includes civil penalties. Analysts highlight that Texas’s broad definition of a “covered entity” extends far beyond traditional healthcare settings.

Mapping the Scope of State Restrictions

The restrictions can be categorized into three distinct tiers, and many organizations discover they fall under more than one.

Statutes that restrict offshore storage of health records, applying broadly to all providers:

Florida (SB 264)
Texas (SB 1188)

State Medicaid programs that explicitly prohibit offshore storage or processing of Medicaid data, typically established through executive order or contract terms:

Alaska
Arizona
Ohio
Wisconsin

States that impose restrictions, conditions, or attestation requirements on offshore subcontracting that involves patient data:

Arizona
Florida
Georgia
Mississippi
Missouri
New Jersey
Ohio
Tennessee
Texas

Several other state Medicaid agencies only allow offshore processing under very specific circumstances. Furthermore, Alaska, Arizona, Missouri, New Jersey, Ohio, and Wisconsin broadly prohibit offshore performance in state contracting, and individual solicitations sometimes ban offshore work even when no specific statute mandates it. Commercial payer contracts vary, but some now require an offshore subcontracting attestation and annual audits of the offshore vendor.

It’s important to note that classifications can vary depending on the source and are subject to frequent change. An organization serving patients from a state with restrictions may still be subject to that state’s oversight even if the organization is located elsewhere. Therefore, providers must verify the current requirements in every state where they are licensed or treat patients.

"The key takeaway for health systems is that these are distinct mandates with their own specific triggers," explained James M. Maisel, MD, Founder and CEO of ZyDoc®. "A vendor can be completely HIPAA compliant and still create legal exposure under a state residency statute or a federal national security rule. Compliance is no longer a single question with a simple answer, and the contracts most organizations signed years ago were not drafted with any of these new realities in mind."

The Second Challenge: The Burden Still Falls on the Physician

This regulatory shift coincides with a new wave of evaluation of AI-only documentation tools.

Ambient and AI-only scribing tools make capturing an encounter and drafting a note look effortless. However, the draft still requires the clinician’s review, correction, and sign-off. This means a significant portion of the burden is merely deferred, not eliminated. Industry data suggests that physicians spend over 80 minutes a day correcting AI-generated documentation. Additionally, financial losses from undercoding and insurance clawbacks due to incomplete documentation surpass $1 billion annually.

Many organizations are now assessing documentation vendors based on two critical factors: the location where the work is performed and the amount of work that still falls back onto the clinician.

"Health systems are being asked to solve a compliance challenge and a workforce challenge with a single contract," said Matt Koerner, Chief Marketing Officer and Strategic Advisor at ZyDoc®. "Previously, these were separate issues managed by different departments, but now they are a single, unified conversation."

He points to an even more fundamental question that underlies both of these issues.

"The question that almost no one has managed to answer yet is who holds the responsibility for data security at the point of sign-off," he said. "A note might be processed by an AI system, sent to a vendor, then to a subcontractor, and moved through a cloud environment before it ever reaches the physician for final approval. By the time the clinician signs off, accountability has been so fragmented across multiple parties that it’s unclear who is ultimately responsible. As an industry, we need to address this promptly, while we still have the opportunity to do so thoughtfully."

Key Questions for Provider Organizations

Leaders in documentation and compliance may want to get clear answers on the following points from any vendor handling clinical documentation:

Where is the actual work being performed, including any subcontractors?
Where is the patient data stored, and who has access to it?
Does the business associate agreement cover data residency, or does it only address safeguards?
Can the vendor support a state residency attestation if required?
Has the vendor assessed its own exposure under 28 C.F.R. Part 202?
How much clinician time is required after the note is returned for review?
Is the final output ready to be integrated into the EHR without significant formatting issues?
At the point of sign-off, who is legally and operationally responsible for the record’s security?

Organizations are advised to consult with qualified healthcare counsel regarding their specific situations, as the requirements vary based on state, licensure type, and the nature of the data involved.

About ZyDoc®

ZyDoc® is a U.S.-based clinical documentation company that serves physician practices, ambulatory surgery centers, and healthcare organizations across the nation. By integrating advanced AI with expert human oversight based in the U.S., the company delivers accurate, secure, and workflow-friendly documentation without the risks associated with offshore processing. Learn more at https://www.zydoc.com.

This release is provided for general informational purposes only and does not constitute legal advice.

Matthew Koerner, MM, MBA
ZyDoc
+1 800-546-5633
email us here
Visit us on social media:
LinkedIn
YouTube


David Hall

David Hall

David is the senior editor at TheCyberMag. He has a background in journalism and has worked with various media outlets, covering topics ranging from threat intelligence and data privacy to cybercrime and cloud security. When he is not writing, David enjoys reading, hiking, photography, and exploring new coffee shops.