Public disclosure registry · Founding cohort open
A public record of where health and workforce software sends your data.
Software vendors sign a structured disclosure of where their customers' sensitive data is stored, who administers the systems, which people in which countries can reach it, and who ultimately controls the company. Buyers check it. It is not a security certification and makes no claim about encryption or security posture. It answers one question: where does the data go, and who can see it?
- Entries published
- 3 — see the registry
- Operated by
- David Main
- Published
- Last updated
Vendors: sign the disclosure → Buyers: get notified → Browse the registry →
The exposure
Who causes healthcare data breaches?
Mostly vendors. Business associates — the software and service companies that handle patient data on a provider's behalf — accounted for 66% of all breached healthcare records in 2024 while filing only 16% of breach reports. Providers filed 73% of reports and accounted for 24% of records.
The figures come from Bluesight's 2025 Breach Barometer, an analysis of the HHS Office for Civil Rights breach portal for calendar year 2024. That year set a record: 663 breaches of 500 or more records, affecting 242.9 million people, according to HHS's own report to Congress.
| Entity type | Share of breach reports filed | Share of breached records |
|---|---|---|
| Business associates Software vendors and service providers | 16% | 66% |
| Healthcare providers Hospitals, practices, clinics | 73% | 24% |
The inversion is the story. Vendors cause a small share of incidents and the overwhelming majority of exposure, because a single vendor aggregates data across many clients. Change Healthcare, one vendor, exposed the records of 192.7 million people in 2024 — the largest healthcare breach in US history. Across every industry, Verizon's 2025 Data Breach Investigations Report found third-party involvement in 30% of breaches, up from roughly 15% the year before.
The gap
Does HIPAA prohibit storing patient data outside the United States?
No. HIPAA does not prohibit storing or processing protected health information offshore, and the Department of Health and Human Services says so directly. Asked whether a cloud provider may store electronic PHI outside the US, the Office for Civil Rights answered:
Document excerpt"Yes, provided the covered entity (or business associate) enters into a business associate agreement (BAA)… while the HIPAA Rules do not include requirements specific to protection of electronic protected health information (ePHI) processed or stored by a CSP or any other business associate outside of the United States…"
What offshoring changes is not your liability but your remedy. HIPAA contains no express extraterritorial provision, and OCR's authority over a purely foreign business associate has never been tested in enforcement. In practice, enforcement runs against the US covered entity and its domestic business associate — for inadequate oversight of their vendors — not against the foreign entity that actually touched the data. You still get fined. You just have nobody to recover from.
The government has documented the problem in its own programs. A 2014 HHS Office of Inspector General review of offshore outsourcing in state Medicaid found that foreign countries may have limited or no comparable privacy protections, and that agencies had limited means of enforcing business associate safeguards against foreign subcontractors.
Offshoring does not reduce your liability. It removes your remedy.
The precedent
What does federal law require when your tax return goes offshore?
Written consent, in advance, with a mandated warning. Under Internal Revenue Code §7216 and 26 C.F.R. §301.7216-3, a US tax preparer may not disclose a taxpayer's return information to a preparer outside the United States without the taxpayer's affirmative, signed consent — an opt-out is expressly not permitted — and Revenue Procedure 2013-14 prescribes the exact words that consent must contain.
When your tax return is sent to a preparer outside the United States
"This consent to disclose may result in your tax return information being disclosed to a tax return preparer located outside the United States, including your personally identifiable information such as your Social Security Number ("SSN"). Both the tax return preparer in the United States that will disclose your SSN and the tax return preparer located outside the United States that will receive your SSN maintain an adequate data protection safeguard (as required by the regulations under 26 U.S.C. section 7216) to protect privacy and prevent unauthorized access of tax return information. If you consent to the disclosure of your tax return information, federal agencies may not be able to enforce United States laws that protect the privacy of your tax return information against a tax return preparer located outside of the United States to whom the information is disclosed."
When your medical record is sent to a vendor's staff outside the United States
None.
HIPAA contains no requirement to tell a patient, or to ask a patient, when protected health information is stored, administered, or accessed outside the United States.
When your accountant sends your tax return offshore, federal law requires them to warn you in writing that US privacy law may not be enforceable against the recipient. When your doctor's software vendor sends your medical record offshore, no one has to tell you anything.
For tax data held by government, the rule is an outright prohibition
Federal Tax Information held by state agencies and their contractors is governed by IRS Publication 1075, which does not ask for consent. It draws a boundary:
Document excerpt"FTI cannot be accessed by agency employees, agents, representatives, contractors, or sub-contractors located outside of the legal jurisdictional boundary of the United States (outside of the United States, its territories, embassies, or military installations). FTI must not be received, processed, stored, accessed, or transmitted to (IT) systems located offshore nor may FTI be sent offshore for disposal. Systems containing FTI must be located, operated and maintained by personnel physically located within the United States (this prohibits foreign remote maintenance, foreign call centers, help desks and the like)."
For cloud systems, §3.3.1 of the same publication adds a two-part test: all federal tax information must "physically reside" in US systems, and "all accesses, and support of the systems and services are performed from the United States."
OnshoreFacts does not propose a new standard. It extends to health and workforce data a boundary the federal government already applies to tax data, and adopts Publication 1075's definition of the United States verbatim: the United States, its territories, embassies, and military installations.
The obligation · Texas
What does Texas Senate Bill 1188 require?
Since 1 January 2026, Texas has required covered entities to keep electronic health records containing patient information physically within the United States or a US territory. The requirement, enacted in 2025 as Senate Bill 1188, applies to records held by third-party and cloud providers.
For a Texas practice this is not a preference but a compliance obligation that has been in force for eight months — and most practices have no way to verify whether their vendors meet it, because most vendors publish nothing about where records are kept. We describe the requirement only as far as the bill text supports it; we do not characterize its penalty regime or scope beyond that, and a practice should confirm its own obligations with a Texas healthcare attorney.
Texas is not alone in drawing the line. Texas HHSC's Uniform Managed Care terms contractually prohibit keeping Medicaid information outside the United States. Michigan's FY2025 Medicaid contract requires that state data be kept in the continental United States. Minnesota Statutes §256B.03, subdivision 4, prohibits Medical Assistance payments for services located outside the United States.
OnshoreFacts original research
How many healthcare software vendors say where patient data is processed?
One in sixty-six published a dedicated, named list of subprocessors with their locations. Thirteen of 66 (about 20%) made any statement at all about where protected health information is stored or processed. Fifty-three of 66 (80%) made no geographic statement whatsoever.
healthcare software vendors examined published a named subprocessor list with locations. That list named six subprocessors, all in the United States.
Method
For each of 66 healthcare software vendors, we attempted to retrieve the pages /subprocessors, /sub-processors, /dpa, /legal, /trust, /security, /privacy, /baa and /hipaa on the vendor's own domain, then read what was published and recorded whether it made any statement about the geography of storage, processing, or personnel. Roughly 150 vendors were touched in total across healthcare and construction, safety and union verticals; the 66 are the healthcare vendors examined in depth. This is our own count, gathered in 2026, not a published study. The full method and vendor-population statistics will be published with the registry.
The texture behind the number: two of the 66 publish an unedited WordPress default privacy policy that never mentions PHI or HIPAA. One has an unfinished legal placeholder live in production. One has no privacy policy at all. One promises, in its Terms of Service, a privacy policy that does not exist. We do not name them, and will not — see the integrity statement.
The second market · Construction and union workforce
Does the same gap exist outside healthcare?
Yes, with harder data. Construction and workforce software holds categories at least as sensitive as a medical record, with the same absence of disclosure.
Certified payroll on federal form WH-347 contains employee Social Security numbers. OSHA 300 and 301 logs contain employee medical information. Taft-Hartley trust funds hold health eligibility and dependent data for union families. Jobsite camera vendors run AI over video of identifiable workers and use human reviewers to validate the alerts — of the AI-camera vendors we examined, exactly one disclosed that its reviewers are US-based. Biometric time clocks and physiological wearables that read core temperature and heart rate are in active use on sites today.
A signatory contractor's identity is American labor. Where its software is built and supported is a question its members are entitled to ask, and one the registry lets a contractor answer with a document instead of an assurance.
The Onshore Disclosure Standard · v0.1
What does a vendor actually disclose?
Attest or disclose — never pass or fail. The form follows California Public Contract Code §12147, which gives state contractors exactly that choice: certify that the work is performed in the United States, or describe the parts that are not. Every honest answer is a valid registry entry.
Vendor marketing collapses four different questions into the phrase "US-based." The disclosure forces them apart.
Onshore Disclosure — attestation structure
Standard v0.1 · one page · signed by a named officer| Dimension | What must be stated, for each data tier |
|---|---|
| Storage | Where production data physically resides — including backups, disaster-recovery replicas, and log aggregation. |
| Administration and remote maintenance | From which countries systems are operated, patched, and maintained. This is the target of IRS Publication 1075's prohibition on foreign remote maintenance. |
| Personnel with production data access | Countries of the people who can reach live customer data, broken out by function:
|
| Ultimate corporate control | Who ultimately controls the company, and the country of that control. |
Resulting status — all three are legitimate registry entries
- Fully onshoreAll four dimensions US-only, no exceptions. Boundary as in Publication 1075: the United States, its territories, embassies, and military installations — so Puerto Rico and Guam count.
- Onshore with disclosed exceptionsEach exception named: country, function, data tier reachable, whether it touches live production data, approximate headcount, and mitigation.
- Not onshoreMaterial processing happens abroad, stated plainly. A vendor that says its support runs from Manila gives a buyer something no vendor currently provides.
Three data tiers
- Tier 3Social Security numbers; protected health information, including OSHA 300 and 301 logs; biometrics; video of identifiable people; drug-test results; Controlled Unclassified Information.
- Tier 2Identifiable personal data; worker geolocation; union membership and grievance records.
- Tier 1Operational data not tied to individuals.
How it is verified
The attestation is signed by a named officer, not by "the company." Supporting evidence is published on the vendor's own domain. A knowingly false statement made to induce a purchase is exposed under Section 5 of the FTC Act. The model is borrowed from the EU–US Data Privacy Framework. We rejected FedRAMP's audit model, which we estimate at $600,000 to $2.5 million for a Moderate authorization and is out of reach for a ten-person vendor, and we rejected the app-store self-report model, which produced 30–80% measured non-compliance in a 2023 USENIX Security study of 5,102 apps. A signed public statement with legal exposure is the level of verification a small vendor can afford and a buyer can rely on.
For vendors
Sign the disclosure. Join the founding cohort.
If your data, your administration, and your people are in the United States, you currently have no way to prove it that a buyer can check. The founding cohort are the first vendors whose signed disclosures the registry publishes. Complete the one-page attestation; we publish it here and you publish it on your domain.
For buyers
Ask about a vendor. Be told when their entry publishes.
For medical practices, signatory contractors, and trust fund trustees. Browse the registry for vendors that have signed. Tell us which software you rely on; we will ask each vendor to sign, and notify you when a disclosure is published — or when the vendor declines to answer.
Integrity statement
What this registry will not do
The premise of this registry is that vendors should make precise, checkable claims instead of vague ones. The same rule binds us. Each of the following claims circulates widely, and each was researched and could not be substantiated.
- We will not name a vendor that has not signed.
Absence from the registry is never presented as a finding. We publish aggregate, anonymized figures about the vendor population; we never publish a specific non-participant's shortfall. The only vendors named on this site are participants who have signed.
- We will not claim that offshoring causes more breaches.
No study with a control group or matched comparison exists. The best third-party analysis — Bisht et al., 2021, in the Journal of Cybersecurity, covering 1,397 incidents — explicitly does not isolate offshore geography.
- We will not claim that offshore workers are more likely to steal data.
No comparative study exists.
- We will not claim that HIPAA prohibits offshore storage.
It expressly does not, and HHS says so directly. The argument on this page is about remedy, not prohibition.
- We will not tell you that FedRAMP guarantees US data residency.
Below the High baseline, it does not. FedRAMP's own guidance states that data location is specified only in the High baseline, in control SA-9(5), and that it "does not provide or specify data location requirements for the other baselines." A FedRAMP authorization covers a cloud service offering, not a company. The US-only rules people have in mind come from DFARS 239.7602-2 and the DoD Cloud Security Requirements Guide.
- We will not quote a dark-web price per health record, or an average cost per record.
The widely repeated per-record figures trace to industry commentary with no rigorous methodology, and IBM's own breach-cost research cautions against extrapolating per-record costs to large breaches.
- We will not publish a statistic we cannot source.
Every figure on this page carries its source beside it. Where the evidence runs out, the page says so.
Who runs this
OnshoreFacts is operated by David Main, who also builds EasyDocForms (patient intake), GoSafety (construction safety documentation) and LicenseKit (software licensing) — all three of which are themselves subject to this disclosure, and all three of which are, as of 30 August 2026, the only entries in the registry. The registry is not yet independent of its operator, and how the standard should be governed — by an independent entity, a trade association, or the operator with the conflict stated — is an open question we intend to settle publicly. We say so here because a disclosure registry that concealed its own conflict would have no standing to ask for yours. The operator's products are entries 0001, 0002 and 0003, disclosed under the same standard, with the same evidence requirements, as every vendor that follows.