A Remote Team, Serving 49 States.

We’re a remote business with staff in the US and internationally. Only our US-based staff log into your systems or see identifiable data. International staff and AI tools work on task data with identifiers removed. Some state Medicaid programs limit work done outside the US, so here’s what we found for each state and how we handle it.

We don’t currently serve Alaska or US territories. How our team is structured

Offshore limits apply

14

Identifiable data and all work in your systems stay with our US-based staff. Offshore staff and AI only get task data with identifiers removed. We also read your plan’s provider agreement at onboarding and follow any stricter terms it passes down to you.

Approval required

4

The approval is needed to move PHI or plan work outside the US, and we don’t do either: identifiable data stays with our US-based staff, and offshore staff and AI only get task data with identifiers removed. We check your plan’s provider agreement at onboarding.

No state rule found

31

HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

State by State

Alabama

Alabama Medicaid Agency

No state rule found

We found no Alabama-specific rule on offshore access to Medicaid data. Federal HIPAA and the federal bar on Medicaid payments to entities outside the US still apply, and individual payer contracts may add limits.

ABA: ABA is covered for under-21s via EPSDT, with licensed behavior analysts as EPSDT-only providers and prior authorization required for most ABA codes (97151 does not require it).

How we handle it: HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

Source 1 Source 2

Arizona

AHCCCS (Arizona Health Care Cost Containment System)

Offshore limits apply

AHCCCS rules bar offshore work that involves access to secure or sensitive data about Arizona members, and these terms flow into provider agreements. Since October 2024 the exception no longer covers patient related data.

ABA: AHCCCS publishes ABA-related coding in its Covered Behavioral Health Services Guide and Behavioral Health Services Matrix.

How we handle it: Identifiable data and all work in your systems stay with our US-based staff. Offshore staff and AI only get task data with identifiers removed. We also read your plan’s provider agreement at onboarding and follow any stricter terms it passes down to you.

Source 1 Source 2

Arkansas

Arkansas Medicaid (Division of Medical Services, DHS)

No state rule found

We found no Arkansas-specific offshore rule for Medicaid data. Federal HIPAA and payer or PASSE contracts still apply, so check each contract.

ABA: ABA is covered for ages 18 months to 21 under the EPSDT Child Health Services program, requires an ASD diagnosis, and all assessments and treatment must be prior authorized.

How we handle it: HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

Source 1 Source 2

California

Medi-Cal (DHCS)

No state rule found

We found no blanket Medi-Cal ban on offshore work, though some plans such as Health Net require an offshore subcontracting attestation, and health plans licensed by the DMHC must disclose offshore outsourcing. Expect plan-level questionnaires and check each contract.

ABA: Behavioral health treatment (including ABA) for under-21s is delivered through the member's Medi-Cal managed care plan under DHCS All Plan Letters.

How we handle it: HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

Source 1 Source 2

Colorado

Health First Colorado (HCPF)

Approval required

Health First Colorado contract language bars sharing PHI with anyone outside the US without express written authorization from the state.

ABA: ABA is covered under the Pediatric Behavioral Therapies benefit for under-21s via EPSDT, with its own billing manual.

How we handle it: The approval is needed to move PHI or plan work outside the US, and we don’t do either: identifiable data stays with our US-based staff, and offshore staff and AI only get task data with identifiers removed. We check your plan’s provider agreement at onboarding.

Source 1 Source 2 Source 3

Connecticut

HUSKY Health (Connecticut Medicaid, DSS)

No state rule found

We found no Connecticut-specific offshore rule for Medicaid data. Federal HIPAA still applies and payer contracts may add limits.

ABA: Connecticut Medicaid covers ABA/autism services for HUSKY A, C and D members under 21.

How we handle it: HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

Source 1

Delaware

Delaware Medicaid (Division of Medicaid and Medical Assistance, DHSS)

No state rule found

We found no Delaware-specific offshore rule for Medicaid data. Federal HIPAA still applies and MCO contracts may add limits.

ABA: ABA is covered for under-21s and is handled through the MCOs, with some services beyond annual unit limits shifting to DDDS prior authorization.

How we handle it: HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

Source 1

Florida

Florida Medicaid (AHCA)

Offshore limits apply

Florida law (SB 264, 2023) requires providers using certified EHR technology, and their vendors, to keep patient information stored in the continental US, its territories, or Canada.

ABA: Behavior analysis for under-21s is governed by Rule 59G-4.125 (effective Feb 2025), with a 40 hour per week limit and annual assessment.

How we handle it: Identifiable data and all work in your systems stay with our US-based staff. Offshore staff and AI only get task data with identifiers removed. We also read your plan’s provider agreement at onboarding and follow any stricter terms it passes down to you.

Source 1 Source 2

Georgia

Georgia Medicaid (Department of Community Health, DCH)

Offshore limits apply

Georgia DCH contract terms bar plan suppliers from providing services from offshore locations. The rule is written for managed care plans and their suppliers; plans may pass similar terms down in provider agreements.

ABA: ABA is a covered benefit for children with ASD, authorized through the Georgia Families care management organizations.

How we handle it: Identifiable data and all work in your systems stay with our US-based staff. Offshore staff and AI only get task data with identifiers removed. We also read your plan’s provider agreement at onboarding and follow any stricter terms it passes down to you.

Source 1 Source 2

Hawaii

Med-QUEST Division (QUEST Integration), Hawaii DHS

No state rule found

We found no Hawaii-specific offshore rule for Medicaid data. Federal HIPAA still applies and QUEST plan contracts may add limits.

ABA: ABA is covered for EPSDT-eligible members under 21 with ASD, with Med-QUEST memos setting billing and rendering provider standards.

How we handle it: HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

Source 1

Idaho

Idaho Medicaid (Department of Health and Welfare)

No state rule found

We found no Idaho-specific Medicaid rule on offshore access to PHI. Federal HIPAA, the federal bar on Medicaid payments to entities outside the US, and each payer contract still apply.

ABA: Idaho Medicaid covers ABA for members under 21 through EPSDT with prior authorization; billing codes and payer routing reportedly changed in late 2025, so confirm current rules with Idaho Medicaid.

How we handle it: HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

Source 1 Source 2

Illinois

Illinois Medicaid (HFS), HealthChoice Illinois managed care

No state rule found

We found no offshore clause in the HFS managed care model contract we reviewed (2018 draft). Individual MCO and subcontractor agreements may still require notice or approval for offshore access, so check each plan contract.

ABA: Illinois HFS covers ABA for members age 0 to 20 with autism through both fee-for-service and HealthChoice Illinois MCOs, with prior authorization.

How we handle it: HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

Source 1 Source 2

Indiana

Indiana Health Coverage Programs (IHCP), Hoosier Healthwise and Healthy Indiana Plan

Offshore limits apply

The state managed care contract bars health plans from subcontracting with entities located or working outside the US. It is written for plans and their subcontractors, not provider billing vendors.

ABA: All ABA services under IHCP require prior authorization, with approvals up to six months.

How we handle it: Identifiable data and all work in your systems stay with our US-based staff. Offshore staff and AI only get task data with identifiers removed. We also read your plan’s provider agreement at onboarding and follow any stricter terms it passes down to you.

Source 1 Source 2

Iowa

Iowa Medicaid (Iowa HHS), Iowa Health Link managed care

No state rule found

The Iowa MCO contract we reviewed says the MCO may not be located outside the US, but we did not verify a specific offshore data access rule for provider vendors. Check each MCO provider agreement.

ABA: Iowa Medicaid covers ABA for children under EPSDT through managed care, and RBT services are billed by the licensed supervising behavior analyst.

How we handle it: HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

Source 1 Source 2

Kansas

KanCare (Kansas Medicaid, KDHE), KMAP

No state rule found

We found no Kansas-specific offshore rule for Medicaid data. Federal HIPAA and each KanCare MCO contract still apply.

ABA: Kansas covers ASD services under EPSDT, billed with ABA CPT codes and subject to prior authorization through the KanCare MCOs.

How we handle it: HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

Source 1 Source 2

Kentucky

Kentucky Medicaid (Department for Medicaid Services), managed care

Offshore limits apply

The managed care contract bars health plans from performing services or functions outside the US and requires disclosure of offshore operations by plan subcontractors.

ABA: Kentucky Medicaid delivers ABA mostly through MCOs and requires a Kentucky Licensed Behavior Analyst credential.

How we handle it: Identifiable data and all work in your systems stay with our US-based staff. Offshore staff and AI only get task data with identifiers removed. We also read your plan’s provider agreement at onboarding and follow any stricter terms it passes down to you.

Source 1 Source 2

Louisiana

Healthy Louisiana (Louisiana Medicaid, LDH)

No state rule found

The LDH MCO model contract bars payments to providers or entities located outside the US, but we found no explicit data access rule for vendors. Check each Healthy Louisiana plan agreement.

ABA: ABA is covered under the State Plan for members under 21, requires MCO prior authorization in two steps, and does not require an autism diagnosis.

How we handle it: HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

Source 1 Source 2

Maine

MaineCare (Maine DHHS Office of MaineCare Services)

No state rule found

We found no MaineCare-specific rule on offshore access to PHI. Federal HIPAA and the federal bar on payments outside the US still apply.

ABA: MaineCare covers ABA for children under Section 28 (rehabilitative and community support services).

How we handle it: HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

Source 1

Maryland

Maryland Medical Assistance (Maryland Department of Health), HealthChoice

No state rule found

The 2026 HealthChoice MCO agreement we searched has no offshore data clause, only an exclusion for services received outside the US. Check each MCO and the BHASO agreements.

ABA: Maryland covers ABA for members under 21 through fee-for-service via the Carelon BHASO under COMAR 10.09.28.

How we handle it: HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

Source 1 Source 2

Massachusetts

MassHealth (Massachusetts EOHHS)

No state rule found

The MassHealth MCO contract bars coverage of services and payments to entities outside the US, but we verified no explicit offshore data rule. Individual plans may require offshore subcontracting disclosure from providers.

ABA: MassHealth requires prior authorization for all ABA services, with authorization periods of up to six months.

How we handle it: HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

Source 1 Source 2

Michigan

Michigan Medicaid (MDHHS; Healthy Michigan Plan, with Medicaid Health Plans and PIHPs)

No state rule found

We did not find a Michigan-specific rule on offshore access to Medicaid data. Federal HIPAA, the federal ban on Medicaid payments to entities outside the US, and each health plan or PIHP contract still apply, so check payer contracts before any offshore involvement.

ABA: Michigan covers behavioral health treatment including ABA for Medicaid members under 21 with autism, delivered through the PIHP and CMHSP system.

How we handle it: HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

Source 1 Source 2

Minnesota

Minnesota Health Care Programs (Medical Assistance / MinnesotaCare, DHS)

No state rule found

We did not find a Minnesota-specific offshore rule for Medicaid data. Federal HIPAA and the federal payment ban still apply, and individual MCO contracts may be stricter.

ABA: Minnesota covers autism treatment for members under 21 through its own EIDBI benefit, which requires MHCP enrollment and has its own policy manual.

How we handle it: HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

Source 1

Mississippi

Mississippi Medicaid (Division of Medicaid; MississippiCAN managed care)

Approval required

The Division of Medicaid business associate agreement bars accessing, storing, sending, or disclosing PHI outside the US, including by subcontractors, without written authorization.

ABA: ABA for autism is covered for EPSDT-eligible members when medically necessary and prior authorized.

How we handle it: The approval is needed to move PHI or plan work outside the US, and we don’t do either: identifiable data stays with our US-based staff, and offshore staff and AI only get task data with identifiers removed. We check your plan’s provider agreement at onboarding.

Source 1 Source 2

Missouri

MO HealthNet (Missouri Medicaid; MO HealthNet Managed Care)

Offshore limits apply

Executive Order 04-09 restricts offshore work on state contracts, and the managed care contract reportedly bars storing or sending program data outside the US. Both are written for state contractors and plans.

ABA: ABA is covered for members under 21 under EPSDT; per secondary sources it is paid fee-for-service by the state rather than by the managed care plans.

How we handle it: Identifiable data and all work in your systems stay with our US-based staff. Offshore staff and AI only get task data with identifiers removed. We also read your plan’s provider agreement at onboarding and follow any stricter terms it passes down to you.

Source 1 Source 2

Montana

Montana Medicaid (DPHHS; Healthy Montana Kids for CHIP)

No state rule found

We did not find a clear Montana rule on offshore Medicaid data. A 2014 federal OIG report noted Montana does not send PHI offshore, but we could not verify a current written prohibition, so federal rules and your payer contracts govern.

ABA: Montana has a dedicated Medicaid ABA Services Manual (updated September 2025) with its own provider qualifications and covered services, framed under EPSDT.

How we handle it: HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

Source 1 Source 2

Nebraska

Nebraska Medicaid (Heritage Health managed care, DHHS)

No state rule found

We did not find a Nebraska-specific offshore rule for Medicaid data. Heritage Health plan contracts and federal law still apply, so confirm with each plan.

ABA: ABA is covered through Heritage Health plans, and the state issued ABA service definitions effective February 2025 and an audit flagged missing BCBA supervision documentation for RBT services.

How we handle it: HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

Source 1 Source 2

Nevada

Nevada Medicaid (DHCFP; Medicaid managed care and fee-for-service)

Offshore limits apply

Nevada's managed care contract was reportedly amended in 2021 to bar health plans from doing contract work or keeping information outside the US. It is written for plans, not provider billing vendors.

ABA: ABA is covered under MSM Chapter 3700 with provider type 85; adaptive behavior treatment requires prior authorization while initial assessments do not.

How we handle it: Identifiable data and all work in your systems stay with our US-based staff. Offshore staff and AI only get task data with identifiers removed. We also read your plan’s provider agreement at onboarding and follow any stricter terms it passes down to you.

Source 1 Source 2 Source 3

New Hampshire

New Hampshire Medicaid (NH DHHS; Medicaid Care Management)

No state rule found

We found only the federal-style limits in New Hampshire's care management contracts, which bar plans and payments from locations outside the US. No NH rule on offshore data access was verified, so plan contracts and HIPAA govern.

ABA: ABA is not in the State Plan but is covered under EPSDT for members under 21 when medically necessary, with service authorization required.

How we handle it: HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

Source 1 Source 2

New Jersey

NJ FamilyCare (NJ Medicaid, DMAHS)

Offshore limits apply

State law (N.J.S.A. 52:34-13.2) requires state service contracts and their subcontracts to be performed in the US. It binds state contractors such as health plans, not providers' own vendors.

ABA: ABA is covered for NJ FamilyCare members under 21 with autism since January 2019, with MCOs handling prior authorization.

How we handle it: Identifiable data and all work in your systems stay with our US-based staff. Offshore staff and AI only get task data with identifiers removed. We also read your plan’s provider agreement at onboarding and follow any stricter terms it passes down to you.

Source 1 Source 2

New Mexico

Turquoise Care (New Mexico Medicaid, Health Care Authority)

No state rule found

We could not read the Turquoise Care MCO contract text and found no verified New Mexico offshore rule. Federal law and each MCO's contract still apply.

ABA: ABA is covered as part of EPSDT in staged services with prior authorization, and the state sets a minimum ABA fee schedule that MCOs cannot negotiate below.

How we handle it: HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

Source 1 Source 2

New York

New York State Medicaid (Medicaid Managed Care and Fee-for-Service)

No state rule found

We did not find a New York Medicaid rule specific to offshore access or PHI processing for providers or billing vendors. Federal HIPAA and the individual health plan and payer contracts still apply, so confirm each contract before any offshore access.

How we handle it: HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

Source 1

North Carolina

NC Medicaid (Standard Plans and Tailored Plans, plus NC Medicaid Direct)

Approval required

NC Medicaid's PIHP contract requires prior written approval before contract work is moved outside the US. It is written for the health plans.

ABA: NC Medicaid covers ABA for members under 21 through the EPSDT benefit.

How we handle it: The approval is needed to move PHI or plan work outside the US, and we don’t do either: identifiable data stays with our US-based staff, and offshore staff and AI only get task data with identifiers removed. We check your plan’s provider agreement at onboarding.

Source 1 Source 2

North Dakota

North Dakota Medicaid (Medicaid Expansion managed care plus fee-for-service)

Offshore limits apply

The Medicaid Expansion managed care contract bars the plan and its material subcontractors from operating outside the US. It does not bind providers directly.

How we handle it: Identifiable data and all work in your systems stay with our US-based staff. Offshore staff and AI only get task data with identifiers removed. We also read your plan’s provider agreement at onboarding and follow any stricter terms it passes down to you.

Source 1 Source 2

Ohio

Ohio Medicaid (Ohio Department of Medicaid)

Offshore limits apply

Ohio's managed care provider agreement bars transferring personal health information outside the US, and Executive Order 2019-12D bars public funds for services performed offshore under state contracts.

ABA: Ohio Medicaid covers ABA (CPT 97151 to 97158 range) through both fee-for-service and managed care plans, and plan policies can differ.

How we handle it: Identifiable data and all work in your systems stay with our US-based staff. Offshore staff and AI only get task data with identifiers removed. We also read your plan’s provider agreement at onboarding and follow any stricter terms it passes down to you.

Source 1 Source 2

Oklahoma

SoonerCare (Oklahoma Health Care Authority)

Offshore limits apply

The SoonerCare General Provider Agreement says Oklahoma health data must never leave or be accessed from outside the continental US, and bars purchasing offshore services. It applies directly to providers and their subcontractors.

ABA: All SoonerCare ABA services require prior authorization from OHCA.

How we handle it: Identifiable data and all work in your systems stay with our US-based staff. Offshore staff and AI only get task data with identifiers removed. We also read your plan’s provider agreement at onboarding and follow any stricter terms it passes down to you.

Source 1 Source 2

Oregon

Oregon Health Plan (OHP), delivered through Coordinated Care Organizations

No state rule found

We did not find an offshore clause in the 2025 OHP CCO contract template. Federal HIPAA and the individual health plan and payer contracts still apply, so confirm each contract before any offshore access.

How we handle it: HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

Source 1

Pennsylvania

Pennsylvania Medical Assistance (HealthChoices managed care)

No state rule found

We did not find an offshore clause in the 2025 HealthChoices agreement text, though a 2013 federal review listed a Pennsylvania executive order on offshore outsourcing. Federal HIPAA and the individual health plan and payer contracts still apply, so confirm each contract before any offshore access.

ABA: Under 21, ABA is delivered as Intensive Behavioral Health Services (IBHS) through behavioral health MCOs, with prior authorization for several service types.

How we handle it: HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

Source 1 Source 2

Rhode Island

Rhode Island Medicaid (EOHHS, managed care through MCOs)

No state rule found

We did not find a current Rhode Island Medicaid rule on offshore access to PHI. Federal HIPAA and the individual health plan and payer contracts still apply, so confirm each contract before any offshore access.

How we handle it: HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

Source 1

South Carolina

South Carolina Healthy Connections Medicaid (SCDHHS)

No state rule found

We did not find a South Carolina Medicaid rule specific to offshore access or PHI processing. Federal HIPAA and the individual health plan and payer contracts still apply, so confirm each contract before any offshore access.

How we handle it: HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

Source 1

South Dakota

South Dakota Medicaid (Department of Social Services)

No state rule found

We did not find a South Dakota Medicaid rule specific to offshore access or PHI processing in the provider agreement. Federal HIPAA and the individual health plan and payer contracts still apply, so confirm each contract before any offshore access.

How we handle it: HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

Source 1

Tennessee

TennCare

Approval required

TennCare contracts and business associate agreements bar viewing, sharing, or disclosing TennCare PHI outside the US without TennCare's prior written authorization.

ABA: ABA is covered for members under 21 through EPSDT and delivered through the TennCare MCOs, which require prior authorization.

How we handle it: The approval is needed to move PHI or plan work outside the US, and we don’t do either: identifiable data stays with our US-based staff, and offshore staff and AI only get task data with identifiers removed. We check your plan’s provider agreement at onboarding.

Source 1 Source 2 Source 3

Texas

Texas Medicaid (HHSC), delivered mainly through STAR/STAR Kids managed care

Offshore limits apply

The HHSC Uniform Managed Care Contract bars health plans and their subcontractors from doing contract work or keeping Medicaid information outside the US, including remote access from abroad. It is written for plans, not provider billing vendors, but plans may pass terms down in provider agreements.

ABA: ABA became a Texas Health Steps-Comprehensive Care Program benefit effective Feb 1, 2022, for ages 20 and under, with prior authorization and specific modifiers such as HO on 97153.

How we handle it: Identifiable data and all work in your systems stay with our US-based staff. Offshore staff and AI only get task data with identifiers removed. We also read your plan’s provider agreement at onboarding and follow any stricter terms it passes down to you.

Source 1 Source 2

Utah

Utah Medicaid (Department of Health and Human Services, Division of Integrated Healthcare)

No state rule found

We found no Utah-specific Medicaid rule on offshore access or processing. Federal HIPAA and the federal ban on Medicaid payments to entities outside the US still apply, and individual health plan contracts may add limits.

ABA: Utah Medicaid publishes an Autism Spectrum Disorder Services provider manual covering ABA.

How we handle it: HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

Source 1

Vermont

Vermont Medicaid (Department of Vermont Health Access)

No state rule found

We found no general Vermont Medicaid provider rule on offshore access, though at least one state Medicaid data vendor solicitation required work to stay within the continental US. Federal HIPAA still applies and any payer or state contract you sign may add limits.

How we handle it: HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

Source 1

Virginia

Virginia Medicaid (DMAS), including Medallion 4.0 managed care

Offshore limits apply

The Medallion 4.0 managed care contract bars offshore servicing of member PHI by health plans or their subcontractors. DMAS enforced it in 2023 over offshore access to its claims portal.

How we handle it: Identifiable data and all work in your systems stay with our US-based staff. Offshore staff and AI only get task data with identifiers removed. We also read your plan’s provider agreement at onboarding and follow any stricter terms it passes down to you.

Source 1 Source 2

Washington

Apple Health (Washington Health Care Authority)

No state rule found

Apple Health managed care contracts require the plan to be located in the US and exclude claims paid to providers outside the US, but we did not verify a rule on offshore handling of PHI by billing vendors. Federal HIPAA and each plan's contract still apply.

How we handle it: HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

Source 1

West Virginia

West Virginia Medicaid (Bureau for Medical Services)

No state rule found

We could not verify a West Virginia-specific offshore rule from the primary documents. Secondary sources suggest contracts limit work to the US apart from some administrative tasks, so check each West Virginia MCO or BMS agreement before using any offshore staff.

How we handle it: HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

Source 1

Wisconsin

Wisconsin Medicaid / BadgerCare Plus (ForwardHealth, DHS)

Offshore limits apply

The ForwardHealth trading partner agreement reportedly limits electronic access to domestic IP addresses and bars sending data offshore.

How we handle it: Identifiable data and all work in your systems stay with our US-based staff. Offshore staff and AI only get task data with identifiers removed. We also read your plan’s provider agreement at onboarding and follow any stricter terms it passes down to you.

Source 1 Source 2

Wyoming

Wyoming Medicaid (Department of Health, Division of Healthcare Financing)

No state rule found

We found no Wyoming-specific rule on offshore access to Medicaid PHI beyond the federal bar on paying entities outside the US. Federal HIPAA and any payer contract still apply.

How we handle it: HIPAA and your payer contracts still apply. Identifiable data stays with our US-based staff, offshore staff and AI only get data with identifiers removed, and we check your plan contracts for offshore terms at onboarding.

Source 1

Please read: this page is a summary of public sources, last reviewed October 2026. It isn’t legal advice. “No state rule found” means we didn’t find a state specific rule, not that offshore work is allowed. Health plan and managed care contracts are often stricter than state rules, so we review yours during onboarding and follow whichever rule is strictest.

Federal law also bars Medicaid payments to entities or financial institutions located outside the US (42 U.S.C. 1396a(a)(80)). All payments for your claims go to your own US accounts.

Billing in More Than One State?

Tell us which states and plans you bill. We’ll walk through how each one is handled on a free 30 minute call.

Book a Free Consultation