Q: My organization is considering outsourcing our coding to an offshore company. Does HIPAA apply only to healthcare entities and business associates located within the United States? If so, what would happen if the offshore third party experiences a breach? What are the risks associated with this decision?
