Skip to main content
All articles

Business · 11 min read

Do Philippine Clinics Need HIPAA Compliance?

HIPAA binds US covered entities and their business associates. A clinic in Cebu is neither. Here is when it does apply.

Studio Aurora
Studio Aurora·September 10, 2026

Share

Do Philippine Clinics Need HIPAA Compliance?

Key takeaways

  • A Philippine clinic treating Filipino patients has no HIPAA obligation. RA 10173, the Data Privacy Act, applies instead.
  • HIPAA reaches Philippine organisations through contract, not territory, when they handle protected health information for a US covered entity under a Business Associate Agreement.
  • Medical BPOs, transcription, billing, telehealth serving US patients, and healthcare software vendors are the genuine exceptions.
  • Treating a foreign tourist does not create a HIPAA obligation; a payer or contractual relationship with a US entity might.
  • Calling your site HIPAA-compliant when you have no US covered entity relationship is meaningless at best and misleading at worst.

No. A clinic in the Philippines treating Filipino patients has no HIPAA obligation. HIPAA is United States legislation, it binds US covered entities and their business associates, and a dental practice in Cebu is neither. The law that applies is the Data Privacy Act of 2012, RA 10173, enforced by the National Privacy Commission.

That answer is straightforward, but the question keeps being asked for a reason, and there are genuine exceptions where HIPAA does reach Philippine organisations. This explains when it applies, when it does not, and why building to the wrong standard is a costly mistake in both directions.

Why do so many Philippine clinics think they need HIPAA?

Three reasons, and none of them are that HIPAA applies.

Search results are American. Search for healthcare website compliance and most of what returns is written for a US audience. The advice is competent and about a different jurisdiction.

Website templates carry it. Practice website templates and page builders are largely built for the US market. Buy one and you inherit a privacy policy referencing HIPAA and naming no Philippine entity.

Agencies use it as a selling point. "HIPAA-compliant website design" sounds authoritative to a clinic owner who has not been told what governs them. Some agencies offering it in the Philippine market are selling a US standard to a domestic buyer who does not need it, and a clinic owner has little way of knowing that from the pitch.

There is a fourth reason worth naming: HIPAA has become shorthand for taking health data seriously. A clinic asking for it is often expressing a reasonable instinct, that patient information deserves protection, and simply reaching for the only framework it has heard of. The instinct is right; the framework is the wrong one.

The result is Philippine clinics with privacy policies referencing a foreign statute, which signals to a regulator that no real assessment of their actual obligations was done.

When does HIPAA genuinely apply to a Philippine organisation?

It applies through contract rather than territory. Specifically, when a Philippine organisation handles protected health information on behalf of a US covered entity, it becomes a business associate, and obligations flow through a Business Associate Agreement.

The organisations this actually affects:

Medical BPOs and healthcare outsourcing. Handling US patient records, claims, or coding.

Medical transcription providers. Processing dictation from US clinicians.

Revenue cycle and billing companies. Working US insurance claims.

Telehealth operators serving US patients. Where the patient is in the United States.

Software vendors with US healthcare clients. If your product stores or transmits protected health information for a US covered entity.

Clinics treating US-insured patients where a US payer relationship creates the obligation.

If you are in one of these, HIPAA is real and specific, and our HIPAA-compliant website design page covers what it requires.

How do the two laws differ in practice?

HIPAA (US)Data Privacy Act (Philippines)
Applies toUS covered entities and business associatesOrganisations processing personal data of individuals in the Philippines
RegulatorUS Department of Health and Human ServicesNational Privacy Commission
ScopeProtected health informationAll personal data, with a stricter tier for sensitive personal information
Consent modelDetailed rules on uses and disclosuresConsent must be freely given, specific, informed, evidenced
Key documentNotice of Privacy PracticesPrivacy notice, with DPO and possible NPC registration
Breach handlingDefined notification requirementsNotification to NPC and affected individuals per the Act

The important structural difference is scope. HIPAA is health-specific. The Data Privacy Act covers all personal data and then applies stricter treatment to sensitive categories, which include health. A Philippine clinic is therefore regulated on everything it collects, not only clinical information.

What does building to the wrong standard actually cost?

Both directions cause real problems.

Building to HIPAA when the DPA applies. You end up with documentation naming the wrong regulator and the wrong rights, and no designated Data Protection Officer. Meanwhile the obligations that do bind you, consent structure, purpose limitation, breach notification to the NPC, registration where required, go unaddressed. You have paid for compliance work that does not answer the question a Philippine regulator would ask.

Building to neither. More common than either. A template privacy policy, one bundled consent checkbox, and an appointment form emailing patient details to a shared inbox.

Assuming DPA when HIPAA also applies. The failure mode for BPOs and telehealth operators. Meeting Philippine obligations does not discharge a Business Associate Agreement, and the contractual consequences of breaching one are usually more immediate than any regulatory penalty.

What if you serve both Filipino and foreign patients?

Common for hospitals and clinics in medical tourism destinations, and the answer is that jurisdiction is not decided by the patient's nationality.

A Filipino clinic treating a walking-in American tourist is not thereby a HIPAA business associate. There is no US covered entity in the relationship and no Business Associate Agreement. The Data Privacy Act governs, because you are an organisation processing personal data in the Philippines.

What can change the analysis is a contractual or payer relationship with a US entity, such as billing a US insurer or operating under agreement with a US provider. That is a contract question, and it is worth asking directly rather than assuming either way.

Separately, if you handle data of individuals in the EU or UK, other regimes may be relevant. The general point holds: your obligations follow the relationships and jurisdictions you actually operate in, not the nationality of whoever walks through the door.

If HIPAA does apply to you, what does that involve?

For the organisations genuinely in scope, the obligation arrives through a Business Associate Agreement, and the BAA is the document that matters more than any general description of HIPAA.

A BAA typically sets out what protected health information you may handle and for what purposes, the safeguards you must maintain, your obligations if a breach occurs including notification timelines, restrictions on subcontracting, and what happens to the data when the agreement ends. Terms vary by client, and the practical consequence is that two US clients may impose materially different requirements on the same Philippine provider.

The website implications for a business associate are usually narrower than people expect, because the protected health information generally lives in operational systems rather than on a marketing site. What matters on the public site is not overstating your status, not collecting protected health information through public forms, and being accurate about certifications and attestations you actually hold.

The heavier work sits in access control, audit logging, encryption, staff training, and subcontractor management, which are operational programmes rather than web design decisions. Anyone offering to make you HIPAA compliant through a website build alone has misunderstood where the obligation lives.

Can both laws apply at the same time?

Yes, and for Philippine BPOs and telehealth operators this is the normal situation rather than an edge case.

If you are a Philippine company handling US protected health information, you are simultaneously a business associate under HIPAA through your BAA, and a personal information controller or processor under the Data Privacy Act because you are processing personal data in the Philippines. Both sets of obligations run in parallel.

That has two practical consequences. First, meeting one does not discharge the other, so a company with strong HIPAA controls can still be non-compliant domestically if it has no Data Protection Officer and no NPC posture. Second, where the two differ, you generally need to satisfy the stricter requirement rather than choosing between them.

Employee data is the case most often missed. A Philippine BPO may run excellent HIPAA controls over client data while handling its own staff records with no privacy notice and no retention policy, which is squarely a Data Privacy Act matter and has nothing to do with the US client at all.

What should a Philippine clinic build to instead?

Six things, all specific to RA 10173 and none of which require a US framework.

A privacy notice written for your practice, naming your clinic and your Data Protection Officer, stating what you collect, why, how long you keep it, and what rights patients have under Philippine law.

Consent separated by purpose, with marketing distinct from booking, unticked, and recorded. The detail is in Data Privacy Act consent for clinic websites.

Collection limited to purpose. Short public forms, detail gathered after confirmation. See what patient data a clinic website should actually collect.

Security measures. HTTPS throughout, controlled storage of submissions rather than a shared inbox, access limited to staff who need it.

Breach readiness. Knowing what data you hold and where, so notification within the prescribed period is possible.

A designated Data Protection Officer, typically an existing staff member with the role formally assigned.

Our Data Privacy Act compliance page covers these in full, including third-party tooling and NPC registration.

How do you tell whether an agency understands this?

Ask one question: which law applies to my clinic, and why?

An agency that answers "the Data Privacy Act, RA 10173, because you process personal data of individuals in the Philippines" understands your position. One that leads with HIPAA without asking whether you serve US covered entities is selling a template.

Two follow-ups are worth asking. Where will appointment submissions be stored, and who can access them? And can you show me consent handling you have built for a Philippine clinic? Both are answerable in a sentence by anyone who has actually done this work.

What about the word "HIPAA-compliant" in marketing?

Be careful using it about your own practice.

If you are a Philippine clinic with no US covered entity relationship, describing your website as HIPAA-compliant is at best meaningless and at worst misleading, because HIPAA compliance is a status defined by obligations you do not have. It may also give patients a false impression about which protections apply.

If you genuinely are a business associate under a Business Associate Agreement, the claim is meaningful and you should be able to evidence it.

The clearer message for a domestic clinic is the accurate one: that you handle patient information in line with the Data Privacy Act. Filipino patients are increasingly aware of the NPC and their rights, and citing the law that actually protects them is more persuasive than citing a foreign one.

What should you tell patients?

Say what is true, in language they recognise.

Patients rarely ask which statute governs a clinic, but they do want to know that their information is handled carefully. A short, plain statement, that you collect only what is needed, keep it securely, do not share it outside the practice except where care requires, and will tell them what you hold if they ask, communicates more than any acronym.

Where naming the law helps is in your privacy notice, because it demonstrates you know which regime applies. Referring to the Data Privacy Act and the National Privacy Commission signals a practice that has assessed its actual position. Referring to HIPAA signals the opposite, however impressive it sounds.

What should you do next?

Open your website's privacy policy and search it for the word HIPAA. If it appears and you do not serve a US covered entity, that document was not written for your practice and neither, probably, was the rest of your compliance setup.

Replace it with a notice describing what your clinic actually does, separate your consents, shorten your forms, and check where submissions land. That sequence addresses the obligations that genuinely apply to you.

For the full picture see Data Privacy Act compliance for Philippine healthcare websites, and for the clinic-specific build see medical clinic website design and healthcare website design. If you want a straight answer about which standard applies to your situation, book a call.

This is general information rather than legal advice. For obligations specific to your organisation, particularly if you handle data for US entities, consult qualified counsel.

healthcaredata privacyphilippines

Frequently asked questions

Do Philippine clinics need to be HIPAA compliant?

No. HIPAA is United States legislation binding US covered entities and their business associates. A clinic in the Philippines treating Filipino patients is neither, and is governed instead by the Data Privacy Act of 2012 (RA 10173), enforced by the National Privacy Commission.

When does HIPAA apply to a Philippine organisation?

Through contract rather than territory, when you handle protected health information on behalf of a US covered entity and become a business associate under a Business Associate Agreement. This affects medical BPOs, transcription providers, billing companies, telehealth operators serving US patients, and healthcare software vendors with US clients.

What if my clinic treats American tourists?

That alone does not create a HIPAA obligation, because there is no US covered entity in the relationship and no Business Associate Agreement. The Data Privacy Act governs, since you are processing personal data in the Philippines. A billing or contractual relationship with a US payer could change the analysis.

Why do so many Philippine clinic websites mention HIPAA?

Because search results on healthcare compliance are largely American, website templates are built for the US market and carry HIPAA references by default, and some agencies market HIPAA-compliant design to Philippine buyers who do not need it. A policy citing a foreign statute signals that no assessment of actual obligations was done.

Work with us

Let's build something
great together

Have a project in mind? We'd love to hear about it and explore how we can help bring your vision to life.

Get in touch