The Department of Health and Human Services treats a cloud provider that maintains ePHI as a business associate even when that provider holds nothing but encrypted data and has no key. Encryption limits what the provider can read and does nothing to move it out of the chain of accountability.
The same split runs through jurisdiction. A party can sit inside that chain and outside your legal system at once, with paperwork that looks complete either way.
In a VDI deployment the chain can run several parties deep: the software vendor, the hosting partner, the underlying cloud, the support subcontractor. Every one of them that touches PHI signs something, because flow-down under the 2013 Omnibus Rule reaches subcontractors too. What none of those agreements records is the country the signatory is organized in, the law that governs its operations, or whether an authority outside the agreement can compel it to produce what it holds.
Residency asks where patient records are held. Sovereignty asks which authorities can order them produced. What follows applies the second question to PHI.
The mechanism
Under the US CLOUD Act, a provider subject to US jurisdiction can be compelled by US legal process to produce data in its possession, custody, or control even when the data sits outside the United States. The obligation attaches to the provider, not the server location. That is why a local data center settles residency and leaves jurisdiction open.
For buyers subject to European rules, this is already a formal step. The transfer assessment that followed the Schrems II ruling asks the exporter to examine whether the law of the destination country permits public authorities to demand access, and extraterritorial reach is one of the things it weighs. Health data sits in a special category under the GDPR, which raises what is at stake.
Where this lands in a VDI evaluation
Three consequences follow. The first is specific to healthcare. The other two hold after decisions that look like they close the question.
- The agreements are already mandated. The place to record jurisdiction is the document set that HIPAA already requires. It is a new field, not a new program of work.
- Key custody is its own question. For each party in the chain, ask who holds the keys. That is a jurisdiction question, not just a security one.
- An on-premises decision does not automatically close it. Updates, licensing checks, diagnostics and remote support can each move information out of the environment. Get the recipient of each channel named in writing, along with the jurisdiction that governs it.
We have set out five questions that test a vendor’s delivery chain, covering the legal entities involved, what each party can reach, and how a vendor handles a government demand. They are written to go straight into an RFP.
Onde a Inuvika entra
Here is where we stand on those questions.
We contract from Canada or the UK and are not subject to US jurisdiction. For EU-based customers, the jurisdiction of our terms and conditions is Ireland. That covers our own entity. The rest of the chain depends on how you deploy.
On premises, OVD Enterprise collects no customer data (other than voluntary subscription expiry and total use numbers). That materially reduces what we could ever be asked to produce. Where a deployment must go further than that, OVD Enterprise can be used in a fully “air-gapped” environment. If you would rather take the service managed, we deliver it through independent local hosting partners, in your country, rather than a single global operator.
OVD Enterprise is Linux-based, delivers Windows and Linux applications and desktops to any device, and is hypervisor and cloud agnostic, working with any Active Directory or LDAP directory. That matters here for one reason: the delivery chain stays a set of choices you make rather than a legal footprint you inherit.
Genomics England selected us to deliver the secure virtualized applications and desktop environment for the 100,000 Genomes Project. Canadian Health Systems delivers applications as a service to medical clinics. Droguería DelSud, Argentina’s largest health distributor, moved its partner network off legacy VPN access and onto secure virtual workspaces.
The questions above are worth putting to everyone on a shortlist, us included. See how we deliver virtual desktops in healthcare.
Perguntas frequentes
Does a business associate agreement settle the sovereignty question?
No. It settles what a signatory may do with PHI. Which legal system that signatory answers to is a separate fact, and it has to be written down rather than inferred from the contract.
Does HIPAA require us to consider where a vendor is based?
Not directly. The HHS Office for Civil Rights has said the HIPAA Rules set no requirements specific to ePHI processed or stored outside the United States, while noting that overseas arrangements can raise special considerations about how enforceable your privacy and security protections are over that data, and that this belongs in the risk analysis the Security Rule already requires. Jurisdiction is the sharper version of the same question.
We already run a transfer assessment under the GDPR. Is that the same question?
It is the closest thing to it. The assessment that followed Schrems II asks whether the law of the destination country lets public authorities demand access, which is the jurisdiction question in another form. It is built around transfers of personal data out of the EEA, so it may not be triggered by a deployment that keeps data in country even where the vendor, or part of its support chain, sits abroad. Worth checking which of your arrangements it actually reaches.

