Skip to main content

Florida's Health Data Location Law (408.051): The US and Canada Rule, Explained (2026)

By Joseph Abear ·
Banner reading Florida 408.051 keeps patient data in the US or Canada: allowed in the continental US, its territories, or Canada, not allowed in Mexico or overseas, and Hawaii unsettled, since July 1, 2023

Last updated: September 23, 2026

The Florida health data storage law requires offsite patient data to stay in the continental United States, its territories, or Canada. The Florida health data storage law is section 408.051(3), in force since July 1, 2023. It covers Florida health care providers that use certified electronic health record (EHR) technology, including data held by cloud vendors. Facilities licensed by the Agency for Health Care Administration (AHCA) also sign an affidavit, under penalty of perjury, at each licensure and renewal. The section sets no fine; AHCA uses its licensing penalties. HIPAA has no such rule, so this is a Florida-only layer on top of it. We sell HIPAA compliant hosting, so weigh our advice accordingly.

TL;DR: Quick answer

  • The rule applies to providers that use certified EHR technology. It reaches seven provider groups, from hospitals and nursing homes to every chapter 456 practitioner and pharmacies (408.051(2)(d)).

  • The Florida health data storage law says offsite data must be "physically maintained in the continental United States or its territories or Canada" (408.051(3)).

  • AHCA licensees sign the section 408.810(14) affidavit at first licensure and every renewal. Practitioners licensed by the Department of Health sign none.

  • The statute governs where data is physically kept. It says nothing about remote access or offshore staff. On its face, it covers cloud backups and replicas.

  • No fine is written into the section. AHCA can fine, deny, or revoke licenses (408.813, 408.815). We found no reported enforcement as of September 23, 2026.

What Florida's health data storage law requires

Quote of Florida Statutes section 408.051(3) requiring providers that use certified EHR technology to keep offsite patient information, including cloud storage, physically in the continental United States, its territories, or Canada

Here is subsection (3) from the 2026 Florida Statutes, read September 23, 2026.

(3) SECURITY AND STORAGE OF PERSONAL MEDICAL INFORMATION. In addition to the requirements in 45 C.F.R. part 160 and subparts A and C of part 164, a health care provider that utilizes certified electronic health record technology must ensure that all patient information stored in an offsite physical or virtual environment, including through a third-party or subcontracted computing facility or an entity providing cloud computing services, is physically maintained in the continental United States or its territories or Canada. This subsection applies to all qualified electronic health records that are stored using any technology that can allow information to be electronically retrieved, accessed, or transmitted.

In plain English, the Florida health data storage law has three parts. It applies to providers that use certified EHR technology. It covers all patient information stored offsite, including with cloud vendors. That data must sit in the continental United States, a US territory, or Canada.

The opening words, "In addition to," tie it to HIPAA (45 CFR part 160 and part 164, subparts A and C). The Florida health data storage law adds a duty; it replaces none. It came from Chapter 2023-33 (CS/CS/SB 264), approved May 8, 2023. No later amendment has changed subsection (3).

Who has to comply with the Florida health data storage law

Chart of who the Florida offsite patient data rule covers: AHCA licensed providers, chapter 456 practitioners, and other listed groups using certified EHR technology; providers without one are outside it; two cases are unclear

The Florida health data storage law has two layers. The rule binds providers that use certified EHR technology. The affidavit binds only AHCA licensees.

Status

Who

Statutory basis

Covered

AHCA-licensed providers: hospitals, surgical centers, nursing homes, assisted living, home health, hospices, clinics

408.051(2)(d)1

Covered

Chapter 456 practitioners: physicians, nurses, dentists, pharmacists, psychologists, counselors

408.051(2)(d)2

Covered

Radiologic personnel, home health aides, mental health service providers, continuing care facilities, pharmacies

408.051(2)(d)3 to 7

Trigger

Uses EHR technology certified under Public Health Service Act section 3001(c)(5)

408.051(2)(a)

Unclear

Stand-alone chapter 483 labs not licensed by AHCA

Not listed in 408.051(2)(d)

Unclear

A certified EHR user's data in non-certified systems

Commentary (Bradley, May 18, 2023)

A provider with no certified EHR is outside subsection (3) on its face. The last row is commentary. Bradley Arant Boult Cummings wrote on May 18, 2023 that the text could reach all patient information such a provider stores. No court or agency has said so. For the HIPAA side, see our guide on who needs HIPAA compliant hosting.

The AHCA affidavit, word for word

Quote of Florida section 408.810(14): AHCA licensees sign an affidavit under penalty of perjury at first licensure and every renewal, while Department of Health practitioners sign none but are still bound by the rule

The affidavit is how the Florida health data storage law reaches licensed facilities. Section 408.810(14) reads as follows.

(14) The licensee must sign an affidavit at the time of his or her initial application for a license and on any renewal applications thereafter that attests under penalty of perjury that he or she is in compliance with s. 408.051(3). The licensee must remain in compliance with s. 408.051(3) or the licensee shall be subject to disciplinary action by the agency.

AHCA carries this as item (7) on Form 3110-1011 (August 2023), the home health agency application. Item (7) cites "sections 408.810(14) and 408.051(3), FS" and then repeats the storage rule word for word. We read only that form, so check yours. Item (8) is a separate promise about a "foreign country of concern" (408.810(15)).

The affidavit omits the certified EHR condition. A licensee with no certified EHR is arguably compliant, since the rule does not reach it. The statute is silent, and we could not read any AHCA guidance. Practitioners licensed by the Department of Health sign no affidavit but are still bound.

What counts as "physically maintained" outside the allowed area

On its face, the Florida health data storage law reaches every stored copy. Check these places:

  • Primary region. Where your EHR, portal, or app database runs.

  • Replicas. A failover or read replica outside the allowed area counts.

  • Backups. An off-site backup is a stored copy too. Our guide to HIPAA backup and disaster recovery covers how copies are made. Jackson Lewis warned on March 25, 2026: "Architectures designed for redundancy or resilience may now create compliance issues" (law firm commentary).

  • Logs and analytics. Tools that capture patient information hold stored copies.

  • SaaS vendors. Your EHR, billing, and add-on vendors each pick their storage regions.

  • Cloud services. "Cloud computing" follows NIST Special Publication 800-145, through section 282.0041 (408.051(2)(b)).

The statute says nothing about remote access, offshore support staff, or data in transit. "Electronically retrieved, accessed, or transmitted" describes the storage technology covered, not an access rule. So the Florida health data storage law is not a remote-access ban. Still, a file saved on an offshore laptop is a stored copy in our reading, so ask counsel about offshore staff.

Where the data may sit: the US, its territories, and Canada

Diagram of where Florida allows offsite patient data: the continental US, US territories, and Canada, including AWS US, GovCloud, and Canada Regions; Mexico and overseas Regions not allowed; Hawaii a gray area

The first committee draft allowed only "the continental United States" (March 15, 2023). On March 22, 2023, the Senate Rules Committee expanded it "to also allow for such storage within U.S. territories and Canada" (staff analysis). The analysis gives no reason. AWS Regions sort as follows as of September 23, 2026.

AWS Region

Country

Allowed under 408.051(3)?

US East (N. Virginia), US East (Ohio), US West (N. California), US West (Oregon)

United States

Yes

AWS GovCloud (US-East), AWS GovCloud (US-West)

United States

Yes

Canada (Central), Canada West (Calgary)

Canada

Yes; Calgary is an opt-in Region you enable first

Mexico (Central)

Mexico

No

All other Regions

Outside the allowed area

No

Location is separate from the contract. Our answer to is AWS HIPAA compliant covers the AWS BAA. Hawaii is a gray area under the Florida health data storage law. "Continental United States" is undefined, and Hawaii is neither continental nor a territory. No guidance we found settles it.

Deadlines, enforcement, and penalties

Timeline and enforcement routes for Florida 408.051: approved May 8, 2023, in force July 1, 2023, no fine in the section, AHCA fines, license denial or revocation, perjury exposure, and no reported enforcement

The Florida health data storage law names no fine of its own.

Item

Rule

Source

Effective date

July 1, 2023

Chapter 2023-33, section 12

Affidavit

Under penalty of perjury, at first application and every renewal

408.810(14)

AHCA fines

Each day is a separate violation; amounts by class, set per provider type

408.813

Denial or revocation

For a violation, or a false statement of material fact in an application

408.815

Department of Health practitioners

No affidavit; general discipline is the likely route (our reading)

456.072(1)(k)

Private lawsuits

None for offshore storage

408.051(8)

Reported enforcement

None found as of September 23, 2026

Our search

How it fits with HIPAA

HIPAA has no data residency rule. HHS's Office for Civil Rights (OCR) cloud guidance says a cloud provider may store ePHI outside the United States. The condition is a business associate agreement (BAA) and compliance with the other HIPAA rules. OCR warns that offshore storage "may increase the risks and vulnerabilities to the information" (question 9). If you run a site from outside the United States, the HIPAA side is covered in is HIPAA only for US sites.

The Florida health data storage law is stricter on location but removes no HIPAA duty. You still need a BAA with each vendor that holds patient data (45 CFR § 164.308(b)). Our HIPAA business associate agreement guide covers the contract; Florida adds one term: where data is kept. Florida's data breach law, section 501.171, has no location rule either.

What to check in your hosting and vendor contracts

Checklist of seven items to get in writing from hosting and software vendors, from the primary region and backup regions to a BAA clause on allowed locations and a dated inventory before each renewal

This list builds the record behind your affidavit. It also documents compliance with the Florida health data storage law.

  1. The primary region, in writing.

  2. Every replica, snapshot, and disaster recovery region, in writing.

  3. Your host's subprocessors, and where each stores data.

  4. Storage regions for your SaaS EHR and add-on vendors, backups included.

  5. Where log, error tracking, and analytics tools keep patient information.

  6. A BAA or data processing clause that names allowed locations and requires notice before changes.

  7. A dated inventory of systems and locations before each renewal, filed with your risk analysis.

Moving hosts? Our guide to HIPAA compliant cloud hosting lists what to ask.

Florida vs Texas: offshore storage of patient records

Comparison of the Florida and Texas patient record location laws: allowed places, Canada allowed only in Florida, who is covered, start dates of July 1, 2023 and January 1, 2026, and penalties

Texas SB 1188 is a separate law with different terms. Its provisions do not apply in Florida.

Question

Florida, section 408.051(3)

Texas SB 1188, Health and Safety Code 183.002

What is required

Offsite patient information "physically maintained in the continental United States or its territories or Canada"; since July 1, 2023

Electronic health records "physically maintained in the United States or a territory of the United States"; storage on or after January 1, 2026

Who is covered

Seven provider groups that use certified EHR technology; AHCA licensees sign an affidavit

Covered entities under Health and Safety Code 181.001, including practitioners and business associates; some long-term care and waiver providers excluded

Penalties

No fine in the section; AHCA licensing penalties; perjury exposure

Up to $5,000 negligent, $25,000 knowing, or $250,000 for financial gain, per violation; the Attorney General enforces

The gap is Canada. A Canadian region meets the Florida health data storage law but not the Texas rule.

If you want the location question answered in writing

We sell HIPAA compliant hosting, so weigh this as a pitch. Our managed HIPAA cloud hosting runs in US AWS regions, with backups kept in the US. We put the region and backup location in writing with the BAA paperwork. You attest; we supply the facts. Managed plans include migration, and the BAA is signed within 24 hours.

The honest inverse: if you use no certified EHR technology, the Florida health data storage law does not reach you, and nothing changes. AHCA licensees still sign the affidavit. If your host already confirms in writing that every copy sits in the US or Canada, you do not need us. Otherwise, see our HIPAA compliant hosting plans, request a quote, or send us your vendor list.

Frequently asked questions

Does Florida law prohibit storing patient data outside the United States?

Yes, for providers that use certified EHR technology. Their offsite patient information must stay in the continental United States, its territories, or Canada (408.051(3)). Europe, Asia, and Mexico do not qualify.

Can Florida patient records be stored in Canada?

Yes. The statute names Canada, added on March 22, 2023. AWS Canada (Central) and Canada West (Calgary) qualify on the text. Texas SB 1188 does not allow Canada.

Does the Florida offshore storage law apply to doctors' offices or only hospitals?

Doctors' offices too. The Florida health data storage law covers every chapter 456 practitioner who uses certified EHR technology. Only AHCA licensees sign the affidavit.

Does HIPAA require PHI to be stored in the United States?

No. HHS guidance allows a cloud provider that stores ePHI abroad, if you sign a BAA and follow the other HIPAA rules. Florida adds a location rule on top.

What happens if a Florida licensee signs the AHCA affidavit falsely?

The affidavit is signed under penalty of perjury. AHCA can also deny or revoke a license for a false statement (408.815) and impose fines (408.813). We found no reported case as of September 23, 2026.

Recap: Florida health data storage law

The Florida health data storage law, section 408.051(3), has applied since July 1, 2023. Certified EHR users must keep all offsite patient information, backups included, in the continental United States, its territories, or Canada. AHCA licensees attest to it at each renewal. HIPAA still applies in full.

This article is general information, not legal advice. Statutes as read on September 23, 2026. AHCA guidance could not be retrieved; its site blocked our requests. Confirm with counsel and AHCA, and base your safeguards on a documented risk analysis. We sell HIPAA compliant hosting. Reviewed September 2026.

Sources

Read full definition

View link to copy manually

Stay current on HIPAA hosting

Practical guidance on compliance, hosting and the rules that actually apply to your practice.

Email me occasional updates about HIPAA hosting and compliance. No more than a few times a month, and you can unsubscribe at any time.