Florida's Health Data Location Law (408.051): The US and Canada Rule, Explained (2026)
HIPAA Compliant Hosting · https://hipaacomplianthosting.com/blog/florida-health-data-storage-law-408-051
Last updated: September 23, 2026
The Florida health data storage law requires offsite patient data to stay in the continental United States, its territories, or Canada. The Florida health data storage law is section 408.051(3), in force since July 1, 2023. It covers Florida health care providers that use certified electronic health record (EHR) technology, including data held by cloud vendors. Facilities licensed by the Agency for Health Care Administration (AHCA) also sign an affidavit, under penalty of perjury, at each licensure and renewal. The section sets no fine; AHCA uses its licensing penalties. HIPAA has no such rule, so this is a Florida-only layer on top of it. We sell HIPAA compliant hosting, so weigh our advice accordingly.
TL;DR: Quick answer
The rule applies to providers that use certified EHR technology. It reaches seven provider groups, from hospitals and nursing homes to every chapter 456 practitioner and pharmacies (408.051(2)(d)).
The Florida health data storage law says offsite data must be "physically maintained in the continental United States or its territories or Canada" (408.051(3)).
AHCA licensees sign the section 408.810(14) affidavit at first licensure and every renewal. Practitioners licensed by the Department of Health sign none.
The statute governs where data is physically kept. It says nothing about remote access or offshore staff. On its face, it covers cloud backups and replicas.
No fine is written into the section. AHCA can fine, deny, or revoke licenses (408.813, 408.815). We found no reported enforcement as of September 23, 2026.
What Florida's health data storage law requires

Here is subsection (3) from the 2026 Florida Statutes, read September 23, 2026.
(3) SECURITY AND STORAGE OF PERSONAL MEDICAL INFORMATION. In addition to the requirements in 45 C.F.R. part 160 and subparts A and C of part 164, a health care provider that utilizes certified electronic health record technology must ensure that all patient information stored in an offsite physical or virtual environment, including through a third-party or subcontracted computing facility or an entity providing cloud computing services, is physically maintained in the continental United States or its territories or Canada. This subsection applies to all qualified electronic health records that are stored using any technology that can allow information to be electronically retrieved, accessed, or transmitted.
In plain English, the Florida health data storage law has three parts. It applies to providers that use certified EHR technology. It covers all patient information stored offsite, including with cloud vendors. That data must sit in the continental United States, a US territory, or Canada.
The opening words, "In addition to," tie it to HIPAA (45 CFR part 160 and part 164, subparts A and C). The Florida health data storage law adds a duty; it replaces none. It came from Chapter 2023-33 (CS/CS/SB 264), approved May 8, 2023. No later amendment has changed subsection (3).
Who has to comply with the Florida health data storage law

The Florida health data storage law has two layers. The rule binds providers that use certified EHR technology. The affidavit binds only AHCA licensees.
Status | Who | Statutory basis |
|---|---|---|
Covered | AHCA-licensed providers: hospitals, surgical centers, nursing homes, assisted living, home health, hospices, clinics | 408.051(2)(d)1 |
Covered | Chapter 456 practitioners: physicians, nurses, dentists, pharmacists, psychologists, counselors | 408.051(2)(d)2 |
Covered | Radiologic personnel, home health aides, mental health service providers, continuing care facilities, pharmacies | 408.051(2)(d)3 to 7 |
Trigger | Uses EHR technology certified under Public Health Service Act section 3001(c)(5) | 408.051(2)(a) |
Unclear | Stand-alone chapter 483 labs not licensed by AHCA | Not listed in 408.051(2)(d) |
Unclear | A certified EHR user's data in non-certified systems | Commentary (Bradley, May 18, 2023) |
A provider with no certified EHR is outside subsection (3) on its face. The last row is commentary. Bradley Arant Boult Cummings wrote on May 18, 2023 that the text could reach all patient information such a provider stores. No court or agency has said so. For the HIPAA side, see our guide on who needs HIPAA compliant hosting.
The AHCA affidavit, word for word

The affidavit is how the Florida health data storage law reaches licensed facilities. Section 408.810(14) reads as follows.
(14) The licensee must sign an affidavit at the time of his or her initial application for a license and on any renewal applications thereafter that attests under penalty of perjury that he or she is in compliance with s. 408.051(3). The licensee must remain in compliance with s. 408.051(3) or the licensee shall be subject to disciplinary action by the agency.
AHCA carries this as item (7) on Form 3110-1011 (August 2023), the home health agency application. Item (7) cites "sections 408.810(14) and 408.051(3), FS" and then repeats the storage rule word for word. We read only that form, so check yours. Item (8) is a separate promise about a "foreign country of concern" (408.810(15)).
The affidavit omits the certified EHR condition. A licensee with no certified EHR is arguably compliant, since the rule does not reach it. The statute is silent, and we could not read any AHCA guidance. Practitioners licensed by the Department of Health sign no affidavit but are still bound.
What counts as "physically maintained" outside the allowed area
On its face, the Florida health data storage law reaches every stored copy. Check these places:
Primary region. Where your EHR, portal, or app database runs.
Replicas. A failover or read replica outside the allowed area counts.
Backups. An off-site backup is a stored copy too. Our guide to HIPAA backup and disaster recovery covers how copies are made. Jackson Lewis warned on March 25, 2026: "Architectures designed for redundancy or resilience may now create compliance issues" (law firm commentary).
Logs and analytics. Tools that capture patient information hold stored copies.
SaaS vendors. Your EHR, billing, and add-on vendors each pick their storage regions.
Cloud services. "Cloud computing" follows NIST Special Publication 800-145, through section 282.0041 (408.051(2)(b)).
The statute says nothing about remote access, offshore support staff, or data in transit. "Electronically retrieved, accessed, or transmitted" describes the storage technology covered, not an access rule. So the Florida health data storage law is not a remote-access ban. Still, a file saved on an offshore laptop is a stored copy in our reading, so ask counsel about offshore staff.
Where the data may sit: the US, its territories, and Canada

The first committee draft allowed only "the continental United States" (March 15, 2023). On March 22, 2023, the Senate Rules Committee expanded it "to also allow for such storage within U.S. territories and Canada" (staff analysis). The analysis gives no reason. AWS Regions sort as follows as of September 23, 2026.
AWS Region | Country | Allowed under 408.051(3)? |
|---|---|---|
US East (N. Virginia), US East (Ohio), US West (N. California), US West (Oregon) | United States | Yes |
AWS GovCloud (US-East), AWS GovCloud (US-West) | United States | Yes |
Canada (Central), Canada West (Calgary) | Canada | Yes; Calgary is an opt-in Region you enable first |
Mexico (Central) | Mexico | No |
All other Regions | Outside the allowed area | No |
Location is separate from the contract. Our answer to is AWS HIPAA compliant covers the AWS BAA. Hawaii is a gray area under the Florida health data storage law. "Continental United States" is undefined, and Hawaii is neither continental nor a territory. No guidance we found settles it.
Deadlines, enforcement, and penalties

The Florida health data storage law names no fine of its own.
Item | Rule | Source |
|---|---|---|
Effective date | July 1, 2023 | Chapter 2023-33, section 12 |
Affidavit | Under penalty of perjury, at first application and every renewal | 408.810(14) |
AHCA fines | Each day is a separate violation; amounts by class, set per provider type | 408.813 |
Denial or revocation | For a violation, or a false statement of material fact in an application | 408.815 |
Department of Health practitioners | No affidavit; general discipline is the likely route (our reading) | 456.072(1)(k) |
Private lawsuits | None for offshore storage | 408.051(8) |
Reported enforcement | None found as of September 23, 2026 | Our search |
How it fits with HIPAA
HIPAA has no data residency rule. HHS's Office for Civil Rights (OCR) cloud guidance says a cloud provider may store ePHI outside the United States. The condition is a business associate agreement (BAA) and compliance with the other HIPAA rules. OCR warns that offshore storage "may increase the risks and vulnerabilities to the information" (question 9). If you run a site from outside the United States, the HIPAA side is covered in is HIPAA only for US sites.
The Florida health data storage law is stricter on location but removes no HIPAA duty. You still need a BAA with each vendor that holds patient data (45 CFR § 164.308(b)). Our HIPAA business associate agreement guide covers the contract; Florida adds one term: where data is kept. Florida's data breach law, section 501.171, has no location rule either.
What to check in your hosting and vendor contracts

This list builds the record behind your affidavit. It also documents compliance with the Florida health data storage law.
The primary region, in writing.
Every replica, snapshot, and disaster recovery region, in writing.
Your host's subprocessors, and where each stores data.
Storage regions for your SaaS EHR and add-on vendors, backups included.
Where log, error tracking, and analytics tools keep patient information.
A BAA or data processing clause that names allowed locations and requires notice before changes.
A dated inventory of systems and locations before each renewal, filed with your risk analysis.
Moving hosts? Our guide to HIPAA compliant cloud hosting lists what to ask.
Florida vs Texas: offshore storage of patient records

Texas SB 1188 is a separate law with different terms. Its provisions do not apply in Florida.
Question | Florida, section 408.051(3) | Texas SB 1188, Health and Safety Code 183.002 |
|---|---|---|
What is required | Offsite patient information "physically maintained in the continental United States or its territories or Canada"; since July 1, 2023 | Electronic health records "physically maintained in the United States or a territory of the United States"; storage on or after January 1, 2026 |
Who is covered | Seven provider groups that use certified EHR technology; AHCA licensees sign an affidavit | Covered entities under Health and Safety Code 181.001, including practitioners and business associates; some long-term care and waiver providers excluded |
Penalties | No fine in the section; AHCA licensing penalties; perjury exposure | Up to $5,000 negligent, $25,000 knowing, or $250,000 for financial gain, per violation; the Attorney General enforces |
The gap is Canada. A Canadian region meets the Florida health data storage law but not the Texas rule.
If you want the location question answered in writing
We sell HIPAA compliant hosting, so weigh this as a pitch. Our managed HIPAA cloud hosting runs in US AWS regions, with backups kept in the US. We put the region and backup location in writing with the BAA paperwork. You attest; we supply the facts. Managed plans include migration, and the BAA is signed within 24 hours.
The honest inverse: if you use no certified EHR technology, the Florida health data storage law does not reach you, and nothing changes. AHCA licensees still sign the affidavit. If your host already confirms in writing that every copy sits in the US or Canada, you do not need us. Otherwise, see our HIPAA compliant hosting plans, request a quote, or send us your vendor list.
Frequently asked questions
Does Florida law prohibit storing patient data outside the United States?
Yes, for providers that use certified EHR technology. Their offsite patient information must stay in the continental United States, its territories, or Canada (408.051(3)). Europe, Asia, and Mexico do not qualify.
Can Florida patient records be stored in Canada?
Yes. The statute names Canada, added on March 22, 2023. AWS Canada (Central) and Canada West (Calgary) qualify on the text. Texas SB 1188 does not allow Canada.
Does the Florida offshore storage law apply to doctors' offices or only hospitals?
Doctors' offices too. The Florida health data storage law covers every chapter 456 practitioner who uses certified EHR technology. Only AHCA licensees sign the affidavit.
Does HIPAA require PHI to be stored in the United States?
No. HHS guidance allows a cloud provider that stores ePHI abroad, if you sign a BAA and follow the other HIPAA rules. Florida adds a location rule on top.
What happens if a Florida licensee signs the AHCA affidavit falsely?
The affidavit is signed under penalty of perjury. AHCA can also deny or revoke a license for a false statement (408.815) and impose fines (408.813). We found no reported case as of September 23, 2026.
Recap: Florida health data storage law
The Florida health data storage law, section 408.051(3), has applied since July 1, 2023. Certified EHR users must keep all offsite patient information, backups included, in the continental United States, its territories, or Canada. AHCA licensees attest to it at each renewal. HIPAA still applies in full.
This article is general information, not legal advice. Statutes as read on September 23, 2026. AHCA guidance could not be retrieved; its site blocked our requests. Confirm with counsel and AHCA, and base your safeguards on a documented risk analysis. We sell HIPAA compliant hosting. Reviewed September 2026.
Sources
Florida Statutes (2026): 408.051, 408.810, 408.802, 408.813, 408.815, 456.001, 456.072, 282.0041.
Chapter 2023-33, Laws of Florida and the CS/CS/SB 264 bill history.
Florida Senate: Rules Committee analysis, March 22, 2023.
AHCA Form 3110-1011 (August 2023): AHCA licensure applications page.
HHS OCR: Guidance on HIPAA and Cloud Computing.
45 CFR § 164.308: ecfr.gov.
AWS: AWS Regions.