Data Residency
Also known as: Data location, Data storage location
Data residency is the physical location where data and its copies are stored, such as a country or region.
Data residency is the physical location where data is stored, usually named as a country or region. It covers every copy, not just the main one. For a healthcare team, that means checking where patient records live across the website, database, backups, and outside services.
Why data residency matters in healthcare
Location can affect whether a service meets a law, contract, or practice policy. A vendor's office address does not tell you where its servers keep your data. A cloud region setting may cover the main database while other services keep copies elsewhere. Hospital and payer security questionnaires also routinely require US data residency, even though HIPAA does not, as our guide on whether HIPAA applies to non-US sites notes.
Some states set location rules, often called data localization laws. Since January 1, 2026, Texas health record storage rules have required covered entities to keep electronic health records physically in the United States or a US territory. Texas defines covered entities more broadly than HIPAA does, and on its face the term includes business associates. Florida's health data location law has applied since July 1, 2023, to providers that use certified EHR technology. Their offsite patient data must stay in the continental United States, its territories, or Canada. A Canadian region meets the Florida rule but not the Texas one.
Check each stored copy
Take a practice that hosts its portal in a US data center. Its nightly backup could go to another country. Both locations belong in its data map. Encryption protects a copy, but it does not change where that copy sits.
- List the main database, uploaded files, exports, and logs that hold patient data.
- Check backups, replicas, recovery sites, and copies kept by each outside service.
- Ask vendors where they keep each copy and how they handle changes.
- Record the evidence and review it when services or settings change.
When you ask vendors about location, ask about the BAA too. n8n Cloud, for example, keeps its data and backups in Germany and signs no BAA, so our review of whether n8n is HIPAA compliant points to self-hosting. Under HIPAA, the missing BAA is the blocker, not the location.
Location, sovereignty, and access
Data residency describes where data sits. Data sovereignty is the idea that data is subject to the laws of the place where it is generated or processed. The terms are related, but they are not synonyms. Take a Canadian vendor that handles PHI for a US covered entity. It must meet its BAA and Canadian privacy law at once, as our guide to HIPAA and PIPEDA in Canada explains.
Where staff may access records is a separate question. A download can create a new stored copy wherever the person sits.
What HIPAA requires
HIPAA does not mention data residency or say where ePHI must be stored. HHS cloud guidance lets a cloud provider store ePHI outside the United States. The conditions are a BAA and compliance with the other HIPAA rules. HHS also warns that offshore storage may increase risks. These Security Rule parts apply:
- Risk analysis and risk management. 45 CFR § 164.308(a)(1)(ii)(A) and (B) are both required. HHS says to weigh location risks in both.
- Business associate contracts. 45 CFR § 164.308(b)(1) to (b)(3) require a written contract, the BAA, between a covered entity and each business associate that handles ePHI, and between a business associate and each of its subcontractors. Its terms are set in § 164.314(a).
- Data backup plan. 45 CFR § 164.308(a)(7)(ii)(A) is required. It calls for retrievable exact copies of ePHI, so there is always more than one copy to place.
- Accountability. 45 CFR § 164.310(d)(2)(iii) is addressable. It asks for a record of the movements of hardware and electronic media.
How it fits with other safeguards
A data center is the facility. An off-site backup keeps a recovery copy away from the main systems. Data residency asks which country or region each one sits in. A US storage location alone does not prove that HIPAA rules are met. Teams still need access controls, a risk analysis, and a business associate agreement with each vendor that holds ePHI.
Sources: HHS guidance on HIPAA and cloud computing, 45 CFR § 164.308, 45 CFR § 164.310, 45 CFR § 164.314, the Texas SB 1188 enrolled text, Florida Statutes 408.051, and IBM on data sovereignty and data residency.