Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What should security teams do when health data…
Governance, Ownership & Risk

What should security teams do when health data is moved across borders?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Governance, Ownership & Risk

Security teams should verify transfer restrictions before data moves, confirm the legal basis for processing, and apply technical and contractual safeguards that match the destination risk. That usually means classifying the data, limiting recipients, documenting approvals, and preserving evidence of compliance. Cross-border movement becomes manageable when transfer decisions are tied to policy, not ad hoc project delivery.

What changes when health data crosses a border?

Once health data leaves its home jurisdiction, the question is no longer just where it is stored. Security teams need to account for transfer rules, local processing constraints, and whether the destination environment can preserve confidentiality, integrity, and evidentiary traceability at the same standard as the source.

Cross-border handling also changes who can lawfully receive the data, which subprocessors may touch it, and what contractual terms have to exist before transfer. For health data, those legal and security conditions are tightly linked, so the transfer decision should be treated as part of the control design, not as a post-deployment compliance check.

Which controls should be in place before transfer?

The practical control set starts with data classification, transfer approval, and destination review. Teams should know whether the dataset contains ordinary health records, special category data, or mixed records with different handling rules, because that determines whether transfer is allowed and what safeguards are expected.

Then come the safeguards themselves: encryption in transit, strong access control at the destination, logging, retention limits, and contractual restrictions on onward transfer. When the transfer depends on vendors or affiliates, the recipient chain matters as much as the first hop, because each additional processor expands the trust boundary and the chance of uncontrolled reuse.

Where cross-border movement is recurring, the cleanest pattern is policy-driven routing rather than project-by-project judgment. That means predefined destination profiles, approved transfer templates, and a record of the legal basis and control set used for each route, so security and privacy teams are not rebuilding the decision every time data moves.

How do teams keep transfer risk from becoming operational drift?

The main failure mode is not usually a single bad transfer, but gradual normalisation of exceptions. If teams can move health data to a new region, cloud tenant, or partner system without rechecking the approval basis, the organisation can drift into transfers that are technically possible but no longer defensible.

A second failure mode is weak visibility into recipient handling. A transfer that is compliant at point of send can still become unsafe if the destination broadens access, shortens retention discipline, or replicates data into secondary systems without the same controls. For that reason, transfer governance should include periodic review of both the route and the recipient environment.

Evidence matters because transfer decisions are often examined after an incident or regulatory inquiry. Security teams should be able to show the classification decision, the transfer approval, the contractual or policy basis, and the technical controls applied. If those artifacts are missing, the organisation may have no practical way to prove that the move was controlled even if the original intent was sound.

Risk and Threat Considerations

Cross-border health data transfer increases exposure because the data may enter another legal regime, another vendor chain, and another operational environment with different default controls. The risk is not only accidental non-compliance, but also broader disclosure if the destination is less restrictive than the source or if onward transfer is not tightly governed.

Failure mechanism: Weak transfer governance, excessive recipient access, or undocumented onward processing can make a lawful-looking transfer functionally uncontrolled. Once that happens, the organisation loses confidence in who can see the data, where it is replicated, and which controls still apply.

Impact: The result can be regulatory breach, contractual breach, loss of patient trust, and harder incident containment because the data now exists under multiple jurisdictions and processor relationships.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

GDPR and ISO/IEC 27001:2022 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
GDPRArt. 9 — Processing of special categories of personal dataHealth data often requires special-category handling before cross-border transfer.
Art. 25 — Data protection by design and by defaultCross-border transfer should be designed with destination limits and minimisation built in.
Art. 32 — Security of processingCross-border transfers depend on encryption, access control, and other security safeguards.
Recommendation — Confirm a valid Art. 9 condition before transferring health data across borders. Build transfer controls and recipient limits into the data flow by default. Apply appropriate technical and organisational security measures for the transfer route.
ISO/IEC 27001:2022A.5.31 — Legal, statutory, regulatory and contractual requirementsTransfer decisions must reflect jurisdictional and contractual obligations.
A.5.34 — Privacy and protection of PIIHealth data transfer needs privacy-aware controls and documentation.
Recommendation — Map transfer approvals to the legal and contractual duties that govern the destination. Treat cross-border health data transfer as a privacy-controlled process with retained evidence.

Practitioner Guidance

What to prioritise: Put the transfer approval path ahead of the delivery timeline. If the destination, recipient list, or legal basis is not already approved, do not let engineering treat the move as a routine infrastructure task.

What to verify: Confirm that the transfer record includes the data category, destination country or region, legal basis, recipient scope, and the specific safeguards expected at the destination. If any one of those is missing, the control set is incomplete.

Decision rule: If the destination cannot demonstrate equivalent access restriction, logging, and retention discipline, treat the transfer as higher risk and require additional review before release. The safest default is not to assume the recipient environment is acceptable just because it is inside the same vendor ecosystem.

Practitioner takeaway: Cross-border health data is managed best when transfer approval, privacy rationale, and technical control design are one workflow, not three separate conversations.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org