Double Exposure: Navigating CFIUS and HIPAA Compliance in an Era of Foreign Investment in Health Data

August 7, 2026

Cyber-Security-Health-.webp

 

In healthcare M&A, de-identifying Protected Health Information (PHI) under HIPAA has long provided a reliable safe harbor for cross-border investors looking to acquire, license, or commercialize bulk health datasets. However, recent regulatory shifts by the Committee on Foreign Investment in the United States (CFIUS) and the Department of Justice’s Data Security Program (DSP) under Executive Order 14117 have fundamentally altered this baseline. Bulk U.S. health data is now categorized as sensitive personal data subject to strict national security oversight, regardless of whether the dataset has been anonymized, pseudonymized, or encrypted under HIPAA guidelines.

This dual-compliance framework creates immediate friction for private equity-backed and foreign-invested healthcare transactions. Beyond invalidating traditional de-identification safe harbors, the incongruence between HIPAA and CFIUS rules creates operational barriers for targets maintaining offshore data hosting systems, while introducing coverage gaps for non-"covered entities" that handle sensitive health data. To navigate these contradictory regulatory regimes, healthcare deal makers must conduct expanded, multi-disciplinary due diligence early in the transaction lifecycle to preserve deal value and avoid enforcement action.

Read the full article on IBA: Double exposure: navigating CFIUS and HIPAA compliance in an era of foreign investment in health data | International Bar Association