In an acquisition or bankruptcy, a company's data is treated as transferable business assets, the same way inventory or intellectual property would be. The difference for healthcare organizations is that data governed by HIPAA doesn't lose its regulatory status just because a business is acquired by another company or is bankrupt. If a vendor holding PHI is a business associate under a business associate agreement (BAA), that PHI remains subject to HIPAA's Privacy, Security, and Breach Notification Rules regardless of who owns the company.
Acquisitions
When a vendor is acquired by another company, the process is more controlled. These would be the steps to take:
- Confirm BAA continuity in writing. Request written confirmation from the acquiring entity that it accepts assignment of the agreement, or execute a new BAA if the acquirer is creating a new corporate entity.
- Re-run vendor risk assessment. An acquisition often means new infrastructure, new subprocessors, new data residency, and sometimes a full platform migration.
- Ask where the data is physically going. Acquisitions can involve migrating data to the acquirer's own cloud environment or consolidating multiple systems. Get specifics on encryption standards, access controls, and audit logging in the new system before migration happens.
- Update risk register and downstream notifications. If the vendor relationship is material, your own compliance obligations (state law, contracts with health plans, accreditation bodies) may require you to document and, in some cases, disclose the change.
Bankruptcy
Under Section 363 of the U.S. Bankruptcy Code, a company in Chapter 11 can sell its assets, including customer and patient data, subject to court approval. The 23andMe bankruptcy in 2025 is the most recent example of this, the company held genetic and health data on more than 15 million consumers, and its Chapter 11 filing put that data on auction. The bankruptcy court took the step of appointing an independent Consumer Privacy Ombudsman to review any proposed sale, and qualified bidders were required to agree to honor the company's existing privacy commitments. The assets were sold to TTAM Research Institute in mid-2025, with the buyer publicly committing to preserve existing customer data choices.
The outcome of this case is not guaranteed in every bankruptcy. It happened because of regulatory and public pressure following a prior breach. For a healthcare organization relying on a vendor that is going through bankruptcy, the operational risks include:
- Data access can become unstable. A bankrupt vendor may cut staff, lose infrastructure funding, or lose control of its own systems before any sale closes.
- Your BAA may not bind the buyer. Contracts can be rejected or renegotiated in bankruptcy under Section 365 of the Bankruptcy Code.
- You may need to act on a compressed timeline. Bankruptcy sale processes often move on court-imposed deadlines. IT and compliance teams should treat a vendor bankruptcy filing as a trigger for an active exit-planning process.
Bankruptcy's own paperwork can leak PHI
When a healthcare provider, not just a data vendor, but a hospital, clinic, or practice files for Chapter 11, the process of federal bankruptcy procedure can force disclosure of PHI regardless of HIPAA.
This is the subject of Sophie R. Rogers Churchill's The "P" Isn't for Privacy: The Conflict Between Bankruptcy Rules and HIPAA Compliance, published in the Washington and Lee Law Review. The paper argues that bankruptcy's disclosure requirements and HIPAA's privacy rule are structurally at odds, and that patients in these cases have little control over what information ends up disclosed.
Chapter 11 debtors must file a "creditor matrix" which is a list of everyone the business owes money to, at the same time as the initial petition, before those creditors are even notified that a case exists. If a healthcare provider owes patients refunds, those patients form part of the matrix as creditors, and their names, addresses, and financial details become part of the public bankruptcy record. What makes this worse is that most bankruptcy filings are searchable and downloadable through the federal PACER system, and that information becomes accessible to anyone, not just parties to the case. The paper walks through several stages of a normal case which include creditor-committee filings, statements of financial affairs, disclosure statements, even attorneys' fee applications.
Rogers Churchill also documents why the existing legal toolkit does not protect PHI. He notes that Federal Rule of Bankruptcy Procedure 9037 allows redaction of things like Social Security numbers and financial account numbers, but doesn't mention health information. Courts can order additional redactions "for cause," but that requires someone to raise the issue and by the time a debtor can ask the court for protection, the initial petition has already been filed.
The papers proposed fixes include amending Rule 9018 (which currently protects trade secrets and defamatory material but not PHI) to cover health information, clarifying Rule 1021's health-care-business designation to require an upfront privacy risk assessment, and creating a dedicated privacy ombudsman whose job would be to pre-screen filings for PHI before they reach the public docket.
Read also: When a healthcare organization is financially liable to a breach victim
When the vendor isn't acquired or bankrupt but closes
AHIMA's practice guidance on business closures, most recently updated in 2011, clarifies that compliance obligations don't cease just because there's no acquirer or bankruptcy court involved, the organization remains liable for how patient records are handled during and after the wind-down, and planning for records disposition should begin when a closure decision is made.
The guidance provides a distinction based on whether a sale is involved. If a facility is sold to another healthcare provider, patient records would transfer as part of the deal's assets, with the original provider retaining a right to access records later for litigation purposes. If a facility closes without a sale, there's no natural recipient, so the organization has to either transfer records to another provider willing to accept responsibility or archive them with a commercial storage firm vetted for confidentiality safeguards and climate-controlled retention. AHIMA is clear about where responsibility sits in that scenario, whatever path is chosen, "The original provider is responsible for ensuring the final disposition of health records."
AHIMA provides a vendor governance checklist:
- Patient notice. AHIMA's guidance treats publishing closure notices through local newspapers, a facility website, or social media as an acceptable way to give patients a chance to request their records before a shutdown.
- Retention periods. Records need to be kept for whatever the applicable state statute of limitations requires, and separately, Medicare-participating providers have their own five-year retention requirement tied to claims settlement.
- Storage vendors need contract language. The brief lists specific provisions to negotiate with a commercial storage firm such as confidentiality guarantees, restrictions on any secondary use of the data, and a defined process for returning or destroying records once the retention period ends.
- Paper and electronic records need a joint plan. Because many healthcare organizations still hold historical papers alongside EHR data, AHIMA recommends HIM and IT teams coordinate closure planning together, including making sure any receiving organization's systems can actually preserve the records in a usable format.
Read also: What are healthcare organizations liable for after a data breach?
FAQs
Does HIPAA require a company to notify patients before selling their health data in an acquisition?
HIPAA itself doesn't have a standalone mandate, but it does require that any new owner handling PHI operate under the same privacy and security obligations as the original entity.
Can patients opt out of having their health records transferred to a new owner?
Generally no, since transferring records to a successor entity is treated as a permitted disclosure for treatment and operations, though patients can request copies or restrictions under their existing HIPAA rights.
Is de-identified health data subject to the same acquisition and bankruptcy rules as PHI?
No, once data is properly de-identified under HIPAA's Safe Harbor or Expert Determination methods, it falls outside HIPAA's scope and can be transferred more freely.
Who enforces HIPAA violations that occur during a bankruptcy or acquisition?
The Department of Health and Human Services' Office for Civil Rights retains enforcement authority over HIPAA compliance regardless of a company's ownership or financial status.
