The Philippine IT and business process management sector booked more than $40 billion in export revenue in 2025, and IBPAP named healthcare as one of the verticals driving that result. Healthcare BPO services are no longer a side business for the country. Health information management services generated around US$4.2 billion in 2024, roughly 12 percent of total IT-BPM revenue. Size, however, is the easy part of the buyer's homework. The harder question is what a provider's compliance page actually proves. This guide covers both: the current data on the vertical, and a working method for separating claims you can check against a registry from claims you have to take on trust.
BPOAI Feature / Philippine BPO Industry
Healthcare BPO Services in the Philippines: Compliance Guide
The Philippine IT and business process management sector booked more than $40 billion in export revenue in 2025 , and IBPAP named healthcare as one of the verticals driving that result.
Share on LinkedIn
- $40 billionexport revenue in 2025
- US$4.2 billionin 2024
- 12 percenttotal IT-BPM revenue
- USD 466.64 billionin 2025
Figures were compiled on 2026-08-06 from fetched pages: Philstar and ASEAN Briefing reporting of IBPAP sector data, Precedence Research market estimates, Inquirer investment reporting, and provider compliance pages from Shearwater Health and Access Healthcare.
01 / 05
A $4.2 Billion Vertical Inside a $40 Billion Industry
from 1.82 million in 2024
Start with the headline numbers. The sector employed 1.9 million digital workers in 2025, up 4 percent from 1.82 million in 2024, and IBPAP's baseline target for 2026 is $42 billion in revenue and 1.97 million jobs. Within that, the healthcare information management segment is projected to reach US$6.7 billion by 2028, per ASEAN Briefing's July 2025 sector analysis.
Government intent has been explicit for years. In April 2023, DTI Undersecretary Rafaelita Aldaba stated the goal plainly: to make the Philippines the health information management destination hub for Asia Pacific. The vertical covers medical coding, claims processing, revenue cycle management, clinical documentation, and nurse-staffed clinical support, most of it delivered for US clients.
02 / 05
Where the Demand Comes From
The global market is large and concentrated. Precedence Research puts worldwide healthcare business process outsourcing at USD 466.64 billion in 2025, heading toward USD 1,112.27 billion by 2035 at a 9.07 percent CAGR. The same report gives North America a 49 percent revenue share in 2025. That concentration matters for Philippine providers: when the client base is American payers and providers, HIPAA obligations follow the data offshore.
Service mix tells you where the work sits. Precedence reports that revenue cycle management captured the highest revenue share among provider services in 2025, while claims management held the largest position in payer services. Both are exactly the functions Philippine healthcare BPO companies have built delivery depth in.
Investment behaviour backs this up. Optum, the UnitedHealth Group subsidiary, announced a P800 million medical BPO investment in Davao expected to create around 1,500 jobs, on top of P5.1 billion invested since 2011 across four Philippine sites. That announcement dates to May 2023, and it remains one of the clearest signals that US healthcare majors treat the Philippines as core delivery infrastructure rather than overflow capacity.
03 / 05
Four Compliance Labels, Two Different Kinds of Proof
Almost every provider in this vertical displays some combination of HIPAA, SOC 2, ISO 27001, and HITRUST on its website. These labels are not the same kind of evidence, and no other distinction matters more when you shortlist vendors.
- ISO 27001 and HITRUST are certifications. An accredited body audits the organisation and issues a certificate with a defined scope and expiry date. Certificates of this kind can be checked against public registries, such as IAF CertSearch for accredited ISO 27001 certificates, so a claim can graduate from marketing copy to verified fact.
- SOC 2 is an auditor's report, not a certificate. There is no public registry to consult. The report is typically shared only under NDA, which means a website badge is unverifiable until you are far enough into procurement to request the document itself.
- HIPAA has no certifying body at all. A compliance guide from Accountable, a US HIPAA software firm, states it directly: there is no official government-issued HIPAA certification, and Philippine BPO firms processing protected health information act as business associates who demonstrate alignment through contracts and third-party attestations such as HITRUST or ISO 27001.
The practical consequence: any vendor phrase like "HIPAA certified" is, at best, shorthand for "we believe our controls map to HIPAA." It is a self-description, not an award.
04 / 05
What Self-Attestation Looks Like in Practice
Two examples show the pattern, and both should be read as self-attested as of 6 August 2026, since the sources are the companies' own pages rather than an independent registry check.
Shearwater Health, a clinical process outsourcer with Philippine delivery centres, announced on 11 May 2026 that its Philippine operations earned HITRUST r2 certification with a two-year designation, alongside an i1 certification for its India operations. That is a strong claim, with a named framework, version, and scope. It is still self-attested as of 6 August 2026 until matched against HITRUST's own directory.
Access Healthcare, which runs delivery centres in the Philippines, India, and the US, publishes a certifications page listing HITRUST CSF, ISO/IEC 27001:2022, ISO 9001:2015, SSAE18 SOC 1 and SOC 2 Type II, and PCI DSS certification specifically covering its payment card processing centres in the Philippines, with the SOC 2 Type II entry dated 27 February 2026. Again: named frameworks, versions, and dates, which is what credible self-attestation looks like. And again: self-attested as of 6 August 2026.
The point is not to doubt these two firms. It is that a buyer cannot tell, from a website alone, which claims would survive a registry check. Providers that publish scope, certificate dates, and framework versions make your verification job possible. Providers that publish a bare row of logos do not.
05 / 05
A Verification Routine Before You Sign
A repeatable sequence keeps the diligence honest:
- Sort every claim into its evidence class. Registry-checkable (ISO 27001, HITRUST), report-based (SOC 2, SOC 1), or self-described (HIPAA alignment, "bank-grade security").
- Check the checkable. Look up ISO 27001 certificates in IAF CertSearch and HITRUST status in the HITRUST directory. Confirm the certified legal entity matches the entity you would contract with, including the Philippine site, not just a US or India parent.
- Request the reports early. Ask for the SOC 2 Type II report under NDA in the first round of diligence, and read the scope section and exceptions, not just the opinion letter.
- Treat HIPAA language as a starting question. Ask which attestation stands behind it, request the business associate agreement template, and confirm breach notification terms in writing.
- Date everything. Certificates expire and reports age. Record when each claim was verified, and re-verify at renewal.
Sector data says the Philippine healthcare vertical will keep compounding: a $4.2 billion segment inside an industry that beat $40 billion in 2025, selling into a global market growing at 9 percent a year. The providers are real and many of the credentials are too. The buyer's job is simply to know which kind of proof each logo represents, and to check the ones that can be checked. Company-level registration and compliance signals for Philippine providers are tracked in the BPOAI BPO directory, with verified and self-attested items labelled separately.
14Sources and methodologyEvery figure on this page carries a source URL, retrieval date, and confidence score
Figures were compiled on 2026-08-06 from fetched pages: Philstar and ASEAN Briefing reporting of IBPAP sector data, Precedence Research market estimates, Inquirer investment reporting, and provider compliance pages from Shearwater Health and Access Healthcare. Each cited figure links to the exact page it was retrieved from. Confidence scores follow BPOAI's standing rule: official or registry sources score 0.90-0.98, third-party aggregated reporting 0.75-0.89, company self-attested claims 0.50-0.74; provider compliance claims sourced from company pages are labelled self-attested as of 2026-08-06 because they were not confirmed against an independent registry.
- 01Philippine IT-BPM export revenues reached above $40 billion in 2025, surpassing the baseline targetPhilstar.com (reporting IBPAP) · retrieved 2026-08-06 · confidence 0.85 · Stated by IBPAP president and CEO Jack Madrid; article dated 29 January 2026
- 021.9 million digital workers in 2025, up 4 percent from 1.82 million in 2024Philstar.com (reporting IBPAP) · retrieved 2026-08-06 · confidence 0.85
- 03IBPAP 2026 baseline targets: $42 billion revenue and 1.97 million jobs; healthcare named a growth driver alongside banking and GCCsPhilstar.com (reporting IBPAP) · retrieved 2026-08-06 · confidence 0.85
- 04Healthcare information management services (HIMS) revenue approximately US$4.2 billion in 2024, about 12 percent of total IT-BPM revenueASEAN Briefing (Dezan Shira & Associates) · retrieved 2026-08-06 · confidence 0.78 · Article dated 14 July 2025
- 05HIMS segment projected to reach US$6.7 billion by 2028ASEAN Briefing (Dezan Shira & Associates) · retrieved 2026-08-06 · confidence 0.70 · Forward projection; scored at inferred/modelled ceiling
- 06Global healthcare BPO market USD 466.64 billion in 2025, projected USD 1,112.27 billion by 2035 at a 9.07 percent CAGR (2026-2035)Precedence Research · retrieved 2026-08-06 · confidence 0.76
- 07North America held a 49 percent revenue share of the global healthcare BPO market in 2025Precedence Research · retrieved 2026-08-06 · confidence 0.76
- 08Revenue cycle management captured the highest revenue share among provider services in 2025; claims management held the largest position in payer servicesPrecedence Research · retrieved 2026-08-06 · confidence 0.76
- 09Optum announced a P800 million medical BPO investment in Davao expected to create around 1,500 jobsPhilippine Daily Inquirer · retrieved 2026-08-06 · confidence 0.80 · Announced May 2023; presented with that date in the article
- 10UHG/Optum invested P5.1 billion since 2011 across four Philippine sites (Taguig, Muntinlupa, Quezon City, Cebu City)Philippine Daily Inquirer · retrieved 2026-08-06 · confidence 0.80
- 11DTI vision statement (April 2023, Undersecretary Rafaelita Aldaba): make the Philippines the health information management destination hub for Asia PacificAsian Journal · retrieved 2026-08-06 · confidence 0.80 · Article dated 21 April 2023
- 12There is no official government-issued HIPAA certification; Philippine BPO firms processing PHI act as business associates and demonstrate alignment via third-party attestations (HITRUST, ISO 27001)Accountable (AccountableHQ) · retrieved 2026-08-06 · confidence 0.78 · US HIPAA compliance software vendor's published guide; consistent with HHS position that no official HIPAA certification exists
- 13Shearwater Health announced 11 May 2026 that its Philippine operations earned HITRUST r2 certification (two-year designation); India operations earned HITRUST i1Shearwater Health (company press release) · retrieved 2026-08-06 · confidence 0.68 · Self-attested as of 2026-08-06; not confirmed against the HITRUST directory
- 14Access Healthcare's certifications page lists HITRUST CSF, ISO/IEC 27001:2022, ISO 9001:2015, SSAE18 SOC 1 and SOC 2 Type II (SOC 2 entry dated 27 February 2026), and PCI DSS certification covering payment card processing centres in the PhilippinesAccess Healthcare (company certifications page) · retrieved 2026-08-06 · confidence 0.62 · Self-attested as of 2026-08-06; not confirmed against IAF CertSearch or the HITRUST directory
Confidence scale: 0.90–0.98 registry or official data, 0.75–0.89 third-party aggregated, 0.50–0.74 self-attested. Figures that could not be sourced were removed rather than published.





