Are workers' compensation records PHI? HIPAA limits for claims notes and licensing

Workers' compensation records are PHI only when a HIPAA covered entity or its business associate holds them in that role, so the answer depends on the holder and the line of business. Any PHI offered for licensing generally needs HIPAA de-identification or authorization, and state rules and contracts may still apply. Confirm with counsel.

Are workers' comp records PHI? The short answer

It depends on who holds the record and in what capacity. Protected health information (PHI) is a HIPAA concept: it describes individually identifiable health information held by a covered entity, such as a health plan or a health care provider that bills electronically, or by its business associate. A claims note is PHI only if the holder falls into one of those roles for that record. Whether a workers' compensation line falls inside or outside that definition depends on the entity's role and the facts, and counsel has to decide it. The same company's group health or provider lines may be treated differently.

That distinction is the first thing a portfolio operating partner should establish before treating a claims archive as a licensing candidate. It also does not end the analysis: state medical-privacy rules, contracts with employers and insurers, and the company's own privacy promises can all restrict reuse even when HIPAA does not apply.

This is general information, not legal, tax or financial advice. Confirm with your own counsel, tax adviser or professional body before acting.

What does the HIPAA de-identification standard require?

If a record is PHI, health information offered for licensing generally must be de-identified under HIPAA's standard or otherwise authorized. HHS describes two methods in its guidance on de-identification of protected health information:

  • Expert Determination: a qualified expert determines and documents that the risk of re-identification is very small.
  • Safe Harbor: 18 specified identifiers are removed and the holder has no actual knowledge that the remaining information could identify an individual.

Health information de-identified by either method is no longer PHI under the Privacy Rule, according to the same guidance. Free-text claims notes are the hard case: adjusters write names, dates, employers, body parts and locations into narrative fields, which makes mechanical removal of identifiers difficult. That is why redaction and de-identification requirements are agreed with the company before any work begins.

How does this apply in common portfolio situations?

Use the table to frame questions for counsel. The right-hand column is what to confirm, not a conclusion.

SituationWhat to checkTypical outcome to confirm
Portfolio company is a workers' comp third-party administrator (TPA) handling claims for insurers or self-insured employersThe role it plays under its service agreements and whether any line of business is HIPAA-regulatedWhich claim notes, if any, are PHI, and whether contracts allow reuse
Insurer writes workers' comp and group healthWhether the claims data sits in separate systems and entitiesHealth-plan data may need de-identification or authorization; workers' comp data needs a separate analysis
Employer self-administers claimsWhether it also runs a group health plan and how records are separatedWhether HIPAA applies depends on its role; state rules may apply either way
Managed care or bill-review vendorWhether it acts as a business associate for any clientRecords handled as a business associate follow that client's agreement
Medical billing company serving providersBusiness associate agreements and de-identification termsSee medical billing company data for denial notes and PHI
Claim files contain adjuster narrative only, with identifiers stripped by processWhether the stripping meets an accepted method and is documentedDocumentation matters; an informal "we remove names" is not a standard

If a record mainly consists of PHI and the company has no HIPAA authorization or de-identification route, it is a red flag for SourceX and the company should not proceed with that material.

What should a sponsor and counsel agree before any inventory?

Treat the following as a checklist for the portfolio company's general counsel or outside counsel. The partner does not take part in it.

  • A written determination of which lines of business, if any, are covered entities or business associates.
  • A map of where claims narrative lives: claims system, email, document store, call notes.
  • Contract review: do insurer, employer and client agreements limit reuse or require consent?
  • A state-law review, since medical-confidentiality and privacy requirements differ by state.
  • A decision on the de-identification method for any health information, with documentation.
  • A privacy-policy review: does anything the company told claimants conflict with licensing?
  • Confirmation that records are the company's to license and not held only as a service provider.

The PII redaction matrix shows how different record types are typically treated, which helps with the narrative-text problem. For the ownership side, compare the question of who owns aircraft maintenance records, another case where the holder and the owner differ.

What can a company still license if claims notes are off limits?

Often quite a lot. Claims is only one source of operating records. A TPA or insurer with 50+ full-time employees at peak (contractors excluded) often also holds records that carry no health information at all:

  • Internal policies, procedures and adjuster playbooks.
  • Business email and Slack or Teams conversations about operations, with personal data redacted.
  • Finance, vendor and contract records.
  • Engineering, product and IT tickets for the claims platform.
  • Customer service and employer-account management records.

Illustrative: a fictional claims administrator finds that its adjuster narrative is the most useful but also the riskiest set, so it keeps that out of scope and inventories its policy library, vendor records and platform engineering tickets instead. Whether any claims-related material is added later is a decision for the company and its counsel.

The data inventory builder helps list those systems by name and years of history without describing contents.

What is the operating partner's role?

You make an introduction and share basic fit details. You never handle claims files or describe confidential records. The steps below are written for a sponsor who wants the licensing question looked at without disturbing operations.

  1. Ask the portfolio CEO or general counsel which privacy determination has already been made.
  2. If none exists, suggest the company commission one from counsel before any licensing discussion.
  3. Register as a partner and introduce the sponsor, or have the company apply through your referral link.
  4. SourceX qualifies the company and asks for the inventory, scoped to what counsel has cleared.
  5. Terms, price and redaction rules are agreed before buyers see anything, and nothing is delivered without a signed agreement and the company's authorization.

For the wider portfolio view, read referral opportunities for private equity operating partners.

How do rewards work?

Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company. The reward is paid only after the buyer pays and SourceX receives its fee; an introduction, meeting or signed agreement alone does not trigger payment, and no reward is guaranteed. The reward is a share of SourceX's fee and is never deducted from what the portfolio company receives. Check your firm's policies on fees connected to portfolio companies before you register.

Questions to ask your counsel

  • Which entities in the group are covered entities or business associates, and for which records?
  • Does a state law add duties for workers' compensation or injury records?
  • Do our contracts with insurers and employers permit licensing de-identified material?
  • Which de-identification method suits free-text notes, and who documents it?
  • What would a license change about our privacy notices?

Next step

Do not start with the claims notes. Start with the determination, and let a lawful scope drive the inventory. If the company has records outside the health-information question, register as a partner and introduce the sponsor, or send them to sourcex.si/apply. For another exception-heavy record type that avoids health data, see OS&D and freight claims records.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Is every claims note at an insurer PHI?

No. PHI depends on the holder's role and the record. An insurer's group health business can be a health plan under HIPAA, while whether a workers' compensation line is covered depends on the facts and the entity's role. Because one company can have both, counsel should map each line of business and record set first.

Does removing names make a note de-identified?

Not by itself. HHS describes two methods: Expert Determination and Safe Harbor, which removes 18 specified identifiers and requires no actual knowledge of remaining identifiability. Free-text notes often hide identifiers in narrative, so the company and counsel decide how to meet a recognized method and document it.

Can a TPA license claims data at all?

Possibly, but only the records it has the right to license. A TPA often holds files on behalf of insurers or employers, whose contracts may limit reuse. If the data is mainly PHI without authorization or de-identification, that is a red flag and the company should not proceed with that material.

What if the company only has policy and engineering records?

Those can still qualify. A company with 50+ full-time employees at peak (contractors excluded), years of documented operations and rights to license can inventory non-health systems such as policies, vendor records, email and engineering tickets, with personal data redacted under agreed terms.

Does a partner need to review claims notes?

No, and a partner should not. A partner's job ends at the introduction and a few basic fit facts. Privacy determinations belong to the company and its counsel, and SourceX works with the company on scope and redaction before any buyer sees material.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment