HIPAA and AI training data: what the rules allow and what stays out of a license
HIPAA generally bars licensing protected health information to an AI developer without patient authorization, another permitted pathway or documented de-identification under 45 CFR 164.514. Ordinary business records of a healthcare administrator, without embedded PHI, are assessed like any other company records. Counsel decides each case.
Can protected health information be used to train AI?
Protected health information generally cannot be licensed to an AI developer unless the HIPAA Privacy Rule allows it: with the individual's authorization, through another permitted pathway, or after the information is de-identified. The rule is in 45 CFR Part 164, and the Department of Health and Human Services (HHS) Office for Civil Rights enforces it.
For SourceX the consequence is simple. Records that are mainly PHI, such as medical records or claims, are a red flag unless HIPAA authorization or de-identification is in place. The much larger pool of ordinary business records from healthcare administrators, such as scheduling operations, vendor management, finance and HR policies, can be a different story.
This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.
Who does HIPAA apply to?
HIPAA applies to covered entities (health plans, clearinghouses and most healthcare providers that bill electronically) and to their business associates. A company that is not a covered entity or business associate, such as a SaaS vendor serving manufacturers, is not governed by the Privacy Rule even if its employees have health benefits.
| Situation | HIPAA status to confirm | Typical consequence for licensing |
|---|---|---|
| Hospital or clinic patient records | Covered entity PHI | Needs authorization or de-identification |
| Billing company processing claims for providers | Business associate | Restricted by the business associate agreement |
| Practice-management vendor with patient data | Business associate | Same, plus the provider's permission |
| Healthcare staffing firm with no patient data | Likely outside HIPAA for its own records | Ordinary business-record review |
| Employer with benefit-plan files | Plan may be covered, employer records differ | See the employee health information question |
What does the sale-of-PHI rule add?
The Privacy Rule at 45 CFR 164.502 treats a disclosure of PHI in exchange for remuneration as a "sale" that generally requires the individual's authorization stating that the entity will be paid. A license fee for a dataset containing PHI is the kind of arrangement counsel will test against that rule. Read the current regulation text in the eCFR and confirm the exceptions with counsel rather than relying on this summary; HHS guidance on the specifics can change.
How does de-identification work under HIPAA?
HHS OCR's guidance on de-identification describes two methods under 45 CFR 164.514:
- Expert Determination. A qualified expert applies statistical methods, concludes that the risk of re-identification is very small, and documents the analysis.
- Safe Harbor. The covered entity removes the 18 specified identifiers and has no actual knowledge that what remains could identify an individual.
Health information de-identified by either method is no longer PHI under the Privacy Rule. Free-text notes, call recordings, images and dates are the hard cases, because identifiers hide in unstructured content. A data set that looks clean in a spreadsheet can fail when notes or transcripts are included.
Where does licensing leave a healthcare company's non-PHI records?
A hospital group or physician practice also generates records that are not patient records: facilities requests, procurement, vendor contracts, internal IT tickets, marketing and finance workflow. Those can be reviewed like any business records, provided no PHI is embedded, such as a patient name inside a ticket or an email thread. Mixed content is the usual trap.
A screening rule: the PHI three-way test
Before a healthcare-adjacent company goes further, ask three questions:
- Source. Does the data come from treating, billing or paying for care?
- Identifiability. Could a person be identified directly or through combination, including names in free text?
- Authority. Is there patient authorization, a business-associate permission or a documented de-identification?
If the answers are yes, yes and no, the records are out of scope. If the first answer is no, ordinary rights review applies. The broader exclusion list is in what data should be excluded from AI training.
Questions to put to the compliance officer
- Is the company a covered entity, a business associate, or neither?
- Which systems hold patient information, and are they excluded from scope?
- Do business associate agreements restrict secondary use?
- Has a PHI search been run across free-text fields such as tickets and email?
- Who signs off on a de-identification method, and is it documented?
What does this mean for a referral partner?
You do not review records or judge HIPAA status. You screen early for a mismatch: if a prospect describes its valuable data as "patient files" or "claims history", it is likely not a fit without authorization or de-identification. If it describes operations, vendor, finance and IT records, a conversation makes sense.
State rules add further layers; see state AI laws in 2026 and the CCPA deletion explainer. Background on the buyer side is in what AI training data is.
Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company. The reward is paid only after the buyer pays and SourceX receives its fee; an introduction, meeting or signed agreement alone does not trigger payment, and no reward is guaranteed.
What to say when a healthcare-adjacent owner raises HIPAA
That framing keeps the conversation on non-PHI business records and shows respect for the owner's obligations.
Illustrative example
Illustrative: a fictional 200-person physician-practice management company holds ten years of vendor contracts, staffing schedules, helpdesk tickets and finance workflows alongside patient-facing systems. The compliance officer proposes scoping out every system that touches patients, running a PHI search across the helpdesk tickets for names and medical record numbers, and licensing only what passes. Tickets that fail the search are dropped rather than edited. The remaining set is smaller but defensible, and the company's counsel signs off before the agreement is executed.
Mistakes to avoid
| Mistake | Why it hurts | Fix |
|---|---|---|
| Assuming removing names equals de-identification | Safe Harbor lists 18 identifier types, and free text hides them | Use a documented method |
| Treating all healthcare companies as out of scope | Their non-PHI business records may fit | Screen record types, not industries |
| Ignoring business associate agreements | They can bar secondary use | Ask who the agreements bind |
| Promising a result | Counsel decides | Refer, do not opine |
Next step
If you know a US healthcare administrator, vendor or services firm with 50+ full-time employees at peak (contractors excluded) and non-PHI operational records, run the company fit checker, read how SourceX referrals work, then register as a partner.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Is de-identified health data still regulated by HIPAA?
Health information de-identified under the Privacy Rule's standard, by Expert Determination or Safe Harbor, is no longer PHI, so HIPAA's use and disclosure limits stop applying to it. Other laws and contracts may still apply, and re-identification risk must be managed. Counsel should confirm the method and documentation.
Can a hospital license its non-patient business records?
Possibly. Procurement, facilities, finance and IT records are not patient records, but they can contain PHI embedded in emails or tickets. The records need screening and redaction, and the organization's compliance officer and counsel should approve the scope before any license is agreed.
Does a business associate agreement limit AI training use?
It can. A business associate may use PHI only as the agreement and the Privacy Rule permit, and an agreement often does not allow secondary uses such as model training. A company in that position should have counsel read the agreement before considering any dataset containing client PHI.
What identifiers does HIPAA Safe Harbor require removing?
Safe Harbor lists 18 categories of identifiers, including names, small geographic units, dates tied to an individual, contact details, account and record numbers, and full-face images, plus a no-actual-knowledge condition. Read the regulation and HHS guidance directly because the details matter.
Do call recordings from a clinic count as PHI?
Recordings of patient conversations typically contain identifiers and health details, so they are generally PHI when created by a covered entity. They are high risk for licensing and normally excluded unless authorization or a documented de-identification process covers them.
Related pages
- State AI laws in 2026 that touch AI training data: what to check before licensing
- How SourceX US company data referrals work
- What is AI training data?
- CCPA deletion requests and licensed AI training data: what happens to records?
- Is employee health information in HR files protected health information?
- What data should be excluded from AI training? A default exclusion list
Free resources
- Due diligence checklist generator — A tailored document request list by deal type.
- Cash flow calculator — A 12-month cash forecast with shortfalls highlighted.
- Referral earnings calculator — Hypothetical partner earnings with the per-company cap.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment