Medical billing company data: denial notes, PHI and what an RCM company can license

Medical billing companies usually cannot license denial and appeal notes as they stand because they contain PHI handled as a business associate. Records de-identified to the HIPAA standard, with contractual rights confirmed, or non-PHI operating records such as playbooks and internal tickets are the realistic starting points for a SourceX introduction.

The short answer: can a medical billing company license denial and appeal notes?

Usually not as they stand. Denial notes, appeal letters and claim histories contain protected health information (PHI), and a revenue cycle management (RCM) company typically handles that PHI on behalf of healthcare providers as a business associate. Whether it can license any version of the records depends on three things: what its business associate agreements (BAAs) allow, whether the data has been de-identified to the HIPAA standard, and what the provider customers have agreed. This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.

For an operating partner, the useful point is that an RCM company may still hold licensable material that is not PHI: its own workflows, payer-rule playbooks, staff training content, internal tickets and process documentation. The conversation should start there.

What does the HIPAA de-identification rule say?

HHS Office for Civil Rights describes two methods of de-identification under the HIPAA Privacy Rule: Expert Determination, where a qualified expert concludes the risk of identifying an individual is very small, and Safe Harbor, where specified identifiers are removed and the entity has no actual knowledge the remainder could identify a person. Data de-identified by either method is no longer PHI under the rule.

Two cautions follow. First, free-text appeal notes are the hardest content to de-identify because names, dates, facility details and rare diagnoses appear in sentences, not fields. Second, de-identification solves the privacy question only. It does not by itself give a business associate the right to use or license a provider's data; that comes from the contract. The same distinction is covered in de-identification versus permission to license and in the PII redaction matrix.

What do RCM companies typically hold?

RecordPHI contentWho likely controls itStarting view
Claim and remittance historiesHeavyProvider customerOut of scope without authorization or de-identification
Denial notes and appeal lettersHeavy, in free textProvider customer, subject to BAAOut of scope unless rights and expert-grade de-identification exist
Payer contact logsModerateMixedDepends on content
Coding and audit working papersHeavyProvider customerOut of scope by default
Payer-rule playbooks, fee schedule analysisLightRCM company, if built from its own workCandidate for review
Staff training and SOP documentsNoneRCM companyCandidate for review
Internal helpdesk and engineering ticketsLight to moderateRCM companyCandidate after PHI screen
Management and finance recordsNoneRCM companyCandidate

How do these situations resolve in practice?

SituationWhat to checkLikely outcome to confirm with counsel
RCM company wants to license its full denial archiveBAAs, provider consent, expert determinationRarely workable unless providers authorize and de-identification is validated
RCM company holds only its own SOPs and playbooksWhether PHI crept into examplesOften screenable as non-PHI operating records
Provider (not vendor) owns the data and is the sellerProvider's own authorization and de-identificationA different conversation, led by the provider
Acquired RCM company with legacy archiveWho controls archive after the deal, BAA termination termsMay be restricted; counsel decides
Data already licensed or promised elsewhereExisting agreementsUsually blocks a new exclusive license

What is the operating partner's three-question screen?

  1. Whose data is it? Ask the CEO whether the company owns any of the records it holds, or only processes them for providers.
  2. What is not PHI? Ask for a list of systems that do not contain patient information, by name only.
  3. What do the BAAs say? Ask whether counsel has ever reviewed use of de-identified or aggregated data under those agreements.

If the answers to the first and third are unclear, pause. If the second yields a meaningful list, the data inventory builder is the next step. Adjacent insurance and claims records raise the same issues, as in workers' comp claims notes, and collections-style businesses raise ownership issues, as in collection agency acquisitions.

What should you say to the CEO?

What questions should you ask counsel?

  • Which of our customer contracts and BAAs mention aggregated, de-identified or derived data, and what do they allow?
  • Would an expert determination be needed for any free-text content, and who would commission it?
  • Do any provider customers need to authorize a license, and can we reach them?
  • Are there state laws on health information or payer confidentiality that tighten the picture?
  • Who is responsible if a de-identified file is later re-identified?

Bring the answers to the sponsor, not to SourceX as a partner. Your role ends at the introduction and the basic fit information, and no record is shared before a signed agreement.

How does the introduction work?

  1. You introduce the company using the referral form or your referral link, with basic fit information only.
  2. SourceX qualifies it on size, history, data breadth and rights, and flags PHI exposure.
  3. The company completes a data inventory.
  4. De-identification and exclusions are agreed before any work begins.
  5. Price and terms are agreed, buyers review and the company decides whether to sign.
  6. Data is delivered after an executed agreement and authorization.
  7. Your reward is paid after SourceX receives payment.

The how to monetize company data page gives the wider context.

How do rewards work for a sponsor?

Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company. The reward is paid only after the buyer pays and SourceX receives its fee; an introduction, meeting or signed agreement alone does not trigger payment, and no reward is guaranteed. Check your fund's and employer's policies on fees connected to portfolio companies before registering.

When is a billing company not worth an introduction?

  • Data is mainly PHI without HIPAA authorization or de-identification.
  • The company only processes provider data and owns none of it.
  • Another party controls the archive after a sale or wind-down.
  • The business has under 50 full-time employees at peak.
  • Nobody can export the data.

Next step

If a portfolio RCM company has non-PHI operating records and clear rights, register as a partner and use the referral link. Who qualifies lists the baseline, and the operating partner overview covers screening across a portfolio.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Does de-identified billing data mean the RCM company can license it?

Not automatically. De-identification under HIPAA removes the data from the definition of PHI, but the company still needs contractual rights from its provider customers. A business associate agreement and service contracts may restrict use. Counsel needs to confirm both the privacy and the contract sides before any license is discussed.

Which RCM records are least likely to contain PHI?

Playbooks on payer rules, training materials, process documentation, management reporting and many internal tickets, provided examples were scrubbed of patient details. A short PHI screen is still needed because screenshots, attachments and ticket text can include patient information that nobody expected.

Is a provider group in a different position than an RCM vendor?

Yes. A provider owns its patient records and has its own HIPAA duties, so the conversation centers on its authorization and de-identification. That is a heavier process, and the sponsor should expect counsel to lead. Provider records that are mainly PHI remain a red flag without authorization.

What is expert determination in plain terms?

A qualified statistical expert analyzes a dataset and documents that the risk of identifying anyone is very small. It suits unstructured text better than simply removing listed identifiers, but it takes time and is tied to the specific dataset. HHS describes it alongside the Safe Harbor method.

Should an operating partner ask to see denial notes?

No. Partners never export, upload or describe confidential records, and denial notes contain PHI. Ask only for system names and date ranges. Anything further is handled between the company, its counsel and SourceX under signed agreements.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment