Dental, veterinary and physician practice platforms: which non-PHI records could be licensed?

Dental service organizations, veterinary roll-ups and physician practice platforms rarely fit data licensing, because most of their records are patient data. Only administrative, non-PHI operating records, such as procurement, SOPs, vendor and staffing workflows, are candidates, and only with clear rights. Patient records are a red flag without HIPAA authorization or de-identification.

Which records at a practice platform are candidates at all?

At a DSO, veterinary group or physician practice platform, the clinical and billing records are the wrong place to look. Patient charts, imaging, claims and appointment histories are protected health information, or in veterinary groups, client personal data, and SourceX treats mainly-PHI datasets as a red flag unless there is HIPAA authorization or de-identification. The candidates sit on the administrative side of the business.

That is why many platforms in this segment will not qualify, and why a sponsor should screen early rather than raise expectations with a platform CEO.

What does a practice platform's back office hold?

SystemRecordsWhy AI buyers may value themPHI risk
Procurement and purchasingSupply orders, vendor quotes, price approvals, exceptionsMulti-step approval workflows with outcomesLow if no patient identifiers
Vendor and facilities managementService tickets, lease and maintenance correspondenceResolution paths from request to closeLow
HR and staffingScheduling rules, credentialing checklists, onboarding SOPsProcess documentation and decision recordsMedium: employee personal data needs review
Finance and shared servicesMonth-end close workpapers, accounts payable queries, intercompany reconciliationsStructured finance operations at multi-site scaleLow to medium
Practice acquisition and integrationDiligence checklists, onboarding plans, integration trackersReal project execution across many sitesMedium: contracts and counterparties
Central support deskIT and operations tickets from site managersTriage, escalation and outcomesMedium: tickets can contain patient details
Compliance and qualitySOPs, audit templates, corrective action logsProcedure and exception handlingMedium: logs may reference patients

The valuable asset is the platform's repeatable operating machinery, not the clinical record.

The PHI-first screen

Before anything else, ask four questions. A no on the first or last ends the conversation.

  • Separation: can the administrative records be exported without patient data, or can patient data be reliably removed first?
  • Authority: is a HIPAA authorization or a de-identification process in place for anything that touches patients? This is general information, not legal, tax or financial advice. Confirm with your own counsel or compliance officer.
  • Scale: does the platform meet the baseline of 50+ full-time employees at peak (contractors excluded) with several years of documented operations?
  • Exports: can someone run exports across systems, and have archives been retained?

If the answer to the first is no, the platform is not a candidate today. Ticket systems and shared drives are the usual trouble: they look administrative but hold patient names in free text.

Which practice platforms fit, and which do not?

Platform typeLikely fitReason
Multi-state DSO with a large central shared-services teamPossibleCorporate procurement, finance and integration records may be separable from clinical data
Veterinary group with central purchasing and HRPossibleBack-office workflows exist at scale, subject to client-data screening
MSO supporting physician practicesPossibleThe management company holds its own contracts, billing operations and SOPs, but not the practices' charts
Single-site or small regional groupUnlikelyFalls short of the size baseline
Platform whose value sits in imaging, charts or claimsNoMainly PHI
Group where practices own their own recordsNoRights sit with the practices, not the platform

Rights is the second filter. In an MSO structure the management company usually does not own the clinical records of the practices it serves, so it cannot license them, and its contracts may restrict even operational material.

What are the rights and confidentiality pitfalls?

  • Patient and client data in free text. Support tickets, emails and scheduling notes routinely mention patients. De-identification and redaction requirements are agreed with the company before any work begins, and some sets will not be separable.
  • Practice-owned records. If affiliated practices or professional entities own the data, the platform needs their consent.
  • Payer and vendor contracts. Confidentiality clauses can limit reuse of pricing, rates and negotiations.
  • Employee data. HR files contain personal information that needs review.
  • Previous licensing. If any dataset was already licensed for AI training, it is out.

How does HIPAA de-identification come into it?

HHS guidance describes two methods for meeting the HIPAA de-identification standard at 45 CFR 164.514: Expert Determination and Safe Harbor. Whether either is workable for a given administrative dataset is a question for the company's counsel and privacy officer. This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.

Who can raise this with a platform?

Operating partners, heads of portfolio operations and heads of value creation are best placed, since they already see procurement and integration playbooks across several sites. Independent sponsors and fractional CFOs working with practice groups also see the shared-services side. The AI value creation playbook for PE operating partners frames where this sits among other levers, and the referral opportunities for operating partners page explains the role.

What to say to a platform CEO

A platform CEO, CFO or authorized representative is the sponsor. For the CEO's side of integration decisions, see the platform company CEO playbook, and for the pre-close view, the add-on acquisition criteria guide.

How the introduction works

  1. You register as a partner and share your referral link, or submit the company by referral form with basic fit information only.
  2. SourceX qualifies size, history, data breadth and rights, and flags any PHI concerns.
  3. The company completes a data inventory of systems, years of history and exports.
  4. Price and terms are agreed before buyers review.
  5. If a deal closes, delivery follows the agreed redaction rules, and the company is paid.

Partners never export, upload or describe confidential records.

How rewards work

Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company. The reward is paid only after the buyer pays and SourceX receives its fee; no reward is guaranteed. Read the program terms and check your firm's policies first.

When to skip this segment

Skip the platform if its value sits in clinical data, if practices own the records, if archives were deleted, or if the company is under the size baseline. The company fit checker gives a preliminary screen without contact details.

Next step

If a platform clears the PHI-first screen, register as a partner and make the introduction, or have the CEO apply at sourcex.si/apply.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Can a dental or physician group license patient records?

Not as a starting point. Datasets that are mainly protected health information are a red flag unless there is HIPAA authorization or de-identification, and rights often sit with the practices. Whether a given dataset can be authorized or de-identified is a question for the company's counsel and compliance officer, not for the referring partner.

What kinds of records at a practice platform could qualify?

Administrative, non-PHI operating records: procurement workflows, vendor correspondence, staffing and credentialing SOPs, finance operations and acquisition integration trackers. They must be separable from patient data, owned or licensable by the platform, and spread across enough systems and years to meet the baseline.

Do veterinary groups face the same problem?

The medical-record issue differs, but client personal data and practice ownership questions still apply. Back-office records such as purchasing, HR and finance operations may be candidates if they can be separated from client details. Each group should be screened on its rights and exports before any introduction.

Does an MSO own the practices' records?

Usually not. The management company typically holds its own contracts, billing operations and SOPs, while charts and clinical data belong to the practices or professional entities. A platform cannot license what it does not own, so confirm ownership in the service agreements before raising the topic.

Is this a good segment to prioritize for referrals?

Only selectively. Many practice platforms will fail the PHI or rights screen, so spend time on a few with large shared-services teams and clean separation. Companies in B2B software, IT services and professional services often screen faster for the same effort.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment