Can a third-party administrator license its data? A partner's guide to TPAs

A third-party administrator can rarely license claim or member files because they belong to clients and often contain health information. What may qualify is the TPA's own procedures, audit checklists and training material, if it has 50+ full-time employees at peak, rights to license and an authorized sponsor.

Can a third-party administrator license its data?

Usually only part of it. A third-party administrator (TPA) processes claims, benefits and workers' compensation files on behalf of carriers, employers and self-insured plans, so the transactional records mostly belong to those clients and often contain health information. What can remain is the TPA's own operating knowledge: procedures, audit checklists, training material and handling patterns.

This page is for partners who know TPAs through benefits consulting, brokerage, M&A or finance work. It draws the line between records that are likely off limits and material that may belong to the firm. A TPA that clears the line and meets the baseline of 50+ full-time employees at peak (contractors excluded) is worth a screen. Many will not clear it, and saying so early protects your credibility.

What records does a TPA hold, and who owns them?

Record typeTypical ownerLicensing outlook
Claim files, adjuster notes, payment historiesClient carrier, employer or planOff limits without client consent; often contains health data
Eligibility and enrollment filesPlan sponsorOff limits; contains personal data
Medical bills and explanations of benefitsClient and patientOff limits unless properly authorized or de-identified
Claims-handling procedures and decision treesThe TPAPossible, after review of client contract terms
Quality audit checklists and scorecardsThe TPAPossible if free of client identifiers
Training modules, onboarding for adjusters and analystsThe TPAOften the cleanest candidate
Escalation and complaint-handling playbooksThe TPAPossible once examples are generalized
Vendor management and network-contracting proceduresThe TPA, plus counterpartiesDepends on confidentiality terms

Why is protected health information the main obstacle?

Many TPA files contain protected health information (PHI). Health data generally has to be de-identified under the HIPAA standard or otherwise authorized before it can be shared. The U.S. Department of Health and Human Services describes two methods, expert determination and the safe harbor removal of specified identifiers, in its guidance on de-identification. Health information de-identified by either method is no longer PHI under the Privacy Rule.

This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.

Two practical points for a partner. First, de-identification is the company's and its counsel's job, not yours. Second, even de-identified claim data usually still belongs to the TPA's clients under the administrative services agreement, so client consent is a separate question from privacy law. A TPA whose value is mainly claim files is the pattern described in the guide on industries that are a poor fit.

Which TPAs are worth a conversation?

Use a four-point screen, the TPA split test: Whose data, What remains, Who signs, Where exported.

  • Whose data: does the administrative services agreement say who owns work product, procedures and derived analytics?
  • What remains: after removing client files, does the TPA still hold years of procedures, audits, training and playbooks in documents it controls?
  • Who signs: is there an owner, CEO, CFO or authorized representative who can consider a license?
  • Where exported: can someone pull the documents from knowledge bases, shared drives, learning platforms and QA tools?

Stronger candidates tend to be larger administrators of benefits and workers' compensation programs with a mature quality program and an internal training function. Weaker ones are small, focused entirely on claim adjudication, or tied to a single carrier with restrictive contract language.

When can a partner raise it?

MomentWhat to listen forPossible question
Client renewal seasonRebidding triggers documentation reviewsWhich of your procedures are yours, apart from client data?
Platform replacementOld claims system or knowledge base is retiringWhat gets archived, and who owns the archive?
Compliance auditAudit checklists get updatedDo you keep a history of audit versions?
Ownership transitionAdvisors catalog assetsIs the knowledge base part of the asset list?
Add-on integrationTwo TPAs merge proceduresWhat happens to the acquired firm's documentation?

Sector context for sponsors is in the guide on buy-and-build sectors.

How does the introduction work?

  1. Confirm informally that the TPA owns a body of procedures and training material, without asking to see any of it.
  2. Introduce the owner or CFO by referral link or the referral form.
  3. SourceX qualifies the firm and flags any client-ownership or PHI problem early.
  4. The TPA inventories its systems and what can be exported, using something like the data inventory builder.
  5. Price and terms are negotiated, and nothing is binding until the company signs.
  6. Buyers review the offering and, once the TPA is deal-ready, typically respond within about two weeks.
  7. After an executed agreement and the company's authorization, data is delivered and the TPA is paid. Your reward is paid after SourceX receives its fee.

You never handle or describe confidential records.

What to say to a TPA executive

Compare adjacent industries, such as market research firms with similar consent limits, before deciding where to spend time.

How rewards work

Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company. Rewards become payable only after the buyer pays and SourceX receives its fee, and no reward is guaranteed. Licensed insurance professionals, including brokers and consultants, should check their own rules on referral fees and disclosure. See the program terms.

When to skip a TPA

  • Its value is almost entirely client claim and member files.
  • A carrier or plan sponsor controls every document in its contract.
  • The firm has fewer than 50 full-time employees at peak.
  • Nobody can export the knowledge base or training library.

Next step

Run a TPA you know through the company fit checker. If the firm clearly owns documentation of its own, register as a partner and make the introduction. Owners can also apply at sourcex.si/apply.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Can a TPA sell its claims data to AI developers?

Generally no, not on its own authority. Claim files usually belong to the carrier, employer or plan, often contain health information and are governed by the administrative services agreement. A TPA's own procedures, audit checklists and training materials are the more realistic candidates, after contract and privacy review.

Does de-identified claims data solve the problem?

It addresses the privacy side only if the de-identification meets the legal standard. It does not settle ownership. The client contract may still restrict any use of derived data, so the TPA needs written client consent or confirmation that the contract allows it.

What size of TPA qualifies?

The baseline is a US company with 50+ full-time employees at peak, contractors excluded, several years of documented operations, rights to license the material and an authorized sponsor. A firm may be large and still fail if it owns nothing licensable.

What if the TPA is owned by a carrier?

A carrier-owned administrator often shares systems and contracts with its parent. Ask who controls the documentation and whether a corporate legal team must approve any license. That can be possible, but the authorized sponsor and rights chain need to be clear before anything is scoped.

Should I mention PHI when I make the introduction?

Yes, briefly. Tell the owner you are not asking about claim or member data and are asking only about the firm's own procedures and training material. That sets expectations, builds trust and keeps you away from handling any confidential record.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment