Can a HIPAA business associate de-identify PHI and license the result?
A business associate can de-identify PHI only if its business associate agreement permits that use, and the output must meet HIPAA's Safe Harbor or Expert Determination standard to stop being PHI. Whether it may then license the result depends on the BAA's ownership and commercial-use clauses, so read the agreement first.
Can a business associate de-identify PHI and license the result?
Only if its business associate agreement (BAA) permits it. A business associate may use protected health information only as the BAA and HIPAA allow, and creating de-identified data from PHI is itself a use of PHI. If the BAA is silent or prohibits it, the vendor generally cannot de-identify the data for its own purposes, and the question of licensing never arises. If the BAA does permit it, the result must meet HIPAA's de-identification standard before it stops being PHI.
That makes the BAA the first document to read when a billing, revenue cycle management (RCM), coding or healthcare-admin company is considered for a referral. It can save a partner a dead-end introduction.
This is general information, not legal, tax or financial advice. Confirm with the company's own HIPAA counsel before acting.
What HIPAA says about the result
HHS describes two methods in its guidance on de-identification of PHI: Expert Determination, where a qualified expert documents that the risk of re-identification is very small, and Safe Harbor, which removes 18 listed identifiers and requires no actual knowledge that the rest could identify a person. Information de-identified by either method is no longer PHI under the Privacy Rule. The Safe Harbor versus Expert Determination comparison covers how those differ for business records.
De-identification does not erase other duties. Contracts with the covered entity, state laws and the BAA's own wording can still limit what a vendor does with data derived from its client's PHI.
What to look for in a BAA
| Clause | What to check | Why it matters |
|---|---|---|
| Permitted uses | Does it list de-identification or only service delivery? | Creating de-identified data needs authority to use PHI that way |
| Ownership of derived data | Who owns de-identified or aggregated output? | A silent clause leaves ownership unclear |
| Standard required | Safe Harbor, Expert Determination, or either | Sets how the output must be produced |
| Commercial use | Any prohibition on sale, licensing or marketing | A de-identification right may not extend to licensing |
| Subcontractors | Which vendors touch the data | Downstream copies need the same authority |
| Return or destruction | What happens at contract end | Archives may have to be deleted |
The related contract issue in ordinary B2B software is covered in aggregated and de-identified data clauses in SaaS agreements.
Where partners should stop and ask
- If most of the company's records are PHI belonging to clients, treat the referral as a red flag until the client contracts say otherwise.
- If the company's work is mostly non-PHI operations, such as HR, finance, IT tickets and sales, the BAA matters less and the usual rights review applies.
- If the BAA is missing or unreadable, ask the owner to bring counsel in before the company sees an inventory form.
The general question of whether licensing business records for AI training is lawful is covered in is it legal to license company records for AI training. Workforce records raise employee consent questions. If the company is being sold, see data licensing during a business sale, since contract rights can change hands in a sale.
What counts as the company's own data?
A healthcare billing firm holds two different kinds of records. Client PHI sits under the BAA. Its own operations (staff tickets, finance, HR, sales, internal procedures) are not PHI, though patient names can leak into free-text notes. Fit screening for a referral looks at the second kind, and a company that cannot separate the two is a "not yet".
What to say to the owner
How SourceX fits
Mainly-PHI datasets without HIPAA authorization or de-identification are a red flag for SourceX, so a billing or RCM firm is judged on its own operational records, not its clients' PHI. The partner's job is to ask the BAA question and step back.
Next step
Screen the company with the company fit checker, then read how it works. If the company is a non-PHI-heavy fit, register as a partner to introduce it.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
What is a business associate under HIPAA?
A business associate is an organization that performs functions or services for a covered entity that involve PHI, such as billing, claims processing, coding or IT hosting. Its permitted uses of PHI come from the BAA and HIPAA. A vendor that never handles PHI is not a business associate, and a separate analysis applies.
If data is properly de-identified, can the vendor do anything with it?
Not automatically. De-identified data is no longer PHI under the Privacy Rule, but the vendor's contracts, the covered entity's wishes, and state laws can still limit its use. The BAA and the services agreement should state who owns derived data. Counsel should read them together.
Does an RCM firm qualify for SourceX?
It can, if it meets the company baseline of 50+ full-time employees at peak (contractors excluded), has years of documented operations, holds rights to the data it would license, and has an authorized sponsor. Its own operational records, such as tickets, finance and internal workflows, differ from client PHI, which would be out of scope without authorization.
Who decides whether the BAA allows de-identification?
The vendor's counsel, usually with the covered entity's input. A partner should not interpret the agreement. Ask the owner whether counsel has reviewed it for de-identification and derived-data rights, and move on if the answer is no or unclear.
Can a covered entity license its own de-identified data?
A covered entity may de-identify its own PHI under HIPAA, subject to its own policies, patient-facing notices, state law and contracts. That is a different question from a vendor doing so. The covered entity should have its privacy officer and counsel confirm the method and any limits.
Related pages
- HIPAA safe harbor vs expert determination: which fits business records?
- Aggregated and de-identified data clauses in B2B SaaS contracts: what they allow
- Is it legal for a company to license its business records for AI training?
- Do you need employee consent to license workplace data?
- Identifying Data Licensing Opportunities During a Business Sale
- Check Company Fit for Data Licensing
Free resources
- SDE vs EBITDA calculator — Seller's discretionary earnings next to market-rate EBITDA.
- IRR calculator — Internal rate of return on annual cash flows.
- Business valuation calculator — Enterprise and equity value from EBITDA, your multiple, cash and debt.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment