Can a healthcare administration company license data that contains no PHI?
Yes, if the records genuinely contain no protected health information and the company has the rights to license them. Billing-operations procedures, scheduling workflows, payer-rule playbooks, staffing records and internal process documentation can be candidates. Anything with PHI needs either HIPAA authorization or de-identification first, and a company that cannot show which side a record falls on should not license it. This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.
This page helps referral partners avoid a dead-end introduction: you can spot early which healthcare administration companies are worth introducing and which are not.
Where does HHS draw the line?
The Privacy Rule treats health information as protected unless it is de-identified. HHS describes two methods for meeting the de-identification standard at 45 CFR 164.514: Expert Determination, where a qualified expert determines and documents that the risk of re-identification is very small, and Safe Harbor, which removes 18 specified identifiers with no actual knowledge that the remainder could identify an individual. Health information de-identified by either method is no longer PHI under the Privacy Rule.
For a referral partner the takeaway is simple. Data about patients, claims or encounters is a separate legal track. Data about how the company runs its business is where most administration companies start.
Which records usually sit on the safe side of the line?
| Record type | Example | PHI risk | Starting posture |
|---|---|---|---|
| Billing-operations SOPs | Claim submission checklists, denial handling playbooks | Low if templates carry no patient data | Strong candidate |
| Workflow and decision records | Escalation rules, exception approvals described without patient detail | Low to medium | Candidate after review |
| Internal communications | Slack or Teams threads about process | Medium; threads often quote patient identifiers | Screen and redact |
| Staffing and scheduling records | Shift coverage, capacity planning | Low | Candidate |
| Support tickets from provider clients | Ticket text often includes names and account numbers | High | Exclude or de-identify |
| Claims, remits, charts | Claim lines, remittance advice, notes | Direct PHI | Out of scope without authorization or de-identification |
For chat archives specifically, see whether a company can license Microsoft Teams chat history for AI training, because identifiers hide in conversational text.
What is the 3-tier PHI screen?
Use it with the owner as a conversation, not an audit.
- Tier 1, no patient data by design. SOPs, training material, policy documents, internal process records. Start here.
- Tier 2, patient data possible. Email, chat, tickets and shared drives. Needs screening, redaction and counsel sign-off before inclusion.
- Tier 3, patient data by definition. Claims, charts, remits, eligibility files. Out of scope unless authorization or HIPAA de-identification is in place and documented.
If the answer to "what does tier 1 contain, and how deep does it go?" is thin, the company probably will not qualify, because buyers value breadth and years of connected operational records.
What other rights issues arise for healthcare administrators?
Rights are usually the bigger obstacle than privacy. A revenue-cycle company works inside its provider clients' systems, and the records may belong to those clients or carry contractual limits. That is the same logic discussed in whether a SaaS company can license customer data for AI training: holding data on behalf of customers does not give the right to license it. Business associate agreements add their own restrictions on use. Treat data belonging to someone else without consent as a red flag.
To see how the company keeps title while licensing, read how to keep ownership of your company data when you license it.
How do you recognize a healthcare administration fit?
- 50+ full-time employees at peak (contractors excluded)
- Several years of documented operations
- Process records the company authored itself (SOPs, playbooks, training)
- An authorized sponsor: owner, CEO, CFO or authorized representative
- A clear answer on which systems hold PHI and which do not
- Willingness to consider an exclusive license for AI training for an agreed term
- No pending sale, trustee or assignee control that has not been involved
For companies mid-transaction, whether a company can license data after signing an LOI covers the timing questions. Dataset sizing is covered in how much data a company needs.
What should a partner say?
What does the process look like, and how are partners paid?
You introduce the company through the referral form or referral link and give basic fit information only. SourceX qualifies the company, the company completes a data inventory (the data inventory builder lists systems without describing contents), price and terms are agreed, buyers review, and the deal closes. Data is delivered only after an executed agreement and the company's authorization.
Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 cumulative per referred company. Rewards become payable only after the buyer pays and SourceX receives its fee, and no reward is guaranteed. Licensed professionals should check their own rules on referral fees and disclosure.
When to skip the introduction
Skip it if the records are mainly PHI without authorization or de-identification, if the company has fewer than 50 full-time employees at peak, or if its archive is mostly its provider clients' data. Read pros and cons of licensing company data to AI developers with the owner if they are undecided.
Next step
If you know a US healthcare administration company with years of its own non-PHI process records, register as a partner. The company can apply directly at sourcex.si/apply, and how it works explains the stages.