What is a HIPAA business associate, and can it license the data it holds?
A HIPAA business associate is a person or company that creates, receives, maintains or transmits protected health information on behalf of a covered entity, such as a billing firm, claims processor or IT vendor. It may use that information only as its business associate agreement allows, so client PHI is generally not the vendor's to license.
The short answer
A HIPAA business associate is a person or organization that creates, receives, maintains or transmits protected health information (PHI) on behalf of a covered entity, or provides certain services to one that involve PHI. Whether a given company is one depends on what it does with PHI and for whom. The definitions and contract requirements sit in the HIPAA Privacy and Security Rules; read the regulation text with HIPAA counsel, because this page is a plain-language guide.
The consequence for data licensing is blunt: PHI a vendor holds for its covered-entity clients is generally the clients' to control, not the vendor's to license.
Who counts as a business associate?
Covered entities are health plans, health care clearinghouses and health care providers that conduct certain transactions electronically. Business associates are the outside organizations that do work for them involving PHI. Common examples:
- Medical billing and revenue cycle management companies
- Claims processing and third-party administration firms
- Healthcare contact centers and business process outsourcers that handle patient or member calls
- IT, cloud hosting and managed service providers that maintain systems containing electronic PHI
- Transcription, coding and document management vendors
- Accountants, lawyers and consultants whose work for a provider or plan involves access to PHI
A business associate's own subcontractor that handles PHI is generally a business associate too. Members of the covered entity's workforce are not business associates, and a provider that receives information to treat a patient acts in its own right rather than on the covered entity's behalf.
Business associate vs covered entity
| Organization | Usual HIPAA role | What it means for licensing its records |
|---|---|---|
| Hospital, physician group, dental practice | Covered entity (provider) | Patient records are PHI; licensing them needs authorization or de-identification |
| Employer-sponsored or insurer health plan | Covered entity (plan) | Member and claims records are PHI |
| Billing, coding or revenue cycle firm | Business associate | Client PHI may be used only as each agreement allows |
| Contact center serving a health plan | Business associate | Member call recordings and tickets are the plan's PHI |
| MSP or cloud host for a clinic | Business associate where it maintains electronic PHI | Client system content serves only the contracted services |
| Healthcare staffing firm or admin consultant with no PHI access | Often neither | Its own operational records are assessed like any company's |
For the wider distinction between personal data and health data, see PII vs PHI. Privacy law's idea of a processor acting for a controller is a close cousin of the business associate role, and the controller and processor comparison sets out the parallel.
What a business associate agreement allows
A covered entity may share PHI with a business associate only under a written business associate agreement (BAA) that sets the permitted and required uses of the information. In general terms, the BAA:
- limits the business associate to the uses and disclosures the contract permits or the law requires
- requires safeguards for the information and reporting of breaches and other incidents
- requires the same restrictions to flow down to subcontractors
- addresses return or destruction of PHI when the relationship ends, where feasible
Licensing client PHI for AI training is generally not a purpose a BAA permits. That decision belongs to the covered entity, under HIPAA's rules on authorization and de-identification, not to the vendor holding the files.
What changes if the data is de-identified?
De-identified health information is no longer PHI under the Privacy Rule. HHS guidance describes two ways to meet the de-identification standard at 45 CFR 164.514: Expert Determination, where a qualified expert determines and documents that the risk of re-identification is very small, and Safe Harbor, which requires removing 18 specified identifiers and having no actual knowledge that the remaining information could identify an individual (HHS de-identification guidance).
Two caveats matter for a vendor. Whether it may de-identify a client's PHI at all, and what it may do with the result, depends on its BAA and client contracts. And de-identification removes HIPAA status but not contractual confidentiality. In SourceX deals, de-identification and redaction requirements are agreed with the company before any work begins.
How this plays out in common screening situations
| Situation | What to check | Typical outcome to confirm with counsel |
|---|---|---|
| A billing company wants to license the claims it processes | BAAs and client contracts | Generally excluded unless the covered entities authorize it |
| The same company offers its internal SOPs, QA rubrics and training guides | Whether documents embed real patient examples; confidentiality clauses | Often in scope after review and redaction |
| A vendor holds a dataset it already de-identified | BAA permission to de-identify, the method used, client restrictions | Depends on the BAA and how the method was documented |
| A contact center records calls for a health plan | BAA terms and recording notices | Recordings are the plan's PHI; usually excluded |
| A health-tech software firm offers engineering tickets and code reviews | Whether tickets contain PHI samples or screenshots | Often in scope with redaction or filtering |
Business brokers and M&A advisors who sell healthcare-services companies meet this question often; the comparison of M&A advisors and business brokers explains who typically handles which deals.
Good practice for partners making introductions
- Never ask for, view, export or describe PHI or any client record; share only basic fit information.
- Ask the owner which records the company created for its own operations and which it holds for clients under BAAs.
- Treat a company whose records are mainly PHI, without authorization or de-identification, as a poor fit for now.
- Let the company and its counsel decide what is in scope; SourceX delivers data only after an executed agreement and the company's authorization.
Questions to ask HIPAA counsel
- Is the company a covered entity, a business associate, or both for different service lines?
- Which of its records contain PHI, and which are purely internal operating records?
- Do its BAAs allow de-identification or any secondary use, and on what conditions?
- Which de-identification method would be used and documented, and by whom?
- Do client contracts impose confidentiality beyond HIPAA?
This is general information, not legal, tax or financial advice. Confirm with your own HIPAA counsel before acting.
Next step
The company fit checker offers a preliminary, non-binding screen, and who qualifies sets out the baseline, including the rights test that rules out client-owned PHI. Advisors to healthcare-administration and BPO owners can register as a partner and introduce companies whose own operational records pass that test.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
What is a BAA?
A business associate agreement is the written contract a covered entity must have with a vendor before sharing PHI with it. It states what the vendor may and may not do with the information, the safeguards it must keep, how incidents are reported and what happens to the data when the relationship ends. It is the first document to read when deciding whether a vendor's records could be licensed.
Can a business associate use PHI for its own purposes?
Only to the extent its business associate agreement and the HIPAA rules allow. Some agreements permit limited uses, such as the vendor's own management and administration, or de-identification under stated conditions. Licensing a client's PHI for AI training is generally outside those permissions, so the covered entity's decision, not the vendor's, controls.
Is a medical billing company a covered entity or a business associate?
Usually a business associate, because it processes claims and payments on behalf of providers that are covered entities. A billing firm that also acts as a clearinghouse, converting nonstandard data into standard transactions, may be a covered entity for that function. Ask counsel to map each service line, because the role determines what the firm may do with each dataset.
Does HIPAA apply to a vendor that never sees patient data?
Generally not for that work. A company that serves a hospital or plan without creating, receiving, maintaining or transmitting PHI is not a business associate for those services. A consultant redesigning scheduling workflows from aggregate, de-identified metrics may fall outside HIPAA for those records, although client contracts can still impose confidentiality.
Can a healthcare administration company still qualify for data licensing?
It can, if it holds substantial operational records of its own: process documentation, quality rubrics, internal tickets, engineering history and finance or sales records about its business clients. Client PHI is generally excluded unless properly authorized or de-identified. The company still needs 50+ full-time employees at peak (contractors excluded), several years of documented operations and an authorized sponsor.
Related pages
- What is a managed service provider, and what does an MSP actually do?
- PII vs PHI: what is the difference, and what can a healthcare company license?
- Data controller vs data processor: what is the difference for data licensing?
- M&A advisor vs business broker vs investment banker: what is the difference?
- Check Company Fit for Data Licensing
- Which US businesses are a fit for a SourceX data licensing introduction
Free resources
- Working capital calculator — Net working capital, current ratio and quick ratio.
- Due diligence checklist generator — A tailored document request list by deal type.
- Cash flow calculator — A 12-month cash forecast with shortfalls highlighted.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment