If your company runs clinics, billing or health services, patient records are mostly off the table for AI data programs. What may remain is the record of how your operations run. This guide names the laws, separates likely exclusions from possible scope, and lists the questions to take to a healthcare lawyer.
Last checked: October 7, 2026
AI labs and data companies are paying businesses for records of real work: how decisions get made, how problems get solved, how processes run. In most industries that means email, chat, tickets and documents. In healthcare, those same systems are full of protected health information, and that changes what a company can realistically offer.
For a provider, a health plan, a billing company or any vendor that handles patient information for one of them, the practical starting point is simple. Assume patient data is excluded, then look at what is left. A clinic group, a revenue-cycle firm or a home-health operator also runs scheduling, staffing, vendor management, IT, training and quality processes. Documentation of that work, written without patient details, is the part a buyer program might review.
That smaller scope is still real work history, and far easier to defend if anyone asks what left the building. This page is for companies; it is not about individuals selling their own medical records.
The term HIPAA uses for individually identifiable health information held or transmitted by covered entities and their business associates. Which of your records it covers is a question for your lawyer, system by system.
Each row pairs a law or term with the question it raises for a data sale. The descriptions are general and simplified. They are not interpretations of the law.
| Law or term | What it addresses, in general | Question to ask your lawyer |
|---|---|---|
| HIPAA Privacy Rule | Federal rules on how covered entities and business associates use and disclose PHI | For each data set we are considering, does the Privacy Rule apply, and on what basis? |
| Covered entities and business associates | The two roles HIPAA regulates directly | Are we a covered entity, a business associate, or neither, and does that differ by business line? |
| Sale of PHI provisions | HIPAA includes provisions that address the sale of PHI | Would this transaction count as a sale of PHI, and if so, what would it require? |
| De-identification, 45 CFR 164.514(b) | Names two methods: Safe Harbor and Expert Determination | Which method, if any, would apply to what we send, and who documents it? |
| Limited data sets and data use agreements | A defined category of partly identifiable data shared under a written agreement | Is a limited data set relevant to this deal at all, or outside what we should consider? |
| Business associate agreements (BAAs) | Contracts between covered entities and the vendors that handle PHI for them | What do our signed BAAs say about using, retaining or licensing client data? |
| 42 CFR Part 2 | Federal confidentiality rules for certain substance use disorder records | Do any of our systems hold records covered by Part 2? |
| State health-privacy laws | State rules that can reach health information, such as California’s CMIA and Washington’s My Health My Data Act | Which state laws apply to our records and our patients, and do they add requirements beyond HIPAA? |
If you also hold data on people in the EU or UK, read GDPR and selling data for AI training. For the general legal picture across industries, see is it legal to sell company data.
Use these lists to start an inventory, not to decide. Every item on the right still needs a review for PHI, a lawyer’s sign-off and the buyer’s confirmation that it is in scope.
The same spreadsheet can mean different things for a clinic, its billing vendor and a wellness startup. Start by asking which role you play for each data source.
Most patient-facing systems likely hold PHI. Your realistic offer is documentation of operations that never touches patient records. Ask your lawyer which systems can be reviewed at all.
Much of what you hold may be your clients’ records under your BAAs. Your own internal processes may be a different matter. Ask what each agreement permits before you list anything, and check the client side too in client confidentiality and data sales.
Health-tech, wellness or scheduling businesses may sit outside HIPAA for some products and inside it for others, depending on who their customers are. Some still hold health information that state laws address. Ask which role applies to each product line, and whether laws such as California’s CMIA or Washington’s My Health My Data Act reach your records.
Candidate and clinician files can include credentials, health screenings and immunization records. Treat those as excluded. Ask whether recruiter playbooks, credentialing workflows and client-onboarding processes can be described without personal details, and what your facility contracts say about information you learn on assignment.
Both companies below are invented to show the reasoning. Neither describes a real business, a real buyer response or a real price.
A fictional group runs eleven clinics in two US states. Its owner reads that buyers want records of how work gets done and starts an inventory.
A fictional 45-person billing firm works for dozens of independent practices under business associate agreements. Almost everything it touches belongs to a client.
These statements come from each program’s own pages. They describe the buyer’s process. They do not tell you whether HIPAA or a state law permits a given disclosure.
| Program | Published privacy statements | Published eligibility and payout |
|---|---|---|
| micro1 | Scope agreed in writing; sensitive and confidential information scrubbed; originals deleted after processing; no customer information exposed; the company keeps ownership of its underlying data | 30+ employees, documented processes, modern software tools, primarily English, US prioritized. Payout: $100K to $2M+ for approved data packages |
| Mode | Buys “an agreed copy”; originals stay with the company; de-identifies before onward delivery | 20+ full-time US office employees; several years of records the company owns. Payout: $100K to $5M |
| Grepped | No healthcare-specific statement cited here | Any vertical. Payout: $20K to $5M |
Last checked: October 7, 2026. Sources: micro1.ai/data-partnerships, micro1.ai/company-referral, data.mode.inc and grepped.ai, as published on that date. Published ranges are not offers; nobody can price your data without seeing it.
Even a clean operational scope carries contract risk. These are generic questions every seller should check, whoever the buyer is. In healthcare, each one matters more.
Ask whether indemnities and warranties run both ways, whether liability is capped, and when it expires. More in indemnities and warranties in data deals.
Contracts may ask you to confirm consent from employees, clients or patients. Do not warrant consent you do not have. Ask your lawyer what you can truthfully state.
Ask what method is used, who performs it, and whether you can review the output before delivery. Ask for audit rights in writing, in general terms.
Get a written list of sources, date ranges and exclusions. Ask how the buyer will treat material that falls outside it if some slips through.
Ask about deletion of exported originals and of the buyer’s copy, what proof you receive, and which clauses survive termination.
Training only, evaluation, or both? Which downstream buyers? Is the license exclusive, time-limited or open to resale?
Work through this list internally, before anything leaves the company.
Each of these is easy to make when a buyer seems interested and the process feels routine.
A sample is a disclosure like any other. Review it for PHI with the same care as the full package, or send a content-free manifest first.
A buyer’s published process describes what it does after receipt. It does not answer what you were allowed to send. Ask your lawyer about both.
Ticket comments, note fields, file names, calendar titles and email subject lines carry patient names more often than anyone expects. Scan them, not just the structured columns.
Contracts with clients, state laws and confidentiality promises can still apply after identifiers are removed. Ask which obligations survive de-identification.
This page cannot tell you that any specific sale is lawful. Patient records held by covered entities and their business associates are protected health information under HIPAA, and HIPAA has provisions that address the sale of PHI. For companies applying to the buyer programs described here, patient data is mostly off the table. The realistic scope is operational documentation. Ask a healthcare lawyer before you list anything.
HIPAA names two de-identification methods in 45 CFR 164.514(b): Safe Harbor and Expert Determination. Whether a given data set meets either one, and whether state laws or your contracts still restrict it, are questions for your lawyer. Also ask the buyer which method it relies on and, in the contract, who pays if de-identification misses something.
Possibly documentation of how operations run: SOPs, internal policies, scheduling and intake workflows described without patient details, revenue-cycle process guides, vendor and IT support processes, and staff training materials. Each item still needs a review for PHI, a lawyer’s sign-off and the buyer’s confirmation that it is in scope.
Treat it as excluded unless your lawyer and each client agreement say otherwise. Data you handle for covered entities is often governed by business associate agreements, and those contracts may limit any use beyond the services you provide. Your own internal processes are a separate question worth raising with your lawyer.
The rules we cite from their pages are general, not healthcare-specific. micro1 lists 30+ employees and documented processes, Mode lists 20+ full-time US office employees, and Grepped lists any vertical (as published October 7, 2026). Run the eligibility checker with the healthcare admin option, then confirm healthcare scope with the buyer before you send anything.
We cannot tell you. Mode’s published rule refers to full-time US office employees, and micro1’s refers to 30+ employees (as published October 7, 2026). How a buyer counts clinical or field staff is a question to put to the buyer before you apply, not something to assume.
A sample is still a disclosure. Practitioners advise sharing a manifest and samples before price, but in healthcare the sample needs the same PHI review and legal sign-off as the full package. A manifest that describes sources, date ranges and exclusions, without any content, can come first.
micro1’s page lists what it wants: SOPs, knowledge bases, internal documentation, CRM data, project histories, QA processes and decision-making patterns. Operational healthcare documentation is that kind of material. Whether a specific package is worth a price is something only a buyer can say after review; published ranges are not offers.
Run the eligibility checker, choose healthcare admin as your industry and answer the patient-records question honestly. It flags regulated data and shows each program’s published rules. Then compare programs before you apply.
Independent site. Some links are referral links: if your company signs with a buyer through them, the buyer may pay us a fee. You are not charged, and we never see your data.