Sell Data to AI
Home Data Asset Score Pricing API documentation US labs and CROs list
For brokers
How to become an AI data broker Data broker business model Buyer programs compared Qualify a company AI training data companies
For data companies
Firmographic data providers Company data API
Seller guides
How to sell data to AI companies Is it legal? FAQ and glossary About
Check domain/company
Healthcare · Legal guide

Selling Healthcare Data for AI Training: What HIPAA Leaves Open

If your company runs clinics, billing or health services, patient records are mostly off the table for AI data programs. What may remain is the record of how your operations run. This guide names the laws, separates likely exclusions from possible scope, and lists the questions to take to a healthcare lawyer.

Last checked: October 7, 2026

$100K to $2M+micro1 referral page, for approved data packages
20+Mode: full-time US office employees
60 to 90 daysPractitioners’ typical time to close
Agreed copyMode: originals stay with the company
Start here

The short answer for healthcare companies

AI labs and data companies are paying businesses for records of real work: how decisions get made, how problems get solved, how processes run. In most industries that means email, chat, tickets and documents. In healthcare, those same systems are full of protected health information, and that changes what a company can realistically offer.

For a provider, a health plan, a billing company or any vendor that handles patient information for one of them, the practical starting point is simple. Assume patient data is excluded, then look at what is left. A clinic group, a revenue-cycle firm or a home-health operator also runs scheduling, staffing, vendor management, IT, training and quality processes. Documentation of that work, written without patient details, is the part a buyer program might review.

That smaller scope is still real work history, and far easier to defend if anyone asks what left the building. This page is for companies; it is not about individuals selling their own medical records.

Definition: protected health information (PHI)

The term HIPAA uses for individually identifiable health information held or transmitted by covered entities and their business associates. Which of your records it covers is a question for your lawyer, system by system.

Laws and terms

What to name when you talk to your lawyer

Each row pairs a law or term with the question it raises for a data sale. The descriptions are general and simplified. They are not interpretations of the law.

Law or termWhat it addresses, in generalQuestion to ask your lawyer
HIPAA Privacy RuleFederal rules on how covered entities and business associates use and disclose PHIFor each data set we are considering, does the Privacy Rule apply, and on what basis?
Covered entities and business associatesThe two roles HIPAA regulates directlyAre we a covered entity, a business associate, or neither, and does that differ by business line?
Sale of PHI provisionsHIPAA includes provisions that address the sale of PHIWould this transaction count as a sale of PHI, and if so, what would it require?
De-identification, 45 CFR 164.514(b)Names two methods: Safe Harbor and Expert DeterminationWhich method, if any, would apply to what we send, and who documents it?
Limited data sets and data use agreementsA defined category of partly identifiable data shared under a written agreementIs a limited data set relevant to this deal at all, or outside what we should consider?
Business associate agreements (BAAs)Contracts between covered entities and the vendors that handle PHI for themWhat do our signed BAAs say about using, retaining or licensing client data?
42 CFR Part 2Federal confidentiality rules for certain substance use disorder recordsDo any of our systems hold records covered by Part 2?
State health-privacy lawsState rules that can reach health information, such as California’s CMIA and Washington’s My Health My Data ActWhich state laws apply to our records and our patients, and do they add requirements beyond HIPAA?

If you also hold data on people in the EU or UK, read GDPR and selling data for AI training. For the general legal picture across industries, see is it legal to sell company data.

Scope

Likely off the table vs. might qualify after review

Use these lists to start an inventory, not to decide. Every item on the right still needs a review for PHI, a lawyer’s sign-off and the buyer’s confirmation that it is in scope.

Likely off the table

  • Clinical notes, charts and EHR exports
  • Lab results, imaging and diagnostic files
  • Claims, remittances and statements tied to patients
  • Patient portal messages, emails and texts with patients
  • Recordings and transcripts of patient calls
  • Intake forms, referrals and appointment records with names or dates
  • Anything from substance use disorder programs
  • Data you hold for a client under a BAA, unless your lawyer and that client’s agreement say otherwise

Might qualify after review

  • Standard operating procedures and internal policies
  • Scheduling and intake workflows, written as process without patient details
  • Revenue-cycle process guides: how denials are worked and how coding questions are escalated, not the claims themselves
  • Vendor management, procurement and contract workflows
  • IT and internal support processes, after a review for PHI
  • Staff training materials and onboarding guides
  • Project histories in tools such as Jira or Asana for non-clinical work
Mixed systems are the hard part. A ticketing system, a shared drive or a Teams workspace often holds both process notes and patient details. If PHI can sit anywhere in a source, treat the whole source as excluded until someone qualified has reviewed it. For how buyers approach redaction and pseudonyms in general, see de-identification before selling data.
Your role

Your role decides the starting point

The same spreadsheet can mean different things for a clinic, its billing vendor and a wellness startup. Start by asking which role you play for each data source.

Providers and health plans

Most patient-facing systems likely hold PHI. Your realistic offer is documentation of operations that never touches patient records. Ask your lawyer which systems can be reviewed at all.

Billing, RCM, transcription and IT vendors

Much of what you hold may be your clients’ records under your BAAs. Your own internal processes may be a different matter. Ask what each agreement permits before you list anything, and check the client side too in client confidentiality and data sales.

Health-tech and health-adjacent companies

Health-tech, wellness or scheduling businesses may sit outside HIPAA for some products and inside it for others, depending on who their customers are. Some still hold health information that state laws address. Ask which role applies to each product line, and whether laws such as California’s CMIA or Washington’s My Health My Data Act reach your records.

Healthcare staffing firms

Candidate and clinician files can include credentials, health screenings and immunization records. Treat those as excluded. Ask whether recruiter playbooks, credentialing workflows and client-onboarding processes can be described without personal details, and what your facility contracts say about information you learn on assignment.

Worked examples

Two fictional companies work out their scope

Both companies below are invented to show the reasoning. Neither describes a real business, a real buyer response or a real price.

Illustrative, not an offer

An 80-person physical therapy group

A fictional group runs eleven clinics in two US states. Its owner reads that buyers want records of how work gets done and starts an inventory.

  • Out: the EHR, plans of care, claims, the patient texting tool, and front-desk email, because staff routinely discuss appointments there.
  • Might remain: the new-clinic opening playbook, the insurance-verification process guide, the staff training curriculum and the Asana history of clinic build-outs.
  • Open questions: do any Asana tasks name patients; do the two states add rules; and do clinicians count toward a buyer’s office-employee minimum?
Illustrative, not an offer

A medical billing company

A fictional 45-person billing firm works for dozens of independent practices under business associate agreements. Almost everything it touches belongs to a client.

  • Out: claims, remittances, patient statements, client ticket queues that quote accounts, and recorded calls with payers and patients.
  • Might remain: its own denial-management SOPs written in general terms, internal training, and the Jira history of its in-house reporting tool, if tickets contain no PHI.
  • Open questions: do the BAAs or client contracts restrict use of knowledge derived from client work, and were the SOPs built from client materials?
The pattern. In both cases the scope shrinks to documentation the company wrote about its own operations. Both owners also end up with a list of questions only a lawyer can answer. That list is the useful output of an inventory, and the reason to make one before you apply. The vendor case also raises client duties; see client confidentiality and data sales.
As published

What the buyer programs publish about privacy

These statements come from each program’s own pages. They describe the buyer’s process. They do not tell you whether HIPAA or a state law permits a given disclosure.

ProgramPublished privacy statementsPublished eligibility and payout
micro1Scope agreed in writing; sensitive and confidential information scrubbed; originals deleted after processing; no customer information exposed; the company keeps ownership of its underlying data30+ employees, documented processes, modern software tools, primarily English, US prioritized. Payout: $100K to $2M+ for approved data packages
ModeBuys “an agreed copy”; originals stay with the company; de-identifies before onward delivery20+ full-time US office employees; several years of records the company owns. Payout: $100K to $5M
GreppedNo healthcare-specific statement cited hereAny vertical. Payout: $20K to $5M

Last checked: October 7, 2026. Sources: micro1.ai/data-partnerships, micro1.ai/company-referral, data.mode.inc and grepped.ai, as published on that date. Published ranges are not offers; nobody can price your data without seeing it.

Reported context. In the Spirit Airlines data sale (August 2026), micro1 said it pursues “non-sensitive, non-consumer data” with third-party de-identification, as reported in coverage of that case. For a healthcare company the takeaway is practical: the buyer side, too, describes its target as non-sensitive data, so a scope built on patient records is unlikely to fit.
Before you sign

Questions to ask before you sign

Even a clean operational scope carries contract risk. These are generic questions every seller should check, whoever the buyer is. In healthcare, each one matters more.

Liability

Who pays if de-identification misses something?

Ask whether indemnities and warranties run both ways, whether liability is capped, and when it expires. More in indemnities and warranties in data deals.

Consent

What will we represent about consent?

Contracts may ask you to confirm consent from employees, clients or patients. Do not warrant consent you do not have. Ask your lawyer what you can truthfully state.

Audit

Can we check the de-identification?

Ask what method is used, who performs it, and whether you can review the output before delivery. Ask for audit rights in writing, in general terms.

Scope

What exactly is in the package?

Get a written list of sources, date ranges and exclusions. Ask how the buyer will treat material that falls outside it if some slips through.

Deletion

What happens to originals and the copy?

Ask about deletion of exported originals and of the buyer’s copy, what proof you receive, and which clauses survive termination.

Use

Who can use the data downstream?

Training only, evaluation, or both? Which downstream buyers? Is the license exclusive, time-limited or open to resale?

Pre-check

A healthcare pre-check before you apply

Work through this list internally, before anything leaves the company.

  • Name your role per source: covered entity, business associate, or neither, for each system you might include.
  • Map where PHI lives: EHR, practice management, billing, phones, shared drives, chat. Mark every source that could contain it.
  • Pull your BAAs and client contracts: note what they say about data use, retention and licensing.
  • Write an exclusions list before you write a scope. Buyers can work with a narrow, clear package.
  • Check for Part 2 records and for state laws that may apply where your patients live.
  • Decide who reviews samples. Practitioners advise sharing a manifest and samples before price and getting more than one offer. In healthcare, the samples themselves need a PHI review first.
  • Plan employee communication. Staff wrote these records, and some will ask what is being sold.
  • Book time with a healthcare lawyer before you sign an NDA that covers data review.
Timing. Deals take weeks to months: NDA, buyer review, agreement, export, de-identification, acceptance, payment. Practitioners cite 60 to 90 days to close. In healthcare, add your own legal review on top, and do not plan around speed.

Common mistakes in healthcare data deals

Each of these is easy to make when a buyer seems interested and the process feels routine.

Mistake

Sending a quick sample before review

A sample is a disclosure like any other. Review it for PHI with the same care as the full package, or send a content-free manifest first.

Mistake

Treating the buyer’s de-identification as your compliance

A buyer’s published process describes what it does after receipt. It does not answer what you were allowed to send. Ask your lawyer about both.

Mistake

Forgetting free-text fields

Ticket comments, note fields, file names, calendar titles and email subject lines carry patient names more often than anyone expects. Scan them, not just the structured columns.

Mistake

Assuming “de-identified” ends every question

Contracts with clients, state laws and confidentiality promises can still apply after identifiers are removed. Ask which obligations survive de-identification.

FAQ

Healthcare data and AI training: common questions

Can a clinic sell patient records to an AI company?

This page cannot tell you that any specific sale is lawful. Patient records held by covered entities and their business associates are protected health information under HIPAA, and HIPAA has provisions that address the sale of PHI. For companies applying to the buyer programs described here, patient data is mostly off the table. The realistic scope is operational documentation. Ask a healthcare lawyer before you list anything.

Does de-identified health data become safe to sell?

HIPAA names two de-identification methods in 45 CFR 164.514(b): Safe Harbor and Expert Determination. Whether a given data set meets either one, and whether state laws or your contracts still restrict it, are questions for your lawyer. Also ask the buyer which method it relies on and, in the contract, who pays if de-identification misses something.

What healthcare company data might a buyer accept?

Possibly documentation of how operations run: SOPs, internal policies, scheduling and intake workflows described without patient details, revenue-cycle process guides, vendor and IT support processes, and staff training materials. Each item still needs a review for PHI, a lawyer’s sign-off and the buyer’s confirmation that it is in scope.

We are a billing or IT vendor to clinics. Can we include client data?

Treat it as excluded unless your lawyer and each client agreement say otherwise. Data you handle for covered entities is often governed by business associate agreements, and those contracts may limit any use beyond the services you provide. Your own internal processes are a separate question worth raising with your lawyer.

Do the buyer programs accept healthcare companies?

The rules we cite from their pages are general, not healthcare-specific. micro1 lists 30+ employees and documented processes, Mode lists 20+ full-time US office employees, and Grepped lists any vertical (as published October 7, 2026). Run the eligibility checker with the healthcare admin option, then confirm healthcare scope with the buyer before you send anything.

Do clinicians count toward a program’s employee minimum?

We cannot tell you. Mode’s published rule refers to full-time US office employees, and micro1’s refers to 30+ employees (as published October 7, 2026). How a buyer counts clinical or field staff is a question to put to the buyer before you apply, not something to assume.

Can we send a small sample to see if a buyer is interested?

A sample is still a disclosure. Practitioners advise sharing a manifest and samples before price, but in healthcare the sample needs the same PHI review and legal sign-off as the full package. A manifest that describes sources, date ranges and exclusions, without any content, can come first.

Is operational healthcare documentation worth anything to buyers?

micro1’s page lists what it wants: SOPs, knowledge bases, internal documentation, CRM data, project histories, QA processes and decision-making patterns. Operational healthcare documentation is that kind of material. Whether a specific package is worth a price is something only a buyer can say after review; published ranges are not offers.

Check fit first, then apply with a narrow scope

Run the eligibility checker, choose healthcare admin as your industry and answer the patient-records question honestly. It flags regulated data and shows each program’s published rules. Then compare programs before you apply.

Independent site. Some links are referral links: if your company signs with a buyer through them, the buyer may pay us a fee. You are not charged, and we never see your data.

Related reading

Keep going