Skip to content

Privacy, de-identification and sensitive data

Business associate agreement or data license? How AI developers should receive health data

Quick answer

Use a business associate agreement (BAA) only when you handle protected health information (PHI) to perform a service for a covered entity; it does not, by default, let you train your own models. If you want health data to build or evaluate your product, receive a limited data set under a data use agreement for narrow purposes, or, more commonly, receive data de-identified under 45 CFR 164.514 and governed by a commercial data license [1][2].

By SourceX Editorial · Updated

This page is general information, not legal advice. Confirm requirements with counsel for your jurisdiction and use case.

The contract follows the data's legal status, not the other way around. PHI disclosed so you can perform a function for a hospital, health plan or clearinghouse makes you a business associate, and the BAA defines every use you may make of it [3]. A limited data set is still PHI, so it travels under a data use agreement (DUA) with fixed purposes [2][5]. De-identified data is no longer PHI, so HIPAA stops governing it and a commercial license sets the terms [1].

Many AI developers sit in two of these positions at once. Your clinical documentation product may run under BAAs with health systems while your research team buys training corpora from other sources. Treat these as separate data flows with separate contracts, separate storage and separate access groups, because PHI that leaks from the service flow into the training flow is the failure mode regulators and customers will ask about.

Illustrative example: invented to show structure; it does not describe an available dataset.

QuestionBAA (PHI, service)DUA (limited data set)Data license (de-identified)
Is the data PHI?YesYes, minus 16 direct identifier categoriesNo, if 164.514(a)-(b) is met
Why you receive itTo perform a function for the covered entityResearch, public health or health care operationsAny purpose the license allows
Who sets permitted usesThe BAA, within what the covered entity could do itselfThe DUA under 164.514(e) [2]The license and other applicable law [1]
Training your own general modelOnly if expressly permitted and lawful; often notOnly within the stated purposeAllowed if the license grants it
HIPAA obligations on youSecurity Rule, breach notice, direct liabilityDUA terms: no re-identification, no contactNone under HIPAA; state law may still apply [6]
Key diligence documentSigned BAA and subcontractor BAAsSigned DUA naming purpose and recipientsExpert Determination report or Safe Harbor attestation [1]

When an AI vendor becomes a business associate

An AI company is a business associate when it creates, receives, maintains or transmits PHI to perform a function or service for a covered entity [3]. Ambient scribing, coding automation, prior-authorization agents, inbox triage and hosted inference on patient records all fit that description. The status attaches by conduct, so an unsigned BAA does not make you something else; it makes you a business associate without the required contract.

The obligation cascades downstream. Market guidance advises signing a BAA with each third party that touches PHI before any data moves, including cloud hosts, annotation vendors and model API providers [4]. If an outside annotation vendor sees transcripts with patient names on your behalf, that vendor is your subcontractor business associate. See annotation vendor access to sensitive data for the access controls that keep that chain auditable.

Why a BAA rarely covers training your own model

A BAA authorizes uses for the covered entity's purposes, and it generally cannot authorize a use the covered entity itself could not make. Building a general model that you will sell to other customers is a use for your benefit, not a service for the hospital. HHS does let a BAA permit the business associate's own management and administration and certain data aggregation services, but those exceptions do not read naturally as product training rights.

Counsel should look for three failure modes in existing BAAs. First, silence: the BAA says nothing about model training, so the use is not permitted. Second, overbroad language such as "to improve our services" that a customer later reads narrowly. Third, a de-identification right with no stated method or permitted downstream use, which leaves the output's status open [1].

The clean route inside a BAA is explicit. HHS guidance says a business associate may de-identify PHI on a covered entity's behalf only to the extent the BAA authorizes it, and data that meets the standard is no longer PHI [1]. If you want that right, negotiate a clause that names the method (Safe Harbor or Expert Determination), who performs it, and what you may do with the result.

Limited data sets and data use agreements

A limited data set suits research or operations work that needs dates or geography that Safe Harbor would strip. Under 164.514(e), it excludes 16 categories of direct identifiers, but may keep elements such as dates and town or ZIP code, and the recipient must sign a DUA [2]. The DUA limits use to research, public health or health care operations, names who may use the data, and bars re-identification and contact with individuals [2][5].

That purpose limit is the constraint for AI developers. A DUA written for a specific study rarely stretches to pretraining a commercial model, and the data stays PHI throughout. Read HIPAA limited data sets and DUAs for AI development before you choose this path for product work.

De-identified data under a commercial license

Properly de-identified health data falls outside the Privacy Rule, which is why it is the usual basis for training and evaluation data [1][5]. Your obligations then come from the license, state privacy law and your own risk controls rather than HIPAA.

The label alone is not enough. Ask which method was used: Safe Harbor removes 18 identifier types and requires no actual knowledge that the rest could identify someone, while Expert Determination relies on a documented statistical or scientific analysis of re-identification risk [1][2]. Free-text clinical notes, call transcripts and claims narratives often hide identifiers that structured removal misses. Compare the methods in Safe Harbor vs Expert Determination for AI training and review an Expert Determination report.

De-identified status can be lost. If a covered entity or business associate re-identifies records, they are PHI again [1], and re-identification by any recipient undermines the basis on which the data was released. Licenses for health data should therefore prohibit re-identification and linkage to other sources that could reverse the process; see linkage and mosaic risk.

Clauses to put in each contract

The contract you sign should state the training position in words, not leave it to inference. Use the checklist below as a redline guide.

Illustrative example: invented to show structure; it does not describe an available dataset.

Health data contract checklist for AI developers

  • BAA (service flow):
    • Permitted uses list the specific service (for example, "generate draft visit notes for review by Customer clinicians").
    • Model training on Customer PHI is either expressly prohibited or expressly permitted with scope, and counsel has confirmed the covered entity could permit it.
    • De-identification clause names the method, performer, and permitted uses of de-identified output [1].
    • Subcontractor BAAs flow down to hosting, inference and labeling vendors [4].
    • Return or destruction terms cover model artifacts, logs, embeddings and caches, not only source files.
  • DUA (limited data set):
    • Purpose is research, public health or health care operations, and AI development is named within it [2].
    • Named recipients and no further disclosure beyond them.
    • No re-identification and no contact with individuals.
  • Data license (de-identified):
    • Representation of the HIPAA method used and a copy of the Expert Determination report or Safe Harbor attestation [1].
    • Defined records, fields, permitted uses (training, fine-tuning, evaluation), term and delivery.
    • Ban on re-identification and on linkage to identified data.
    • Treatment of non-HIPAA health data, such as consumer health data under Washington's My Health My Data Act [6].
    • Separate handling for substance use disorder records under 42 CFR Part 2.

State law and records HIPAA does not cover

HIPAA is not the only regime for health data. Washington's My Health My Data Act defines consumer health data broadly, including information that identifies past, present or future health status, and it reaches companies outside HIPAA [6]. Substance use disorder treatment records carry their own rules under 42 CFR Part 2. Operational data from employers, insurers and wellness apps can contain health facts without being PHI; see special category data in training datasets.

How SourceX handles health data for buyers

SourceX sources operational datasets from US companies on request and manages the licensing process; it does not hold inventory, and a request does not guarantee a match. Every dataset is rights-reviewed for ownership and consents and delivered under a license that defines records, uses, term and delivery. Health records require HIPAA de-identification by Safe Harbor or Expert Determination, and other personal details are removed or replaced before delivery, with the method recorded and a sample checked; no method is perfect. Buyers can describe the data they need through the SourceX buyer request page.

For background, read HIPAA and AI training data and the supplier-side question can I license data if I am HIPAA-covered?. The privacy and de-identification hub and data license vs data use agreement cover adjacent decisions.

Licensing de-identified health data for AI training

If your team needs health operational data for training, fine-tuning or evaluation, SourceX looks for US businesses that hold it and assesses data and licensing permissions before anything is agreed. Nothing is contracted until a supplier agrees, and delivery runs through private, access-controlled workflows after an executed agreement. Describe the records you need at sourcex.si/buyers.

Frequently asked questions

Can a business associate use PHI to train an AI model?

Only if the BAA permits it and the covered entity could make that use itself. A more defensible path is a BAA clause allowing de-identification under 164.514, after which the output is no longer PHI and can support training subject to other law [1][2].

Is a limited data set the same as de-identified data?

No. A limited data set removes 16 categories of direct identifiers but remains PHI, so it requires a data use agreement and stays under HIPAA [2][5].

Does a de-identified data license need any HIPAA terms?

HIPAA does not govern de-identified data, but the license should still record the method used, ban re-identification and linkage, and address state health privacy laws [1][6].

Sources

  1. U.S. Department of Health and Human Services, Office for Civil Rights, "Guidance Regarding Methods for De-identification of Protected Health Information in Accordance with the HIPAA Privacy Rule" (2012). https://www.hhs.gov/hipaa/for-professionals/special-topics/de-identification
  2. Electronic Code of Federal Regulations (eCFR), "45 CFR 164.514 - Other requirements relating to uses and disclosures of protected health information". https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.514
  3. Tonic.ai, "HIPAA and AI compliance". https://www.tonic.ai/guides/hipaa-ai-compliance
  4. Accountable, "HIPAA and Machine Learning: What You Need to Know to Build Compliant Healthcare AI". https://www.accountablehq.com/post/hipaa-and-machine-learning-what-you-need-to-know-to-build-compliant-healthcare-ai
  5. HealthExec, "Healthcare AI and HIPAA compliance: 5 key legal questions + answers". https://healthexec.com/topics/artificial-intelligence/healthcare-ai-and-hipaa-compliance-5-key-legal-questions-answers
  6. Washington State Legislature, "Chapter 19.373 RCW - Washington My Health My Data Act". https://app.leg.wa.gov/RCW/default.aspx?cite=19.373&full=true

Tell us what your models need

Share scope, volume, language, format, timing and licensing requirements.

Request data