Skip to content

Training data for healthcare administration AI

Healthcare administration AI, such as prior authorization, coding, claims, denial management and patient access agents, learns from de-identified records of real administrative work: authorization requests and determinations, claims linked to remittances, denials and appeals with outcomes, payer and patient calls, and the payer-specific playbooks staff follow. SourceX sources these from established healthcare organizations, and records are de-identified before delivery, following methods such as HIPAA Safe Harbor or Expert Determination where applicable.

  1. Healthcare revenue cycle and prior authorization records

    The decision record an admin agent learns from: prior authorization requests and determinations, coded claims linked to their remittances, and denials with the appeals that followed. Reason codes and appeal results show what a payer rejected and what got a denial overturned.

  2. Insurance claims workflows

    Claim files show the payer's side of a decision: coverage checks, adjuster notes, documentation requests and pay-or-deny reasons. Injury claims in workers' compensation and auto lines also carry medical bills reviewed for coverage and payment.

  3. Contact center call recordings and transcripts

    Patient access and billing calls, and staff calls to payer phone lines, teach voice and chat agents how identity is verified, what payers ask for, and when a call ends with a reference number or a callback.

  4. SOPs, playbooks and internal knowledge bases

    Payer-specific playbooks, work-queue procedures and appeal templates hold rules that public payer policies leave out, such as which attachments a given plan expects. Paired with transaction records, they show whether following the procedure led to payment.

Why this data is hard to get

The records are full of protected health information

Authorization requests, claims and patient calls carry diagnoses, procedures, member IDs and dates of service. Freely downloadable claims data is mostly synthetic or aggregated, and it lacks the authorization correspondence, denial letters and appeal arguments that admin work runs on.

One encounter spans many systems

The eligibility check, authorization, claim, remittance, denial and appeal for one encounter can sit in a practice management system, a clearinghouse, payer portals and fax queues, months apart. They form one training example only if an identifier links them through de-identification.

Safe Harbor removes the timing signal

Safe Harbor keeps only the year of dates tied to a patient, which removes the day-level timing behind turnaround times, filing windows and appeal deadlines. Keeping that detail generally points to Expert Determination, which is assessed for the specific dataset and the recipient who will hold it.

Payer rules are fragmented and keep changing

Each payer and plan sets its own authorization lists, documentation requirements and filing limits, and revises them. Published policies state criteria but not how reviewers apply them, so models need dated decisions as well as the rulebook.

Healthcare administration AI is several jobs, each with its own data

Healthcare administration AI covers several distinct jobs, and each one needs a different slice of the administrative record:

  • Eligibility and benefits: eligibility inquiries and responses (X12 270/271), payer portal lookups and calls to payer phone lines.
  • Prior authorization: requests (X12 278, portal or fax), the clinical documentation sent with them, and approvals, denials or requests for more information.
  • Coding and claims: encounter documentation, coded claims (X12 837) and the edits raised before submission.
  • Denial management: remittances (X12 835) with CARC and RARC codes, denial letters, appeals and what was paid afterwards.
  • Patient access: scheduling, coverage and billing calls and messages.

The most valuable records link these steps for the same encounter, because the label for a coding or authorization decision often arrives weeks later, on the remittance or in the appeal result.

De-identification choices decide what a model can learn

The de-identification method sets a ceiling on what a healthcare administration dataset can teach. Under the HIPAA Privacy Rule, data can be de-identified by Safe Harbor, which removes listed identifiers outright, or by Expert Determination, in which a qualified expert assesses and documents re-identification risk for a specific dataset and recipient (HHS guidance). Safe Harbor is simpler to apply but strips day-level dates, collapses ages over 89 into one category and removes most geography below the state level. Expert Determination can preserve more structure, at the cost of an expert analysis and conditions on how the data is used.

Free text is where identifiers hide: relatives' names in notes, employers in injury claims, dates written out in appeal letters. Residual checks on narrative text and scanned attachments deserve the most attention on the sample.

A covered entity can have a business associate de-identify data on its behalf only where their business associate agreement authorizes it, so who de-identifies, by which method and under which agreement is settled during scoping. Some sources are not covered entities at all: HHS notes that the Privacy Rule does not apply to workers' compensation insurers, administrative agencies or employers, except where they are covered entities in another capacity (HHS). Their injury claim files fall under insurance and state privacy rules instead, but hold the same medical detail.

Licensing questions specific to healthcare administration

Healthcare administration data raises licensing questions that most other domains do not:

  • Who controls the data. Billing companies and outsourced revenue cycle teams process records for provider clients, who usually have to approve any licensing.
  • Which payment details travel. Contracted rates can be confidential, so paid amounts may be kept, banded or removed.
  • Code descriptors. CPT is copyrighted by the American Medical Association, so whether descriptor text is included, or you map codes under your own license, is agreed in scope.
  • Specially protected records. Substance use disorder treatment records covered by 42 CFR Part 2, and categories some state laws protect more strictly, carry their own rules.

Ask only for the fields each task needs. Narrow scope keeps de-identification simpler and follows the same logic as HIPAA's minimum necessary standard.

What good data looks like

  • Transactions linked by a pseudonymous encounter or claim ID across eligibility, authorization, claim, remittance, denial and appeal.
  • Determinations and denials with standard reason codes, such as CARC and RARC codes on remittances, plus the result of any appeal.
  • Diagnosis and procedure codes (ICD-10, CPT, HCPCS and modifiers) kept with the service year, because the code sets are revised at least once a year.
  • The de-identification method named for each source, with any conditions of an Expert Determination, such as no linkage to other data, written into the license.
  • Payer type kept at an agreed level of detail, such as commercial, Medicare Advantage or Medicaid managed care, because rules differ by payer.
  • Free-text letters and attachments scrubbed and checked for residual identifiers on the sample, or excluded.

Questions buyers ask

Can I license real prior authorization and claims data for AI training?

Yes, when the organization holding the records agrees and the data is de-identified before delivery. Provider groups and billing companies hold authorization, claim and appeal histories, but a billing company usually needs its provider clients' authorization to license their data, which SourceX confirms during rights review. Whether a match exists depends on which organizations hold suitable records and are willing to license them.

What is the difference between Safe Harbor and Expert Determination?

They are the two de-identification methods in the HIPAA Privacy Rule. Safe Harbor removes 18 listed types of identifiers, including names, most geography smaller than a state, every element of patient-related dates except the year, and full-face photos, and the data holder must have no actual knowledge that the rest could identify someone. Expert Determination relies on a qualified expert who finds the re-identification risk very small for the anticipated recipient and documents the analysis.

Is de-identified healthcare data still covered by HIPAA?

Not by the Privacy Rule: HHS guidance says health information de-identified under Safe Harbor or Expert Determination is no longer protected health information. Other obligations can still apply, including state privacy laws, contracts with payers or provider clients, and the license itself, which can prohibit re-identification and linkage with other data.

Can de-identified claims keep dates of service?

Under Safe Harbor, only the year can remain for dates tied to a patient, such as dates of service, admission or birth. If your model needs turnaround times or deadlines, ask about Expert Determination, under which intervals can sometimes be kept, for example by shifting all dates in a record by the same offset, if the expert finds the risk very small.

Do healthcare call recordings contain protected health information?

Usually, yes. Callers and staff say names, dates of birth, member IDs and symptoms aloud, and the Safe Harbor identifier list includes voice prints. Calls are therefore often delivered as de-identified transcripts, while audio needs a separate assessment, such as an Expert Determination, decided case by case.

Tell us what you are building

Describe the model or agent, the tasks it must handle, and the volume, format and permitted use you need. SourceX will match it to partner data.

Updated 3 October 2026.

See if you qualify