Industries
Can a dental practice sell its data to AI companies?
On this page
- Which of a practice’s records are patient information?
- Is my practice covered by HIPAA?
- Can patient records be licensed if the names are taken out?
- Which buyers say they want dental or patient data?
- What are the practice’s own records, and where does patient information hide in them?
- What could a dental practice’s records be worth?
- How does a dental practice owner start?
Usually not for patient records. A practice that sends claims to dental plans electronically is a HIPAA covered entity, so selling patient records needs each patient’s authorization or HIPAA de-identification first. The practice’s own operating records are a separate question.
Which of a practice’s records are patient information?
Nearly everything in the practice-management and imaging systems, and more of the rest than most owners expect. HHS defines the protected information as individually identifiable information about a person’s health, the care given, or “the past, present, or future payment for the provision of health care to the individual”. The ledger and the claims are covered as fully as the chart.
| Record | Usually lives in | Patient information? |
|---|---|---|
| Appointments, recall and reminders | Dentrix, Eaglesoft, Open Dental or similar; reminder services | Yes |
| Charts, clinical notes, periodontal charting | The practice-management system | Yes |
| Radiographs, intraoral scans and photos | Imaging software | Yes |
| Treatment plans, accepted and declined | The practice-management system | Yes |
| Claims, pre-authorizations and EOBs | The practice-management system, the clearinghouse | Yes: payment for care |
| Patient ledgers, statements and payment plans | The practice-management system | Yes: payment for care |
| Lab prescriptions and lab invoices | Paper, email, lab portals | Usually; Florida requires the “patient’s name or number” on each prescription |
| The practice’s books | QuickBooks or similar | The practice’s own, but deposits and refunds can name patients |
| Payroll, HR and staff schedules | Payroll service, shared drive | Employees’ personal data |
| Supply orders, equipment service, sterilization logs | Distributor portals, binders | The practice’s own |
| Office manual, phone scripts, insurance-verification steps | Shared drive | The practice’s own, if written without patient examples |
| Practice email and texts | Microsoft 365, Google Workspace, texting tools | Mixed |
The top six rows are the clinical and financial story of each patient: what was found, what was proposed, what the patient accepted, what the plan paid. They are also what healthcare buyers name. The rows below them are mostly the practice’s own, and a much thinner record.
Is my practice covered by HIPAA?
If it sends claims to dental plans electronically, yes. HHS lists dentists among providers who are covered entities “only if they transmit any information in an electronic form in connection with a transaction for which HHS has adopted a standard” (content last reviewed August 21, 2024), and HHS has adopted one for “Health Care Claim: Dental (837)”.
A practice that conducts none of these standard transactions electronically, such as a paper-only or cash-only office, may sit outside HIPAA, but not outside other rules:
- State law. Texas, for one, defines a covered entity to include anyone who “comes into possession of protected health information”, and bars disclosing it “in exchange for direct or indirect remuneration” except to other covered entities for treatment, payment, health care operations or certain insurance functions, or as law authorizes (§181.153).
- Professional ethics. The ADA Code says “Dentists are obliged to safeguard the confidentiality of patient records” (Section 1.B, in the edition revised to October 2025).
- Your state dental board’s rules on keeping and releasing records.
Can patient records be licensed if the names are taken out?
Only if what is left meets HIPAA’s de-identification standard, and a dental chart loses much of its value on the way. Identifiable records cannot be sold without each patient’s authorization: a covered entity “may not sell protected health information” otherwise, and the authorization “must state that the disclosure will result in remuneration to the covered entity”. Properly de-identified data is different: “There are no restrictions on the use or disclosure of de-identified health information”.
The rule allows two methods, which HHS’s de-identification guidance explains (as of October 2026):
- Safe Harbor. Remove 18 kinds of identifiers and have no actual knowledge that what remains could identify someone. The list includes “All elements of dates (except year)” directly related to the patient, geographic units smaller than a state, and “Full-face photographs and any comparable images”.
- Expert Determination. A qualified expert finds the risk of identification very small. HHS says “There is no explicit numerical level of identification risk” that always meets that bar.
Two of those identifiers matter most in dentistry. Much of a chart’s value is its dated sequence of exams, radiographs, treatment and recall, and Safe Harbor keeps only the year. Frontal smile photos taken for orthodontic and cosmetic cases show the patient’s face.
HHS also says a covered entity may use a business associate to de-identify on its behalf “only to the extent such activity is authorized by their business associate agreement”, and that agreement must bar the associate from using the information “other than as permitted or required by the BAA or as required by law” (reviewed July 30, 2026). So if a provider offers to de-identify your charts for you, ask about a business associate agreement before anything moves; your existing vendors’ agreements also govern what they may do with the data they host for you. Which method, who performs it and what your state adds are questions for a healthcare lawyer.
Which buyers say they want dental or patient data?
None names dental practices, dentistry or a dental system such as Dentrix, Eaglesoft or Open Dental (checked October 2026). As of October 2026, 13 providers name healthcare, clinics or patient records. Five name patient or clinical records, or clinics, which is the part of a practice that HIPAA governs:
| Provider | Type | What its pages say |
|---|---|---|
| FileYield | Listing marketplace | “Medical & Clinical Data” among its most valuable data types: “EHR records, medical imaging (DICOM), clinical trial data, discharge summaries” |
| LH2 AI Labs | Licenses directly | “De-identified patient records, clinical history intact”; it says it removes “PII and PHI before data leaves the source institution” |
| License My Data | Introducer | Clinical records from “hospital and clinic groups, telehealth platforms, EHR vendors, scribe services and CROs”; “Consent must be documented, not asserted” |
| Mercor | Licenses directly | Healthcare among eight industries, with “Clinical notes, claims, intake forms” |
| Troveo | Licensing agent | Healthcare, clinics and revenue-cycle management among business types in its assessment |
License My Data also says the standard for US records is “Expert determination under HIPAA”, and LH2 says hospitals, enterprises and factories are who licenses to it.
The other eight name healthcare or healthcare administration among the businesses they work with, without naming patient records: Avelence, Corpus, micro1, Miro Advisory, Polyshares, Scale AI, Sell My Business Data and Telegraph Lab (affiliated). Two say where they draw the line. Miro Advisory says “Healthcare and other regulated industries can qualify, but require substantially greater privacy, consent and regulatory review”, and Corpus asks sellers to keep out “Patient health records or anything covered by HIPAA”. For the practice’s own records, the providers whose categories cover email, documents and accounting are the ones to compare on the buyers page.
What are the practice’s own records, and where does patient information hide in them?
The records of running the office: the books, payroll and staff scheduling, supply ordering, equipment service and sterilization logs, the office manual and phone scripts, and practice email. Patient information turns up in them in predictable places:
- The books. Deposits, refunds and write-offs can carry patient names in the name and memo fields.
- Lab work. Prescriptions carry the patient’s name or number, as the Florida rule above shows; check lab invoices for the same.
- Email and texts. Front-desk threads with patients, insurance correspondence and referral letters sit beside vendor and staff mail.
- Staff files. Employees’ personal data, which some providers exclude: Corpus asks sellers to keep out “Employee HR files, compensation and performance records”.
Contracts can limit the rest. Read your participation agreements with dental plans for confidentiality terms on fee schedules, and, if a dental service organization runs your back office, its management services agreement for who controls the records. Leaving out records covers cutting mailboxes, senders and folders.
What could a dental practice’s records be worth?
No provider publishes a figure for a dental practice. Of the five that name patient records, only FileYield prices them: its listing guide puts medical and clinical data at $10 to $1,000+ per record (FileYield, as of October 2026), a marketplace guide rather than an offer, and one that does not change the HIPAA rules above. Mercor publishes no range, and LH2 does not say how much owners are paid.
A scope limited to the practice’s own records is narrower than the company-wide records most published ranges assume, and a single-office practice may fall below several providers’ published size floors. The general ranges are on how much is my company’s data worth?
How does a dental practice owner start?
By drawing the line between patient systems and practice systems, and counting only the practice side until a healthcare lawyer has looked at the rest.
- Split the systems. Patient side: the practice-management system, imaging, the clearinghouse, reminder and texting services, lab portals. Practice side: QuickBooks, payroll, staff email, the shared drive, supply accounts.
- Take patient data to a lawyer first. The questions are authorization, which de-identification method, the business associate agreement, and your state’s law.
- Find patient information on the practice side. Shared front-desk mailboxes, memo fields in the books, lab invoices.
- Count the practice side. The free sample tool recognizes QuickBooks transaction exports and replaces the customer and vendor names in them with labels; check memo text for names it missed. It also reads mail as .mbox or .eml. Record the totals in an inventory.
- Apply with patient records out. The application needs no files; say that patient records are out of scope.
Which systems hold this industry's records?
Providers named on this page
Get offers
Find the next step for your company’s data.
- No records or exports needed to apply
- Free for businesses
- Your company profile comes to our team for review