If the former, I wonder if some statistical analysis could be done in order to detect possible fraud, waste, and abuse. (I'm not a data geek or anything, but have I always wanted to learn.)
Just to clarify...you have some data with patient identifiers already "removed"...or are you stripping it yourselves before sharing?
If the latter (which I hope is not true), how would a third-party like you obtain identifiable data? Why would a third-party providing an eligibility API end up storing data (particularly claim data) of any kind to offer to share?
Please provide your backup, retention, deletion, access logging, etc., policies on that data you are manipulating.
Am I understanding that an audit two months from now (you log your access and use of this data as required by HIPAA, right?) will indicate that this data was "stripped" and shared?
I would be very very cautious about thinking that "stripping" data like this isn't very prone to error, and to not realizing that storing and sharing this kind of data without a lot of care and thought could create huge problems.