Oktopeak
Healthcare October 2, 2026 · 9 min read

Is Claude HIPAA Compliant? Plan by Plan, With What Anthropic's BAA Leaves Out

Claude can be used with PHI on two surfaces: Claude Enterprise with HIPAA turned on by the Primary Owner, and the first-party API in a HIPAA-ready organization. Free, Pro, Max and Team are not HIPAA-ready plans. Cowork, the Console and several beta features are excluded, and Claude Code is covered only with zero data retention. Plan by plan, checked against Anthropic's BAA article on 2 October 2026.

By Petar Jovanović · Co-Founder & Technical Lead
Is Claude HIPAA Compliant? Plan by Plan, With What Anthropic's BAA Leaves Out

[ KEY TAKEAWAYS ]

Claude can handle patient data on two surfaces: Claude Enterprise, once the organization's Primary Owner turns on HIPAA and accepts Anthropic's Business Associate Agreement, and the first-party API in a HIPAA-ready organization. Free, Pro and Max are consumer plans, and Team isn't one of the HIPAA-ready services Anthropic names. Even on a covered plan, Cowork, the Console and several beta features sit outside the BAA, and Claude Code is covered only with zero data retention.

Last checked: 2 October 2026, against Anthropic's BAA article for commercial customers, its ZDR scope article, the Covered Models page and its commercial retention and training articles. Anthropic changes this table often, so check the date on its article before you rely on ours. Not legal advice.

2

surfaces Anthropic's BAA covers: Claude Enterprise and the first-party API.

4

plans that can't hold PHI: Free, Pro, Max and Team.

30 days

minimum retention on Covered Models, so no ZDR with them.

0

Cowork features covered by the BAA. Keep PHI out of it.

We connect Claude to EHRs and practice systems for healthcare teams, so we read Anthropic's BAA page closely and often. Its table now covers dozens of features across three products, and the BAA versions it references are dated December 2025 and April 2026, so older write-ups miss rows. This one maps the current table to the questions a practice owner actually asks.

Which Claude plans does Anthropic's BAA cover?

Anthropic's BAA article says it "provides a BAA covering our HIPAA-ready services, such as use of our first-party API or Enterprise plans." For Enterprise, the Primary Owner turns on HIPAA compliance under "Data and privacy" in organization settings and accepts the BAA there. The article adds: "Standard Claude Enterprise plans do not include BAA coverage without action from a Primary Owner." For the API, the Primary Owner signs the BAA and then asks the Anthropic account team or sales to switch the organization on.

Claude plan or surface Under Anthropic's BAA? What that means for a practice
Free, Pro, Max No Consumer plans. No BAA. Pasting a patient's note into one is a disclosure to a vendor with no BAA.
Team No Commercial terms and no training on your data by default, but not a HIPAA-ready service in Anthropic's list. Fine for work with no PHI.
Enterprise, HIPAA not activated Not yet Same software, no BAA until the Primary Owner turns HIPAA on and accepts it.
Enterprise, HIPAA activated Yes, for listed features Chat, projects, artifacts, file creation and code execution (without network access), voice, web search, research and skills are covered.
First-party API, HIPAA-ready org Yes, for listed features The Messages API is covered, with prompt caching, structured outputs, memory, web search, the bash tool and the text editor tool. Batch, Files, Skills, Code Execution, Computer Use and Web Fetch aren't, and HIPAA-ready orgs can't reach them.
Claude through AWS, Google or Microsoft That cloud's BAA You sign with the cloud, not with Anthropic. Amazon Bedrock is on AWS's HIPAA eligible services list. Check the other clouds' lists the same way before you assume coverage.

The BAA covers only the organization that accepted it. If a clinic runs two Claude organizations, one for admin staff and one for clinicians, each one needs its own HIPAA activation.

What the BAA leaves out, even on Enterprise

This is the part most practices miss. A covered Enterprise organization still offers features that aren't covered, and Anthropic leaves it to administrators to decide whether staff can turn them on. Its article sorts them into three groups.

Excluded outright

Cowork, Console, beta features

The BAA "excludes features such as Claude Console, Claude Cowork, or features currently in beta such as Claude in Office, Claude Design, Claude Slides, and Claude Docs." Design, Slides and Docs aren't available to HIPAA-ready organizations at all yet. Claude for Microsoft 365 has some beta features that aren't covered.

Third-party data flows

Connectors, MCP, Enterprise Search, Claude in Chrome

You can use them, but "sending data to 3rd parties via this feature isn't covered under Anthropic's BAA." Whatever system sits on the other end of a connector needs its own BAA with you.

Covered only with ZDR

Claude Code

The CLI and the desktop app's local mode are covered only with zero data retention, which Anthropic grants to qualified accounts. Remote mode, Claude Code on the web, Code Review, Code Security, Computer Use and Remote Control aren't covered.

The Cowork exclusion matters because Cowork is the feature most office managers want to switch on first: it works with files and runs tasks across apps. In a HIPAA-ready organization it's available and not covered, so either it stays off or PHI stays out of it. We wrote up what Cowork can and can't reach in our note on Cowork and local connectors.

How zero data retention changes the answer

Zero data retention is a separate arrangement from the BAA, and the two interact in a way that surprises people. Per Anthropic's ZDR article, ZDR applies only to eligible APIs, products that use your commercial API key (Claude Code through the API included) and Claude Code on Enterprise plans. It's approved per organization. It doesn't apply to chats in the Claude app, and Anthropic still keeps User Safety classifier results to enforce its Usage Policy.

Then there are Covered Models. Anthropic designated Claude Fable 5 and Mythos 5 on 9 June 2026, and Fable 5.1 and Mythos 5.1 on 31 August 2026. These models keep prompts and outputs for at least 30 days, so ZDR isn't available wherever they run. The BAA article spells out the consequence: "Some services, like Claude Code, are only covered under the BAA when ZDR is enabled, which means those services can't use Covered Models under the BAA."

What that means in practice

A developer on your team using Claude Code on a repository with real patient data has to be on a ZDR-enabled account and on a model that isn't a Covered Model. Anthropic has said a temporary ZDR option for Fable 5 and 5.1 is coming for eligible customers, ahead of a program it calls Enterprise Frontier Safeguards. Until your organization is told it qualifies, plan as if it doesn't.

One more thing ZDR doesn't mean: that nothing leaves the practice. Prompts still travel to Anthropic or to your cloud provider and get processed there. What you can defend in front of an auditor is a signed BAA, training off (Anthropic doesn't train on commercial data by default), the shortest retention your plan allows, and a log of who sent what. Our guide to ZDR on Team versus the API goes deeper on retention.

Want Claude in the practice without guessing?

We set up HIPAA-ready Claude for healthcare teams: the right plan, permissions, which features stay off, connectors to your EHR under BAAs, and a log of what was sent.

Talk to a founder

What a practice still has to set up

The BAA covers Anthropic's side. Everything around it stays with you, and this is the list we work through with a practice before real patient data goes in.

Plan and activation

A HIPAA-ready Enterprise organization with HIPAA turned on by the Primary Owner, or an API organization switched on by Anthropic after the BAA is signed. Record the date and the BAA version you accepted.

Features that stay off

Cowork, beta features, and any connector or MCP server whose other end has no BAA with you. Claude Code only on ZDR accounts for anyone near PHI.

Who can see what

SSO and seats limited to staff who need it, projects split by team so front desk and clinicians don't share a knowledge base, and minimum necessary data in every prompt.

Where the records live

Claude reads from your EHR or document system through a connector you control, scoped to the records a task needs, instead of staff uploading chart exports into chats.

Audit trail

Enterprise offers audit logs and a Compliance API for admins. Add your own log of what each connector read and wrote, kept somewhere staff can't edit.

Human review

Anything that goes into a chart, a claim or a message to a patient is reviewed by a person first. Your policies and training say so in writing.

Where Claude for Healthcare fits

Anthropic announced Claude for Healthcare on 11 January 2026, describing it as tools for providers, payers and health tech companies to use Claude "through HIPAA-ready products." It added connectors to the CMS Coverage Database, ICD-10 and the National Provider Identifier Registry, plus Agent Skills for FHIR development and prior authorization review. Those are reference data sources, and they don't contain your patients. The question this page answers still applies to everything else: your notes, your EHR and your intake forms go through a covered plan or they don't go through Claude.

If you're building a product rather than running a practice, the same rules apply one level down. Your app's calls to Claude need a HIPAA-ready API organization, and the rest of your stack needs its own BAAs. We covered that for the most common AI-built stack in is Supabase HIPAA compliant.

Frequently Asked Questions

Is Claude HIPAA compliant?

Claude can be used with protected health information on Anthropic's HIPAA-ready services under a signed Business Associate Agreement: Claude Enterprise with HIPAA activated by the organization's Primary Owner, and the first-party API in a HIPAA-ready organization. Free, Pro and Max are consumer plans, and Team is not named as a HIPAA-ready service, so they should not hold PHI. Even on a covered plan, some features are excluded from the BAA, and the practice is still responsible for its own policies, access and other vendors.

Can I use Claude Team with patient data?

No. Anthropic's BAA article names the first-party API and Enterprise plans as its HIPAA-ready services. Team isn't on that list. A practice that wants a shared Claude workspace for PHI needs a HIPAA-ready Enterprise organization, or a workflow built on the API under the BAA.

Is Claude Cowork covered by Anthropic's BAA?

No. Anthropic's BAA article lists Cowork as available to use but not covered under the BAA, and makes administrators who enable it responsible for how their workforce uses it. Keep PHI out of Cowork.

Is Claude Code HIPAA compliant?

Claude Code in the CLI and in the desktop app's local mode is covered by Anthropic's BAA only when zero data retention is enabled, and ZDR is available for qualified accounts. Without ZDR it can be used but isn't covered. Remote mode, Claude Code on the web, Code Review, Code Security, Computer Use and Remote Control aren't covered at all.

Are Claude connectors and MCP servers covered by the BAA?

The connector feature can be used in a HIPAA-ready organization, but data sent to third parties through connectors, MCP servers, Enterprise Search and Claude in Chrome isn't covered by Anthropic's BAA. Each system on the other end of a connector needs its own BAA with the practice, and the connector should be configured so it only reaches what it needs.

Does zero data retention mean nothing is stored?

Not quite. Anthropic says that under ZDR arrangements it still keeps User Safety classifier results to enforce its Usage Policy, and ZDR applies only to eligible APIs, products using a commercial API key, and Claude Code for Enterprise. Covered Models, which include Claude Fable 5 and 5.1, require at least 30 days of retention and can't run with ZDR.

Next step

If you want Claude connected to your EHR or practice system under the right BAAs, that's our healthcare AI integration work. If the plan, permissions and staff training are the open question, start with healthcare AI implementation.

NEWSLETTER

No spam. We use this list for product and connector upgrade announcements, new research findings, and not much else. Unsubscribe anytime.

Petar Jovanović

[ WRITTEN BY ]

Petar Jovanović

Co-Founder & Technical Lead

Co-Founder and Technical Lead at Oktopeak. Builds regulated software for legal and healthcare teams, and leads the rescues of codebases other vendors left half-finished.

[ HEALTHCARE ]

Related Articles

HEALTHCARE

Jun 14, 2026 · 12 min read

HIPAA Compliant AI: What Actually Makes ChatGPT or Claude Safe for PHI | Oktopeak

"HIPAA compliant AI" is not a product you buy. It is an architecture and a process. The model is rarely the variable. The surface, the BAA, retention, access controls, the audit trail, and human review are. Here is a vendor-agnostic breakdown of what actually makes an AI workflow HIPAA-compliant, and a checklist to run before any PHI touches a model.

Read Article

HEALTHCARE

Oct 2, 2026 · 10 min read

Is Supabase HIPAA Compliant? BAA Plans, Vercel and Lovable Apps (2026) | Oktopeak

Supabase signs a BAA on the Team plan and up, with its paid HIPAA add-on, and only for projects you configure as high compliance. Free, Pro and self-hosted Supabase get no BAA. Here is what the BAA requires, what Vercel and Lovable add to the picture, and how to put PHI behind a backend that is covered. Checked against vendor docs on 2 October 2026.

Read Article

[ GET STARTED ]

Ready to build?

30-minute call. No pitch deck. Just an honest conversation about your project.

Check if we're a fit