Yes, with conditions. Anthropic signs a BAA covering Claude Enterprise (HIPAA-ready), the first-party API, and Claude Code with zero data retention enabled. Consumer Claude (Free, Pro, Max), Claude Team, and Claude Cowork are not covered and must never touch PHI.
No AI tool is "HIPAA compliant" as a blanket statement — compliance describes how a covered entity deploys a tool, not the tool itself. What a vendor can offer is a business associate agreement (BAA) and configurations that make compliant use possible. Anthropic offers both, with sharper product boundaries than most buyers expect. Statuses change: re-check Anthropic's official BAA article before you rely on anything here. Last verified: September 5, 2026. This post is the sibling of Is ChatGPT HIPAA Compliant? in the same series.
Which Claude products does Anthropic's BAA cover?
Anthropic publishes the answer in its Privacy Center article on Business Associate Agreements for commercial customers — itself unusual; most AI vendors make you ask sales. Three product lines are eligible:
- Claude Enterprise (HIPAA-ready orgs): Chat, Projects, Artifacts, file creation and code execution, Voice, Web Search, Research, and Skills are the eligible features.
- First-party API: the Messages API — including prompt caching, structured outputs, memory, web search, and the bash and text editor tools — plus the Token Counting, Models, Org Management, and Compliance APIs.
- Claude Code: covered only "with ZDR enabled," and only for specific deployment methods (CLI via the first-party API console, CLI via Enterprise OAuth, desktop local mode).
Just as explicitly, the same article says the BAA "excludes features such as Claude Console, Claude Cowork, or features currently in beta such as Claude in Office and Claude Design." Third-party integrations — MCP servers, Enterprise Search, Claude in Chrome — are "available to use but sending data to 3rd parties via this feature isn't covered under Anthropic's BAA."
| Product / surface | BAA available? | Conditions |
|---|---|---|
| Claude Free / Pro / Max | No | Never enter PHI |
| Claude Team | No | Never enter PHI |
| Claude Enterprise (HIPAA-ready) | Yes | Primary Owner accepts the BAA; one-way activation; covered features only |
| First-party API | Yes | BAA via sales; Covered Models require 30-day retention and are not available with ZDR |
| Claude Code | Yes | Only with ZDR enabled, on approved deployment methods |
| Claude Cowork | No | "Not yet covered under Anthropic's BAA" |
| Claude Console, Claude in Office, Claude Design | No | Explicitly excluded or in beta |
| Third-party MCP connectors, Claude in Chrome | No | Usable, but data sent to third parties sits outside the BAA |
How do you activate HIPAA coverage — and why is it one-way?
For Claude Enterprise, Anthropic's help center is specific: the organization's Primary Owner "must activate HIPAA compliance in the HIPAA-ready Claude Enterprise organization settings" and accept the BAA — "Other Owners or Admins can't complete this flow on the org's behalf." The flow sits under Organization Settings, then Data and Privacy, then HIPAA Compliance, where you review and download the BAA and the Implementation Guide before accepting. Anthropic's own warning: "This is a one-way decision. Once HIPAA is enabled and the BAA is accepted, the change can't be reversed."
For the API, Primary Owners sign a BAA and then contact their Anthropic representative or the sales team to have it enabled. One legacy note from the help center: organizations with API BAAs signed before December 2, 2025 must sign a new agreement to cover the Enterprise plan.
What is the difference between ZDR and HIPAA-ready?
They are different arrangements, and confusing them causes real misconfigurations. Anthropic states that "Covered Models require 30-day data retention and aren't available with zero data retention (ZDR) enabled" — HIPAA readiness leans on safeguards such as encryption, access controls, and audit logging rather than on immediate deletion. Claude Code is the inverse: "Claude Code is covered under your BAA only with zero data retention (ZDR) enabled." An organization can hold one BAA and still be out of scope on one surface because retention was configured for the other. The Implementation Guide you download at acceptance defines which features are in scope — read it, then map it to your configuration.
Why is Claude Cowork the trap?
Claude Cowork is Anthropic's agentic product: it reads and writes local files, executes code in a sandboxed VM, browses with the user's authenticated sessions, and connects to enterprise systems over MCP. It ships inside the same Enterprise plans that carry the BAA. And Anthropic's help center states plainly: "Cowork is not yet covered under Anthropic's BAA."
That is the trap. A hospital ops team buys HIPAA-ready Enterprise, reasonably assumes the whole bundle is covered, and someone drops a referral spreadsheet into Cowork — an impermissible disclosure inside a "compliant" deployment. Two aggravating details: Anthropic's Compliance API now surfaces Cowork and Claude Code session content for security teams, which is an audit capability, not BAA coverage; and per third-party summaries of Anthropic's own docs, local Cowork session history is stored on users' machines and cannot be centrally managed or exported by admins. For the full picture, see our Claude Cowork and Claude Code enterprise security review.
Can consumer Claude ever touch PHI?
No. There is no BAA for Free, Pro, Max, or Team, so entering PHI there is an impermissible disclosure regardless of in-app privacy settings — a conclusion consistent across third-party HIPAA analyses and grounded in the product scope of Anthropic's own BAA article. BastionGPT's analysis adds that since September 2025, consumer plans carry an opt-in toggle to share conversations for model training — one more reason PHI and personal accounts must never meet. Anthropic aims HIPAA-ready Enterprise at "healthcare providers, health plans, healthcare data processors, and their business associates." Everyone else on your org chart needs guardrails instead, which is a workforce problem, not a contract problem — see the healthcare AI security playbook.
The decision tree: which Claude for PHI?
- Individual account (Free/Pro/Max)? Never PHI.
- Claude Team? No BAA. Never PHI.
- Claude Enterprise? PHI is permitted after the Primary Owner accepts the BAA and enables HIPAA — and only in covered features. Cowork, Console, and beta features stay PHI-free.
- Building on the API? Sign the BAA via sales and use Covered Models with their 30-day retention. Do not assume ZDR and BAA coverage combine — for Covered Models, they don't.
- Claude Code? Covered only with ZDR enabled on approved deployment methods.
What must you still do after signing — and where do Claude DLP gaps remain?
A BAA is necessary, not sufficient. HHS still expects a documented risk analysis covering the Claude deployment (45 CFR 164.308(a)(1)) and the minimum necessary standard applied to what goes into prompts (45 CFR 164.502(b)). Anthropic frames its product the same way: "Features fall into three categories: covered by your BAA, available but not covered, and disabled." Your job is making sure users can tell the categories apart.
The residual gap is behavioral. Nothing in the BAA stops a nurse pasting a full chart into Cowork, or an analyst using personal Claude on a work laptop. Closing it takes prompt-level DLP: classify PHI before it leaves the device, redact rather than block where the workflow allows (why redaction beats blocking), and audit per-feature usage with Anthropic's Compliance API plus your own telemetry. This is what AccuroAI's workforce AI governance layer does across every AI surface — 40+ data classifiers applied inline at under 38ms p99, so covered and uncovered Claude features can carry different policies without slowing clinicians down. For the regulator-side view, see the CMS AI guidance for 2026.
FAQ
Is Claude HIPAA compliant?
Claude can be used in a HIPAA-compliant way on three surfaces — Claude Enterprise with HIPAA activated, the first-party API under a signed BAA, and Claude Code with ZDR — provided the covered entity does its own risk analysis and configuration. Consumer Claude and Claude Cowork are not covered.
Is Claude Cowork HIPAA compliant?
No. Anthropic's help center states "Cowork is not yet covered under Anthropic's BAA," even though Cowork ships inside HIPAA-ready Enterprise plans. Keep PHI out of Cowork — and re-check the official page, because this is the status most likely to change.
Does the Claude API support HIPAA with zero data retention?
Not together. Anthropic states "Covered Models require 30-day data retention and aren't available with zero data retention (ZDR) enabled." Claude Code runs the other way: BAA coverage only with ZDR on.
Can I use Claude Free or Pro for patient data if I anonymize it first?
Only if the data is genuinely de-identified under HIPAA's Safe Harbor or expert-determination standards — casual redaction rarely qualifies. With no BAA on consumer plans, anything short of full de-identification is an impermissible disclosure.
Who can accept Anthropic's BAA?
Only the organization's Primary Owner, per Anthropic — other Owners and Admins cannot complete the flow — and acceptance is irreversible once HIPAA is enabled.
Related reading: Workforce AI Governance · Is ChatGPT HIPAA Compliant? · Claude Cowork and Claude Code: The Enterprise Security Review · The Healthcare AI Security Playbook