Published August 25, 2026· 8 min read
Is Claude HIPAA compliant? Enterprise, API, and feature coverage explained

Claude can support HIPAA-regulated work, but not through every Claude account or feature. Anthropic provides a Business Associate Agreement for specified HIPAA-ready Enterprise and first-party API services. The organization must activate the appropriate setting, accept the BAA, follow configuration requirements, and verify that each feature in the workflow is covered.
Claude Free, Pro, and Max should not be treated as approved places for PHI. A standard Enterprise subscription is not enough either: Anthropic states that the organization’s Primary Owner must activate HIPAA compliance in a HIPAA-ready organization and accept the BAA.
Which Claude products can be covered?
Anthropic’s currentcommercial BAA documentationdescribes two primary routes: a HIPAA-ready Claude Enterprise organization and a HIPAA-ready first-party API organization. Coverage is attached to the organization and eligible services, not to the Claude model name in the abstract.
- Claude consumer plans: not covered by Anthropic’s commercial BAA.
- Claude Enterprise: eligible features can be covered after the Primary Owner activates HIPAA compliance and accepts the BAA.
- Anthropic first-party API: eligible API services can be covered after the organization signs a BAA and Anthropic enables the HIPAA-ready configuration.
- Third-party platforms: coverage depends on the contract and configuration with that platform, not automatically on Anthropic’s direct BAA.
Feature-level scope matters
Anthropic publishes a detailed coverage table because not every feature is treated the same. Core Enterprise features such as chat, projects, artifacts, voice, web search, research, and skills may be eligible under current BAA terms. Data sent to third parties through connectors, MCPs, or enterprise search is not automatically covered by Anthropic’s agreement.
The API has its own boundaries. Anthropic lists eligible services within the Messages API and excludes other surfaces such as certain beta APIs and computer-use features. Claude Code has separate zero-data-retention requirements and exclusions. A procurement review should use the live coverage table and the implementation guide referenced in the executed BAA.
Why the BAA does not settle the entire question
A BAA establishes permitted uses, safeguards, incident duties, subcontractor obligations, and other responsibilities. HHS guidance also requires the regulated organization to understand its cloud environment, conduct a risk analysis, and establish risk-management policies.
The organization still has to decide which users may access Claude, which PHI workflows are allowed, how outputs are reviewed, what retention is acceptable, and which integrations must remain disabled. Enabling a HIPAA-ready setting is a prerequisite, not a substitute for those operating decisions.
A practical Claude HIPAA review
- Identify whether the account is consumer, Enterprise, API, or supplied through another cloud platform.
- Confirm that the correct organization has accepted a current Anthropic BAA.
- Record the exact model, product surface, and features the workflow will use.
- Check each feature against Anthropic’s current eligible-services table.
- Map any connector, MCP, external site, storage service, or downstream application separately.
- Configure identities, sharing, retention, logging, and offboarding.
- Test the workflow with nonproduction cases and require human review of clinical outputs.
Can a clinician use Claude Pro after removing a patient name?
Removing a name alone does not reliably remove PHI. Dates, locations, contact details, record numbers, and distinctive combinations of facts can identify a patient. If the organization has not approved the account and workflow, the safer decision is not to paste clinical information into a consumer account.
Proper de-identification can change whether information is PHI, but it has formal standards and residual risks. A clinician should follow the practice’s approved process rather than improvise redaction during a busy clinic day.
The bottom line
Claude is not universally HIPAA compliant. Specific Enterprise and first-party API services can be used under Anthropic’s BAA when the HIPAA-ready environment is activated and all feature, configuration, and organizational requirements are satisfied. Consumer accounts and uncovered features are not made safe for PHI simply because they use the same Claude models.
Review the exact service and data journey before approving a workflow. If a small practice prefers a healthcare-specific workspace, our security ledger andprivacy journey show the equivalent questions to ask about PHI handling, model access, retention, and the applicable agreement.
