Yes, conditionally — but signing Anthropic's BAA does not bring Claude Code under it. Claude Code is covered only with zero data retention (ZDR) enabled, and only on accounts Anthropic calls qualified. Three Claude Code surfaces can be covered that way; six others each carry the line "This feature is incompatible with ZDR", so no admin action reaches them. Getting a team into a covered configuration takes us 6–10 weeks.
| Fact | Value |
|---|---|
| Tool | Claude |
| Verdict | Yes, with conditions |
| Sources checked | August 2026 |
| Typical range | $13,000–$25,000 |
| Typical timeline | 6–10 weeks |
| Last updated | August 2026 |
Which surfaces the BAA actually reaches
"Covered" here means listed as covered in Anthropic's published BAA feature tables, for an organisation that has accepted the BAA. Three cautions before you read the rows. First, coverage of any Claude Code surface additionally requires ZDR, which is not a self-serve toggle: Anthropic says ZDR "is not included in the standard Enterprise plan; it is enabled on a per-organization basis by your account team after confirming eligibility." Second, Anthropic points past its own published tables: it says the Implementation Guide for HIPAA Entities on its Trust Center "lists every feature's status and is the authoritative source," and access to that document must be requested — we could not read it, so this table, like Anthropic's public one, is secondary to a document you have to ask for. Third, Anthropic states that "Your signed BAA is the official source of truth for which features are covered."
Your PHI
Your Claude app
Inside the agreement — PHI may live here
- Chat, Projects, Artifacts, Voice, Web Search, Research, Skills (Claude Enterprise)
- File creation & code execution (Claude Enterprise)
- Messages API (Prompt Caching, Structured Outputs, Memory, Web Search, Bash tool, Text Editor tool)
- Token Counting API, Models API, Org Management API, Compliance API
- Claude Code CLI (via 1P API console)· conditional
- Claude Code CLI (via Claude Enterprise OAuth)· conditional
- Claude Code in the desktop (local mode)· conditional
Outside it — PHI here is a gap
- Claude Code in the desktop (remote mode)
- Claude Code in the web [beta]
- Claude Code Review [beta]
- Claude Code Security [beta]
- Claude Code Computer Use [beta]
- Claude Code Remote Control [beta]
- MCPs / Connectors
- External MCP
- Claude in Chrome
- Enterprise Search / “Ask Your Org”
- Claude Console
- Claude Cowork
- Claude in Office / Claude for Office (Excel, PowerPoint, and Docs (beta))
- Claude Design [beta]
- Batch API, Files API [beta], Skills API [beta], Code Execution, Computer Use [beta], Web Fetch
- Claude Free, Pro and Max — including Claude Code used from those accounts
- Team plans
- Claude Code metrics logging
| Service | Under the BAA | Condition |
|---|---|---|
| Claude Code CLI (via 1P API console) | Conditional | "Only covered under the BAA with ZDR enabled." This is the API credential path, not the Console web interface — the two are easy to confuse and are treated differently. It is coverable only on a ZDR organisation, never on a HIPAA-ready API organisation. |
| Claude Code CLI (via Claude Enterprise OAuth) | Conditional | "Only covered under the BAA with ZDR enabled", with the added restriction "ZDR is available for qualified accounts only." |
| Claude Code in the desktop (local mode) | Conditional | Same condition: ZDR enabled, qualified accounts only. Local mode is the coverable desktop mode. |
| Claude Code in the desktop (remote mode) | Not covered | "This feature is incompatible with ZDR." Since ZDR is the precondition for coverage, remote mode cannot be brought under the BAA by any setting. |
| Claude Code in the web [beta] | Not covered | "Available to use without ZDR but this feature is not covered under Anthropic's BAA. This feature is incompatible with ZDR." |
| Claude Code Review [beta] | Not covered | Same line: incompatible with ZDR, therefore never coverable. |
| Claude Code Security [beta] | Not covered | Same line: incompatible with ZDR, therefore never coverable. |
| Claude Code Computer Use [beta] | Not covered | Same line: incompatible with ZDR, therefore never coverable. |
| Claude Code Remote Control [beta] | Not covered | Same line: incompatible with ZDR, therefore never coverable. |
| MCPs / Connectors | Not covered | "Available to use but sending data to 3rd parties via this feature isn't covered under Anthropic's BAA." Anthropic places the obligation on the administrator who enables them. |
| External MCP | Not covered | Listed with the same third-party carve-out. Any agreement for that leg is between you and whoever runs the server. |
| Claude in Chrome | Not covered | Listed with the same third-party carve-out. |
| Enterprise Search / “Ask Your Org” | Not covered | Listed with the same third-party carve-out. |
| Claude Console | Not covered | Named in the BAA page's exclusion sentence. Anthropic's platform docs are more precise: "enabling HIPAA readiness from Console settings is supported; processing PHI through the Console is not covered." Do not read this row as meaning the API-console CLI path is uncovered — it is a different surface with a different status. |
| Claude Cowork | Not covered | Named in the same exclusion sentence. Anthropic's wording elsewhere is "not yet covered", so read this as current status rather than a permanent position. |
| Claude in Office / Claude for Office (Excel, PowerPoint, and Docs (beta)) | Not covered | Named in the BAA page's exclusion sentence as a beta feature. |
| Claude Design [beta] | Not covered | Named in the BAA page's exclusion sentence as a beta feature. |
| Chat, Projects, Artifacts, Voice, Web Search, Research, Skills (Claude Enterprise) | Covered | Listed as covered Claude Enterprise features, under the footnote "*Covered under versions of the BAA accepted after 12/2/25". |
| File creation & code execution (Claude Enterprise) | Covered | Listed as covered, and scoped in Anthropic's own words: "excluding network access and use of external websites". |
| Messages API (Prompt Caching, Structured Outputs, Memory, Web Search, Bash tool, Text Editor tool) | Covered | Listed as covered under a different footnote — "*Covered under versions of the BAA accepted after 4/1/26". The two footnotes attach to different tables and should not be merged. |
| Token Counting API, Models API, Org Management API, Compliance API | Covered | Listed as covered API features under the 12/2/25 footnote. |
| Batch API, Files API [beta], Skills API [beta], Code Execution, Computer Use [beta], Web Fetch | Not covered | API features listed as outside coverage. Anthropic's platform docs describe a 400 error returned when a HIPAA-enabled organisation calls a non-eligible feature — but also warn that some client-side tools "are accepted but remain outside HIPAA readiness", so a successful response is not proof of coverage. |
| Claude Free, Pro and Max — including Claude Code used from those accounts | Not covered | The BAA article routes these to Anthropic's consumer documentation and names Claude Code use from them explicitly. |
| Team plans | Not covered | "Team plans and individual plans (Free, Pro, and Max) can't enable HIPAA." Note the phrasing is about enabling HIPAA, not about signing a BAA. |
| Claude Code metrics logging | Unconfirmed | Anthropic does not give this a BAA status. It says metrics "never include your code, prompts, or file paths", and separately that "productivity data such as usage statistics is exempted from ZDR and may be retained." We are not going to guess which side of the line that lands on. |
We read these pages in August 2026. The BAA page prints no absolute date at all — only "Updated over a week ago" — so you cannot tell from the page itself how current it is. The Enterprise HIPAA page prints July 23, 2026 and the Covered Models page July 1, 2026. Two tables on the BAA page also disagree with each other about whether the API-console CLI path is restricted to qualified accounts: the Claude Code feature table does not say so, while the later per-surface table renders the same surface as eligible "(for qualified accounts)". Treat every row below as a prompt to check the page yourself, not as a substitute for it.
The claim we tried to confirm and could not
What secondary sources say
A claim we set out to verify before publishing this page held that a BAA accepted after 1 April 2026 unlocks Claude Code on a HIPAA-ready first-party API organisation, ZDR no longer required. It is a reasonable-looking reading: the 4/1/26 date is genuinely printed on Anthropic's BAA page, and a HIPAA-ready API organisation without ZDR really is a supported, covered arrangement for API traffic.
- The pre-publication claim described above, tested and refuted against Anthropic's own platform and Covered Models documentation on 26 August 2026.
What the vendor's own documentation says
The footnote governs something else. It sits immediately after the Messages API feature table — Prompt Caching, Structured Outputs, Memory, Web Search, Bash tool, Text Editor tool — and reads "*Covered under versions of the BAA accepted after 4/1/26". The Claude Code table carries no date footnote at all. Anthropic's platform documentation states "Claude Code: Claude Code is not covered under HIPAA readiness." and its Covered Models article states "HIPAA readiness and ZDR cannot coexist on a single 1P API organization. If your organization needs both HIPAA-ready production API usage and ZDR for Claude Code, you'll need separate organization IDs."
How we resolve it
Two true facts, joined into a false one. HIPAA readiness on the API is real and covers API usage; the 4/1/26 footnote is a BAA-version gate on Messages API sub-features. Neither reaches Claude Code, which is carved out by name. The practical consequence is the reason we are printing this at all: a buyer who runs the self-serve API HIPAA flow lands in an organisation where Claude Code can never be covered, and Anthropic describes that enablement as permanent and not disableable by an administrator. If you want covered API traffic and covered Claude Code, you need two organisations, and the order you do this in matters.
Where PHI actually enters Claude Code
The prompt itself, in an organisation without ZDR
HighA developer pastes a failing record, a stack trace with a patient name in it, or a row of production data to show the model the shape of the problem. On a commercial plan without ZDR that text is not trained on — Anthropic says it "does not train generative models using code or prompts sent to Claude Code under commercial terms" unless you opted in — but it is retained server-side for the standard 30-day window, and it is not covered by the BAA. Privacy-reasonable and contractually uncovered are different questions, and this is where they come apart.
How to check
Ask your Primary Owner two things: whether HIPAA is activated in Organization settings > Data and privacy, and whether anyone can produce written confirmation from your Anthropic account team that ZDR is enabled for the organisation your developers actually sign in to. The second one is the one people cannot produce.
/bug, /share and /feedback
HighThese upload conversation history, including code, to Anthropic. Anthropic states that transcripts shared this way "are retained for 5 years." The default scope is the current session, but the person sending it can widen it to a day or a week of project sessions, and the flow can also offer to open a public GitHub issue. This is the single worst default on the page: a five-year retention of whatever was in the window, initiated by a developer who was trying to be helpful.
How to check
Ask your developers directly whether they have ever sent feedback or a bug report from Claude Code while working against real data, then search your public repository's issues for pasted transcript text. The behaviour can be switched off with an environment variable named DISABLE_FEEDBACK_COMMAND set to 1, applied through your managed settings rather than left to each person.
Session transcripts sitting in plaintext on the laptop
HighEverything typed or pasted into Claude Code is written to the developer's own machine in readable form. Anthropic's Claude Code documentation says clients "store session transcripts locally in plaintext under ~/.claude/projects/ for 30 days by default to enable session resumption." Its platform documentation says local session transcripts for Claude Code on users' machines "are stored for 6 years by default". Those are both current Anthropic pages and they do not agree — one month or six years, depending which one you read. No BAA addresses a file on a laptop either way.
How to check
On one developer's machine, open the ~/.claude/projects/ folder and search the files in it for a real surname, a record number prefix or an email domain you know belongs to a patient. Do this on the machine of whoever has been debugging production, not on a fresh one.
MCP servers and connectors inside the session
HighAn agent that can reach a database MCP, a ticketing connector or an internal search tool will pull record contents into the conversation and push them back out to whoever operates the far end. Anthropic disclaims that leg in plain words: these features are "Available to use but sending data to 3rd parties via this feature isn't covered under Anthropic's BAA", and it places responsibility on the administrator who enabled them. Every server on that list is a separate vendor relationship you have to paper yourself.
How to check
Open your project's MCP configuration and your managed Claude Code settings and write down every server listed. For each one, answer two questions: who operates it, and do we have an agreement with them. Anything you cannot answer in one line is the finding.
The surfaces that can never be covered — remote mode, web, Code Review, Code Security, Remote Control
MediumThe same developer, the same prompt, a different surface. Each of these carries "This feature is incompatible with ZDR", and ZDR is the only route to coverage, so switching to one of them moves the work outside any configuration the BAA can reach. Automated code review running over a repository that contains fixture data with real names is the version of this people do not notice, because no human decided to send anything.
How to check
Ask which mode people work in on the desktop app, and check whether Claude Code Review or Code Security is enabled on any repository that holds fixtures, seed files or exported samples. Then grep those fixtures for a real surname.
Telemetry and error reporting
LowClaude Code sends operational metrics to Anthropic and to third-party logging infrastructure, and error reports to a third-party error tracking service. Anthropic scopes both narrowly: metrics "never include your code, prompts, or file paths", and it says error reporting only ever runs for Pro or Max sign-ins on recent versions connecting directly to the API where the organisation has no ZDR or HIPAA agreement — which means a HIPAA or ZDR organisation is excluded from it automatically. We list it for completeness rather than alarm, with one caveat: Anthropic also says productivity metrics are exempted from ZDR and may be retained.
How to check
Confirm nobody on the team is signed into Claude Code with a personal Pro or Max account, since that is the only configuration where error reporting applies. That check overlaps with the plan-tier question below and takes the same minute.
Six checks before you talk to anyone
All six are yes-or-no, and someone with organisation admin access can work through them in about ten minutes. Do them before you pay anybody, us included — the answers decide whether there is a project here.
01Can anyone produce written confirmation from your Anthropic account team that zero data retention is enabled on the organisation your developers sign in to?
02Is anyone on the team using Claude Code signed in with a Free, Pro, Max or Team account?
03Is the first-party API organisation you enabled HIPAA readiness on the same organisation your developers authenticate Claude Code against?
04Does anyone use Claude Code in desktop remote mode, in the web, or with Code Review, Code Security, Computer Use or Remote Control switched on?
05Do any MCP servers or connectors run inside your Claude Code sessions?
06Has anyone used /bug, /share or /feedback in Claude Code while working with real records?
What we do about it
Typical range
$13,000–$25,000
Typical timeline
6–10 weeks
- 01
Surface and account map
3–5 daysOne page listing every Claude Code surface your developers actually use, which organisation and plan each of them authenticates with, and each surface's status against Anthropic's coverage tables, with the date we read those tables printed on it.
- 02
Organisation topology
2–3 weeksA ZDR organisation provisioned for Claude Code and kept separate from any HIPAA-ready API organisation, the account-team correspondence confirming ZDR filed with your records, and every developer re-pointed to it. We prepare and drive the request; Anthropic decides eligibility.
- 03
Closing the surfaces that cannot be covered
1–2 weeksDesktop remote mode, Claude Code in the web, Code Review, Code Security, Computer Use and Remote Control disabled through managed settings rather than by asking people nicely, feedback and bug upload switched off, with a before-and-after list of every setting changed.
- 04
Prompt path and MCP inventory
1–2 weeksEvery MCP server, connector and integration reachable from a session listed with its operator, marked as covered by an agreement, needing one, or removed — plus the removals actually done.
- 05
Laptop exposure and history
1 weekLocal transcript directories inventoried across the fleet and cleared, the retention period set deliberately rather than by default, disk encryption and machine access confirmed, and a written account of anything already uploaded through feedback commands.
- 06
Handover pack
3–5 daysA written document with the surface map, the checks we ran, dated copies of every Anthropic page behind each decision, your executed BAA version, and an explicit list of what remains yours — the thing your auditor asks for.
What moves the number
- How many developers and how many organisations are involved, since coverage is granted per organisation and every developer's authentication path has to be traced individually.
- Whether you have already enabled HIPAA readiness on a first-party API organisation, because that is a one-way door and the work becomes provisioning and migration rather than configuration.
- How many MCP servers and connectors sit inside the sessions, since each operator is a separate agreement and some have to be replaced rather than papered.
- Whether /bug, /share or /feedback were ever used against real data, because tracing what left and when takes far longer than switching the command off.
- The size of the laptop fleet, since local transcripts live on each machine and the retention window is ambiguous in Anthropic's own documentation.
- Whether Anthropic grants your organisation ZDR at all — that decision is theirs, not ours, and everything downstream waits on it.
When not to hire us
- You have no real PHI in the loop yet. If developers are working against synthetic fixtures, this is a policy to write, not a project to run, and doing it before the architecture settles usually means doing it twice.
- All you actually need is the paperwork. The Primary Owner accepts the BAA in organization settings under “Data and privacy”, and ZDR is a request to your Anthropic account team. Paying an agency to send that email is paying an agency to send an email.
- You are two developers on one Enterprise organisation, using only the CLI, with no MCP servers and no personal Pro accounts. Then the self-check above is the entire audit and you have just finished it.
- You want a certificate. There is no government HIPAA certification for any product, so nobody can sell you one — not Anthropic, not us.
Worth knowing either way
There is no government HIPAA certification
No authority certifies software as HIPAA-compliant. What exists is a signed Business Associate Agreement with every vendor that touches protected health information, plus the administrative, physical and technical safeguards you implement and document yourself.
SOC 2 is not a substitute for a BAA
Supabase states it plainly in its own documentation: “SOC 2 does not cover, nor is it a substitute for, compliance with the Health Insurance Portability and Accountability Act (HIPAA).” The same holds for every vendor here.
An absence of documentation is not a vendor promise
Several answers here rest on what vendor documents do not say. We name which documents we read and when. A vendor that has never published a HIPAA position may still decline to sign, and one that publishes nothing today may publish something next quarter.
The same question, for the other fifteen tools
Firebase
NoOnly the Google Cloud equivalents are covered — no Firebase-branded service is
Supabase
Yes, with conditionsBAA plus a paid HIPAA add-on, on the Team plan or above
v0 by Vercel
PartiallyVercel hosting is covered; v0 itself is contractually off-limits for PHI
Lovable
NoIts terms prohibit uploading protected health information
Bubble
NoIts own documentation says apps built on Bubble won't achieve compliance
Replit
NoIts Terms, Commercial Agreement and DPA carry no HIPAA or BAA terms
Bolt.new
NoNo BAA in the StackBlitz and Bolt documents we read; HIPAA is named only for self-hosted
FlutterFlow
NoIts terms bar processing HIPAA-protected data outright
Claude Code
Yes, with conditionsCovered only with zero data retention, on accounts Anthropic qualifies
Codex
Yes, with conditionsCodex Local on a Regulated or Healthcare tier; Codex Cloud is excluded
Cursor
Yes, with conditionsEnterprise only, with Privacy Mode locked organisation-wide
GitHub Copilot
NoNo BAA offered; the Data Protection Agreement tells customers not to send PHI
Devin
NoPHI is Prohibited Data under the acceptable-use policy
Hermes Agent
Not the right questionSelf-hosted — the agreement you need is with your model provider
OpenClaw
Not the right questionSelf-hosted — but the vendor-run router still receives prompts
Base44
NoNo BAA; its terms ask customers to keep PHI off the platform
Sources, quoted as printed
Every claim above traces to one of these. Quotes are reproduced as printed on the source page and are never spliced together. Where an entry reports something we observed rather than something a vendor wrote, the claim says so in our own words. One quirk worth naming: Anthropic's Claude Code table carries a superscript footnote marker rendered as "1" whose footnote text does not appear anywhere on the page, and we have left that stray character inside the quotes rather than tidy them.
Accepting the BAA does not cover Claude Code. ZDR is a separate precondition, and Anthropic says so including for Enterprise seats that bundle Claude Code access.
Important: Enabling HIPAA readiness alone doesn't bring Claude Code under your BAA. Claude Code is covered under your BAA only with zero data retention (ZDR) enabled, and only on qualified accounts. Without ZDR, Claude Code remains available to use but isn't covered—including when Claude Code access is bundled into your Enterprise seats. To explore Claude Code coverage, contact your Anthropic account team or our Sales team.
Anthropic offers the BAA, and an Enterprise Primary Owner accepts it in organisation settings.
Anthropic provides a BAA covering our HIPAA-ready services, such as use of our first-party API or Enterprise plans. Claude Enterprise Primary Owners can accept the BAA directly when activating HIPAA compliance in the organization settings under “Data and privacy.”
Anthropic — Business Associate Agreements (BAA) for commercial customersSource dated: no absolute date printed; the page shows only “Updated over a week ago”Checked: August 2026The three Claude Code surfaces that can be covered, as Anthropic names them, each with the ZDR condition attached.
Claude Code CLI (via 1P API console) — ✅ Only covered under the BAA with ZDR enabled. If your org needs ZDR for 1P API, please contact a sales representative. ⚠️ Without ZDR enabled, this feature is available to use but is not covered under Anthropic's BAA.
Anthropic — Business Associate Agreements (BAA) for commercial customers, Claude Code tableSource dated: no absolute date printed; the page shows only “Updated over a week ago”Checked: August 2026The Enterprise OAuth CLI path carries the additional qualified-accounts restriction.
Claude Code CLI (via Claude Enterprise OAuth) — ✅ Only covered under the BAA with ZDR enabled.1 ZDR is available for qualified accounts only. If your org needs to use PHI with this feature, please contact a sales representative to evaluate options.
Anthropic — Business Associate Agreements (BAA) for commercial customers, Claude Code tableSource dated: no absolute date printed; the page shows only “Updated over a week ago”Checked: August 2026Desktop local mode is coverable; desktop remote mode is architecturally incapable of coverage. These are two adjacent rows of the same table and we reproduce each separately.
Claude Code in the desktop (remote mode) — ⚠️ Available to use without ZDR, but this feature is not covered under Anthropic's BAA. This feature is incompatible with ZDR.
Anthropic — Business Associate Agreements (BAA) for commercial customers, Claude Code tableSource dated: no absolute date printed; the page shows only “Updated over a week ago”Checked: August 2026Claude Code in the web, Code Review, Code Security, Computer Use and Remote Control each carry an identical status line, which is why we describe them as a group.
Available to use without ZDR but this feature is not covered under Anthropic's BAA. This feature is incompatible with ZDR.
Anthropic — Business Associate Agreements (BAA) for commercial customers, Claude Code tableSource dated: no absolute date printed; the page shows only “Updated over a week ago”Checked: August 2026A HIPAA-ready first-party API organisation cannot cover Claude Code, and the two configurations cannot share one organisation.
HIPAA readiness and ZDR cannot coexist on a single 1P API organization. If your organization needs both HIPAA-ready production API usage and ZDR for Claude Code, you'll need separate organization IDs.
Anthropic's platform documentation states the carve-out directly.
Claude Code: Claude Code is not covered under HIPAA readiness.
Anthropic Platform docs — API and data retentionSource dated: no date printed on the pageChecked: August 2026Coverage always requires both the signature and the right configuration, and for Claude Code that configuration is ZDR specifically.
Note: Coverage under Anthropic's BAA always requires (a) signing the BAA, and (b) accessing Anthropic's products via their HIPAA-ready or (in the case of Claude Code) zero data retention configurations.
Choosing ZDR to get Claude Code covered closes off the Covered Models. This is a genuine trade-off, not a temporary gap you can configure around.
Some services, like Claude Code, are only covered under the BAA when ZDR is enabled, which means those services can't use Covered Models under the BAA.
Anthropic — Business Associate Agreements (BAA) for commercial customersSource dated: no absolute date printed; the page shows only “Updated over a week ago”Checked: August 2026Anthropic never defines “qualified accounts”. We searched the BAA article, the HIPAA-ready Enterprise article, the Covered Models article, the ZDR article, the Claude Code data usage docs and the platform retention docs, and found no eligibility criteria anywhere — only that an account team decides per organisation. The quote below is the closest published language.
Zero data retention: available to qualified accounts for Claude Code on Claude for Enterprise. ZDR is not included in the standard Enterprise plan; it is enabled on a per-organization basis by your account team after confirming eligibility.
Anthropic docs — Claude Code data usageSource dated: page metadata shows dateModified 2026-08-21; no date printed in the bodyChecked: August 2026ZDR is granted at Anthropic's discretion, per organisation.
zero data retention requests are reviewed and applied on a per-organization basis
Anthropic — I have a zero data retention agreement with Anthropic. What products does it apply to?Source dated: June 9, 2026Checked: August 2026Consumer and Team plans cannot enable HIPAA at all. Note Anthropic's phrasing is about enabling HIPAA rather than about signing a BAA.
You can enable the HIPAA configuration from organization settings if your organization is on an Enterprise plan. Team plans and individual plans (Free, Pro, and Max) can't enable HIPAA.
Claude Code used from consumer accounts is routed out of the commercial BAA article entirely.
This article is about our commercial products such as Claude for Work and the Anthropic API. For our consumer products such as Claude Free, Pro, Max and when accounts from those plans use Claude Code, see here.
Anthropic — Business Associate Agreements (BAA) for commercial customersSource dated: no absolute date printed; the page shows only “Updated over a week ago”Checked: August 2026The BAA binds a single organisation and names specific excluded surfaces — including Claude Console, which is not the same thing as the API console credential path used by the CLI.
For clarity, the BAA only covers the single organization that accepted it, and excludes features such as Claude Console, Claude Cowork, or features currently in beta such as Claude in Office and Claude Design.
Anthropic — Business Associate Agreements (BAA) for commercial customersSource dated: no absolute date printed; the page shows only “Updated over a week ago”Checked: August 2026Enabling HIPAA readiness from the Console is supported even though processing PHI through the Console is not covered — the precise distinction behind the row above.
Claude Console: Usage through the Claude Console interface (enabling HIPAA readiness from Console settings is supported; processing PHI through the Console is not covered).
Anthropic Platform docs — API and data retentionSource dated: no date printed on the pageChecked: August 2026The third-party leg of MCP servers, connectors and similar features is disclaimed, and the obligation is placed on the administrator who enables them.
Available to use but sending data to 3rd parties via this feature isn't covered under Anthropic's BAA. Administrators who enable these features are responsible for ensuring their workforce uses them in compliance with applicable legal obligations.
Anthropic — Business Associate Agreements (BAA) for commercial customersSource dated: no absolute date printed; the page shows only “Updated over a week ago”Checked: August 2026Enabling HIPAA is irreversible from organisation settings and resets configuration.
This is a one-way decision. Once HIPAA is enabled and the BAA is accepted, the change can't be reversed from organization settings
A BAA signed before 2 December 2025 does not stretch to the HIPAA-ready Enterprise plan.
If your organization signed a BAA for Claude API usage before December 2, 2025, that agreement only covers API usage—it does not extend to the HIPAA-ready Enterprise plan. To add this Enterprise plan access, you'll need to sign a new BAA with your account team. BAAs signed after December 2, 2025 can cover both API usage and the Enterprise plan under a single agreement.
Coverage is pinned to the version of the BAA an organisation accepted, which is why the published tables are advisory for any particular customer.
Download the Business Associate Agreement and the HIPAA Implementation Guide, then accept the agreement as an authorized legal representative of your organization. Each step becomes available after you download the prior document, and your enablement is bound to the exact BAA version you downloaded.
Anthropic Platform docs — API and data retentionSource dated: no date printed on the pageChecked: August 2026Anthropic points past its own public tables to a gated document, and to your executed agreement. We requested nothing and read nothing behind that portal, so we cannot report what it says.
The Implementation Guide for HIPAA Entities on the Anthropic Trust Center lists every feature's status and is the authoritative source.
Anthropic — Business Associate Agreements (BAA) for commercial customersSource dated: no absolute date printed; the page shows only “Updated over a week ago”Checked: August 2026Default commercial handling without ZDR: no model training on Claude Code prompts under commercial terms.
Commercial users: (Team and Enterprise plans, API, 3rd-party platforms, and Claude Gov) maintain existing policies: Anthropic does not train generative models using code or prompts sent to Claude Code under commercial terms, unless the customer has chosen to provide their data to us for model improvement (for example, the Developer Partner Program).
Anthropic docs — Claude Code data usageSource dated: page metadata shows dateModified 2026-08-21; no date printed in the bodyChecked: August 2026Default server-side retention for commercial API users, for orientation on what “uncovered but retained” means in practice.
For Anthropic API users, we automatically delete inputs and outputs on our backend within 30 days of receipt or generation
Anthropic — How long do you store my organization's data?Source dated: July 1, 2026Checked: August 2026Transcripts sent through the feedback commands are retained for five years.
Transcripts shared via /feedback, or via /bug and /share, which report through the same path, are retained for 5 years.
Anthropic docs — Claude Code data usageSource dated: page metadata shows dateModified 2026-08-21; no date printed in the bodyChecked: August 2026Local plaintext transcripts, first of two conflicting Anthropic statements about how long they are kept.
Local caching: Claude Code clients store session transcripts locally in plaintext under ~/.claude/projects/ for 30 days by default to enable session resumption. Adjust the period with cleanupPeriodDays.
Anthropic docs — Claude Code data usageSource dated: page metadata shows dateModified 2026-08-21; no date printed in the bodyChecked: August 2026Local plaintext transcripts, second of two conflicting Anthropic statements. Both pages were live in August 2026 and we are printing the conflict rather than choosing a side.
Local session transcripts (Cowork and Claude Code on users' machines) are stored for 6 years by default, or for your organization's custom conversation retention period when a finite one is set (the same claude.ai setting).
Anthropic Platform docs — API and data retentionSource dated: no date printed on the pageChecked: August 2026ZDR has carve-outs of its own: metrics are exempted from it.
If metrics logging is enabled in Claude Code, productivity data such as usage statistics is exempted from ZDR and may be retained.
Anthropic Platform docs — API and data retentionSource dated: no date printed on the pageChecked: August 2026The API blocks some non-eligible features for HIPAA-enabled organisations, but a successful response is not proof of coverage.
Client-side tools whose Details column in the feature eligibility table says they are not blocked are accepted but remain outside HIPAA readiness.
Anthropic Platform docs — API and data retentionSource dated: no date printed on the pageChecked: August 2026
Frequently asked questions
We accepted Anthropic's BAA. Is Claude Code covered now?
No, not on that alone. Anthropic writes: "Important: Enabling HIPAA readiness alone doesn't bring Claude Code under your BAA. Claude Code is covered under your BAA only with zero data retention (ZDR) enabled, and only on qualified accounts." It adds that without ZDR, Claude Code stays usable but uncovered "including when Claude Code access is bundled into your Enterprise seats." So the BAA is step one of two, and step two is not a setting you can find — it is a request to your account team.
What counts as a “qualified account”?
Anthropic does not say. We looked across the BAA article, the HIPAA-ready Enterprise article, the Covered Models article, the ZDR article, the Claude Code data usage docs and the platform retention docs and found no published criteria — only that ZDR is "enabled on a per-organization basis by your account team after confirming eligibility" and that requests are "reviewed and applied on a per-organization basis." Treat it as a discretionary sales gate, not a plan tier or a checklist. If someone tells you your account qualifies, ask for that in writing, because that correspondence is the only artefact that exists.
We already turned on HIPAA readiness for our API organisation. Can our developers use Claude Code there?
Not under the BAA. Anthropic's platform documentation says "Claude Code: Claude Code is not covered under HIPAA readiness." and its Covered Models article says "HIPAA readiness and ZDR cannot coexist on a single 1P API organization. If your organization needs both HIPAA-ready production API usage and ZDR for Claude Code, you'll need separate organization IDs." You need a second organisation with ZDR for the coding work. Anthropic also describes HIPAA enablement as permanent, so this is worth getting right before you click, not after.
Which Claude Code surfaces can never be covered, no matter what we pay?
Six. Claude Code in the desktop in remote mode, Claude Code in the web, Claude Code Review, Claude Code Security, Claude Code Computer Use and Claude Code Remote Control. Each carries "This feature is incompatible with ZDR" in Anthropic's own table, and ZDR is the precondition for coverage, so the two facts close the door together. The surfaces that can be covered are the CLI via the first-party API console, the CLI via Claude Enterprise OAuth, and desktop local mode. Local versus remote is the whole distinction.
Our BAA is older. Does the date we signed matter?
Yes, in two ways. Anthropic prints version footnotes on its feature tables — "*Covered under versions of the BAA accepted after 12/2/25" on the Enterprise and API tables, and "*Covered under versions of the BAA accepted after 4/1/26" on the Messages API table — and its platform docs say "your enablement is bound to the exact BAA version you downloaded." Separately, a BAA signed for API usage before 2 December 2025 "only covers API usage—it does not extend to the HIPAA-ready Enterprise plan." So the green checkmarks you read today describe the current agreement, not necessarily yours.
What do we give up by turning ZDR on?
Three things worth knowing before you ask for it. Anthropic states that Covered Models require 30-day retention and are unavailable under ZDR, and that because Claude Code is only covered with ZDR, "those services can't use Covered Models under the BAA" — so the configuration that makes Claude Code covered is the same one that keeps those models out of reach. Its platform docs also say CORS is not supported for organisations with ZDR arrangements, and that productivity metrics are exempted from ZDR. ZDR is a strong control, not a total one.
Is anything left on our developers' laptops?
Yes, and Anthropic's own pages disagree about for how long. The Claude Code documentation says clients "store session transcripts locally in plaintext under ~/.claude/projects/ for 30 days by default", while the platform documentation says local session transcripts on users' machines "are stored for 6 years by default". Both were live when we checked. Either way it is plaintext on a laptop, no BAA speaks to it, and it is the fastest thing on this page to verify — open the folder on the machine of whoever last debugged production and search it for a real name.
This page reports what Anthropic's published documents said on the dates shown and is technical information rather than legal advice; HIPAA compliance is a property of your whole system and the processes around it rather than of any single tool, and vendor terms change — verify the current terms with Anthropic before relying on anything here.
