# Is Claude Code HIPAA compliant? Only in a zero-data-retention org

- Tool: Compliance
- Last updated: August 2026

## TL;DR

Yes, conditionally — but signing Anthropic's BAA does not bring Claude Code under it. Claude Code is covered only with zero data retention (ZDR) enabled, and only on accounts Anthropic calls qualified. Three Claude Code surfaces can be covered that way; six others each carry the line "This feature is incompatible with ZDR", so no admin action reaches them. Getting a team into a covered configuration takes us 6–10 weeks.

## Frequently asked questions

### We accepted Anthropic's BAA. Is Claude Code covered now?

No, not on that alone. Anthropic writes: "Important: Enabling HIPAA readiness alone doesn't bring Claude Code under your BAA. Claude Code is covered under your BAA only with zero data retention (ZDR) enabled, and only on qualified accounts." It adds that without ZDR, Claude Code stays usable but uncovered "including when Claude Code access is bundled into your Enterprise seats." So the BAA is step one of two, and step two is not a setting you can find — it is a request to your account team.

### What counts as a “qualified account”?

Anthropic does not say. We looked across the BAA article, the HIPAA-ready Enterprise article, the Covered Models article, the ZDR article, the Claude Code data usage docs and the platform retention docs and found no published criteria — only that ZDR is "enabled on a per-organization basis by your account team after confirming eligibility" and that requests are "reviewed and applied on a per-organization basis." Treat it as a discretionary sales gate, not a plan tier or a checklist. If someone tells you your account qualifies, ask for that in writing, because that correspondence is the only artefact that exists.

### We already turned on HIPAA readiness for our API organisation. Can our developers use Claude Code there?

Not under the BAA. Anthropic's platform documentation says "Claude Code: Claude Code is not covered under HIPAA readiness." and its Covered Models article says "HIPAA readiness and ZDR cannot coexist on a single 1P API organization. If your organization needs both HIPAA-ready production API usage and ZDR for Claude Code, you'll need separate organization IDs." You need a second organisation with ZDR for the coding work. Anthropic also describes HIPAA enablement as permanent, so this is worth getting right before you click, not after.

### Which Claude Code surfaces can never be covered, no matter what we pay?

Six. Claude Code in the desktop in remote mode, Claude Code in the web, Claude Code Review, Claude Code Security, Claude Code Computer Use and Claude Code Remote Control. Each carries "This feature is incompatible with ZDR" in Anthropic's own table, and ZDR is the precondition for coverage, so the two facts close the door together. The surfaces that can be covered are the CLI via the first-party API console, the CLI via Claude Enterprise OAuth, and desktop local mode. Local versus remote is the whole distinction.

### Our BAA is older. Does the date we signed matter?

Yes, in two ways. Anthropic prints version footnotes on its feature tables — "*Covered under versions of the BAA accepted after 12/2/25" on the Enterprise and API tables, and "*Covered under versions of the BAA accepted after 4/1/26" on the Messages API table — and its platform docs say "your enablement is bound to the exact BAA version you downloaded." Separately, a BAA signed for API usage before 2 December 2025 "only covers API usage—it does not extend to the HIPAA-ready Enterprise plan." So the green checkmarks you read today describe the current agreement, not necessarily yours.

### What do we give up by turning ZDR on?

Three things worth knowing before you ask for it. Anthropic states that Covered Models require 30-day retention and are unavailable under ZDR, and that because Claude Code is only covered with ZDR, "those services can't use Covered Models under the BAA" — so the configuration that makes Claude Code covered is the same one that keeps those models out of reach. Its platform docs also say CORS is not supported for organisations with ZDR arrangements, and that productivity metrics are exempted from ZDR. ZDR is a strong control, not a total one.

### Is anything left on our developers' laptops?

Yes, and Anthropic's own pages disagree about for how long. The Claude Code documentation says clients "store session transcripts locally in plaintext under ~/.claude/projects/ for 30 days by default", while the platform documentation says local session transcripts on users' machines "are stored for 6 years by default". Both were live when we checked. Either way it is plaintext on a laptop, no BAA speaks to it, and it is the fastest thing on this page to verify — open the folder on the machine of whoever last debugged production and search it for a real name.

---

Source: https://www.rapidevelopers.com/compliance/is-claude-code-hipaa-compliant
© RapidDev — https://www.rapidevelopers.com/compliance/is-claude-code-hipaa-compliant
