Is Claude HIPAA Compliant? Only on Enterprise, Once a BAA Is Signed

Practical guidance for healthcare teams and business associates

In March 2026, OCR announced a settlement with MMG Fusion, a Maryland software company and business associate, after a December 2020 intrusion exposed the protected health information of approximately 15 million individuals. The company had never completed an accurate and thorough risk analysis and had failed to notify the covered entities it served. It paid $10,000, a figure OCR tied to the company's financial condition, plus a three-year corrective action plan. The point for a practice choosing an AI vendor is not the dollar amount. It is that a software business associate with contracts in place still had no risk analysis, and the covered entities that trusted it found out late.

Is Claude HIPAA compliant? Yes, on the Enterprise plan, after a specific person flips a specific switch, and only for the features on Anthropic's covered list. Anthropic offers "a HIPAA-ready version of Claude that is available for organizations on Enterprise plans," which "includes a Business Associate Agreement (BAA), functionality, and safeguards designed to support an organization's HIPAA compliance requirements." Claude Free, Pro, Max, and Team "can't enable HIPAA." A HIPAA-ready configuration also exists for the Claude API. This guide walks the plan, the B.A.A. (Business Associate Agreement), the features it covers and excludes, and the setup a practice owes on its side.

Is Claude HIPAA Compliant? The Enterprise Switch and the BAA

Does Anthropic Sign a BAA for Claude?

Yes, and the mechanics are unusually self-serve. On Claude Enterprise, "the Primary Owner of the organization must activate HIPAA compliance in the HIPAA-ready Claude Enterprise organization settings under 'Data and privacy' and accept Anthropic's BAA." The BAA "is included in the flow as click-to-accept," it "is a standard agreement and can't be modified," and clicking "Accept and Enable HIPAA" constitutes acceptance. Anthropic is direct about the default: "Standard Claude Enterprise plans do not include BAA coverage without action from a Primary Owner." Buying Enterprise is not enough. Someone has to press the button, and only the Primary Owner can.

Two more details matter. Enabling HIPAA "is a one-way decision" that "can't be reversed from organization settings," and it "resets certain settings across your organization." Anthropic tells owners to review the BAA and its Implementation Guide for HIPAA Entities before accepting. That guide, on Anthropic's Trust Center, "lists every feature's status and is the authoritative source." Download both during the flow and file them with the date. The regulation's version of this step is 45 CFR 164.502(e)(2): the assurance "must be documented through a written contract." A screenshot of the checkmark is not the contract. The full checklist for what a BAA must contain is in the business associate agreement guide.

Which Claude Plans Are HIPAA-Eligible?

Plan or surfaceBAA availableNotes from Anthropic
Claude Free, Pro, MaxNoIndividual plans "can't enable HIPAA"
Claude TeamNo"Team plans ... can't enable HIPAA"
Claude Enterprise (self-serve or sales-assisted)Yes, after the Primary Owner enables HIPAA and accepts the BAACovers Chat and the eligible features listed below
Claude API (first-party)Yes, on a HIPAA-ready API organizationOwner signs the BAA, then Anthropic turns the configuration on; some API features are excluded
Claude through a third-party cloud providerNot Anthropic's BAA"Anthropic's BAA doesn't apply to services purchased through a third-party cloud provider"

What the Claude BAA Covers, and What It Does Not

Anthropic publishes a feature table, and the honest summary is that enabling HIPAA "doesn't bring every feature under your BAA." Features fall into "covered by your BAA, available but not covered, and disabled," and P.H.I. (Protected Health Information) "should only be processed through covered features." On Enterprise, as of the fetched page:

  • Covered: Chat, Projects, Artifacts, file creation and code execution (excluding network access and external websites), Voice, Web Search, Research, and Skills, for BAAs accepted after December 2, 2025.
  • Available but not covered when data goes to third parties: MCP connectors, Enterprise Search, and Claude in Chrome. Anthropic's line: "sending data to 3rd parties via this feature isn't covered under Anthropic's BAA," and administrators who enable these features "are responsible for ensuring their workforce uses them in compliance."
  • Not covered in any configuration: Cowork. Beta features such as Claude Design and parts of Claude for Office are also outside the BAA.
  • Claude Code: covered "only with zero data retention (ZDR) enabled, and only on qualified accounts." Without ZDR it works but is not covered, "including when Claude Code access is bundled into your Enterprise seats."
  • API exclusions on a HIPAA-ready organization: the Batch API, Files API, Skills API, and code execution are "not covered under Anthropic BAA and not accessible for HIPAA-Ready API users."

One wrinkle for the newest models: Anthropic's "Covered Models," including Claude Fable 5, "require 30-day data retention" and cannot run with zero data retention. The covered paths to those models under the BAA are Chat on a HIPAA-ready Enterprise plan and the HIPAA-ready API. Claude Code cannot use them under the BAA in any configuration. Retention is a decision to make knowingly, not a default to discover.

What Stays Your Job

The BAA covers Anthropic's conduct with the PHI you send. Everything about what you send remains yours. 45 CFR 164.502(b)(1) requires a covered entity to "make reasonable efforts to limit protected health information to the minimum necessary to accomplish the intended purpose," and pasting a full chart into a prompt to draft a two-line letter fails that test with or without a BAA. What counts as PHI in an AI prompt is broader than most staff assume; a case description with an age, a date, and a clinic location can identify a patient with no name attached. Where the task allows it, strip the identifiers listed in 45 CFR 164.514(b)(2), as walked through in the de-identification guide, and the question of coverage becomes moot for that prompt.

The other job is the one MMG Fusion skipped. 45 CFR 164.308(a)(1)(ii)(A) requires "an accurate and thorough assessment of the potential risks and vulnerabilities" to ePHI. A HIPAA-ready Claude organization is a system that receives ePHI. It belongs in the risk analysis, with its connectors, its retention setting, and its user list.

How to Set Up Claude for HIPAA

  1. Get on Enterprise. Team and individual plans cannot enable HIPAA, full stop.
  2. Have the Primary Owner enable HIPAA. Organization settings, Data and privacy, HIPAA Compliance, Enable. Download the BAA and the Implementation Guide during the flow, then accept.
  3. File both documents in the vendor register with the acceptance date. If the organization signed an API BAA before December 2, 2025, note that Anthropic says it "does not extend to the HIPAA-ready Enterprise plan," and a new BAA is needed.
  4. Configure the workspace to the guide. Decide, per Anthropic's table, which non-covered features stay on. If MCP connectors or Claude in Chrome remain enabled, the policy must say PHI never goes through them.
  5. Settle Claude Code. Either obtain ZDR for a qualified account or write "no PHI in Claude Code" into policy and training.
  6. Close the consumer accounts. A clinician's personal Pro account is outside the BAA. Require work use through the Enterprise organization only, the same rule the ChatGPT guidance applies to every consumer AI tool.
  7. Restrict access. Unique logins per person under 45 CFR 164.312(a)(2)(i), multifactor authentication where the console supports it, and prompt removal at termination.
  8. Write the AI acceptable use policy. Approved tools, prohibited data, approved tasks, an approval path for new tools, and sanctions.
  9. Add Claude to the risk analysis and to the annual review.
  10. Train staff on prompts, not just policy. The habit that causes breaches is copy-paste from the EHR. Show what a minimum-necessary prompt looks like.

Common Claude HIPAA Mistakes

Buying Enterprise and assuming coverage. Anthropic says the opposite in one sentence.

Treating the checkmark as the contract. The BAA is the document you downloaded, dated and filed.

Leaving connectors on for everyone. The feature works; the coverage stops at the third party.

Mixing consumer and Enterprise use. The same person, two accounts, one of them outside the BAA.

Alternatives and Comparisons

ToolBAA pathNotes
ClaudeEnterprise (owner enables HIPAA) or HIPAA-ready APIPublished covered-feature table; Cowork and some betas excluded
ChatGPTEnterprise and API onlyFree and Plus have no BAA; see the ChatGPT analysis
Microsoft 365 CopilotIn-scope under the Microsoft 365 BAA on commercial plansConsumer Copilot is not; see the Microsoft 365 guide
Google GeminiGemini app and Gemini in Workspace are on Google's HIPAA Included Functionality list for paid Workspace with the BAA acceptedConsumer Gemini on a personal account is not

Claude is one of the few AI assistants with a published, feature-by-feature statement of what its BAA covers. That transparency is useful, and it cuts both ways: the list of what is not covered is right there, and so is the sentence that says the plan alone does nothing. Read both before the first prompt with a patient's name in it.

---

FAQ

Does Anthropic sign a BAA for Claude?

Yes, for Claude Enterprise organizations after the Primary Owner enables HIPAA in organization settings and accepts the click-to-accept BAA, and for HIPAA-ready Claude API organizations. Free, Pro, Max, and Team plans cannot enable HIPAA.

Is Claude Pro or Claude Max HIPAA compliant?

No. Anthropic states that individual plans (Free, Pro, and Max) and Team plans can't enable HIPAA. A personal Claude account used with patient information is a disclosure to a vendor without a BAA.

Does enabling HIPAA on Claude Enterprise cover every feature?

No. Anthropic publishes a table: Chat, Projects, Artifacts, Voice, Web Search, Research, and Skills are covered; MCP connectors, Enterprise Search, and Claude in Chrome are available but sending data to third parties is not covered; Cowork and some beta features are not covered.

Is Claude Code covered by the BAA?

Only with zero data retention enabled on a qualified account. Without ZDR, Claude Code works but is not covered, even when it is bundled into Enterprise seats. Covered Models such as Claude Fable 5 cannot run under ZDR, so Claude Code cannot use them under the BAA.

What does a practice still have to do after the BAA is accepted?

Configure the workspace to Anthropic's Implementation Guide, apply the minimum necessary standard to prompts, close consumer accounts, control access, write an AI acceptable use policy, and add Claude to the risk analysis.

Conclusion

AI tools arrive in a practice through the side door, and the policy usually arrives a year later. One Guy Consulting's Full-Scope plan includes vendor and BAA management, the AI acceptable use policy template, and consulting time to decide which AI tools your staff may use with patient information and on what terms. Start with a free 30-minute compliance review. No obligation, no pressure.

Sources


Related Reading