Claude can handle patient data on two surfaces: Claude Enterprise, once the organization's Primary Owner turns on HIPAA and accepts Anthropic's Business Associate Agreement, and the first-party API in a HIPAA-ready organization. Free, Pro and Max are consumer plans, and Team isn't one of the HIPAA-ready services Anthropic names. Even on a covered plan, Cowork, the Console and several beta features sit outside the BAA, and Claude Code is covered only with zero data retention.
Last checked: 2 October 2026, against Anthropic's BAA article for commercial customers, its ZDR scope article, the Covered Models page and its commercial retention and training articles. Anthropic changes this table often, so check the date on its article before you rely on ours. Not legal advice.
2surfaces Anthropic's BAA covers: Claude Enterprise and the first-party API.
4plans that can't hold PHI: Free, Pro, Max and Team.
30 daysminimum retention on Covered Models, so no ZDR with them.
0Cowork features covered by the BAA. Keep PHI out of it.
We connect Claude to EHRs and practice systems for healthcare teams, so we read Anthropic's BAA page closely and often. Its table now covers dozens of features across three products, and the BAA versions it references are dated December 2025 and April 2026, so older write-ups miss rows. This one maps the current table to the questions a practice owner actually asks.
Which Claude plans does Anthropic's BAA cover?
Anthropic's BAA article says it "provides a BAA covering our HIPAA-ready services, such as use of our first-party API or Enterprise plans." For Enterprise, the Primary Owner turns on HIPAA compliance under "Data and privacy" in organization settings and accepts the BAA there. The article adds: "Standard Claude Enterprise plans do not include BAA coverage without action from a Primary Owner." For the API, the Primary Owner signs the BAA and then asks the Anthropic account team or sales to switch the organization on.
| Claude plan or surface |
Under Anthropic's BAA? |
What that means for a practice |
| Free, Pro, Max |
No |
Consumer plans. No BAA. Pasting a patient's note into one is a disclosure to a vendor with no BAA. |
| Team |
No |
Commercial terms and no training on your data by default, but not a HIPAA-ready service in Anthropic's list. Fine for work with no PHI. |
| Enterprise, HIPAA not activated |
Not yet |
Same software, no BAA until the Primary Owner turns HIPAA on and accepts it. |
| Enterprise, HIPAA activated |
Yes, for listed features |
Chat, projects, artifacts, file creation and code execution (without network access), voice, web search, research and skills are covered. |
| First-party API, HIPAA-ready org |
Yes, for listed features |
The Messages API is covered, with prompt caching, structured outputs, memory, web search, the bash tool and the text editor tool. Batch, Files, Skills, Code Execution, Computer Use and Web Fetch aren't, and HIPAA-ready orgs can't reach them. |
| Claude through AWS, Google or Microsoft |
That cloud's BAA |
You sign with the cloud, not with Anthropic. Amazon Bedrock is on AWS's HIPAA eligible services list. Check the other clouds' lists the same way before you assume coverage. |
The BAA covers only the organization that accepted it. If a clinic runs two Claude organizations, one for admin staff and one for clinicians, each one needs its own HIPAA activation.
What the BAA leaves out, even on Enterprise
This is the part most practices miss. A covered Enterprise organization still offers features that aren't covered, and Anthropic leaves it to administrators to decide whether staff can turn them on. Its article sorts them into three groups.
Excluded outright
Cowork, Console, beta features
The BAA "excludes features such as Claude Console, Claude Cowork, or features currently in beta such as Claude in Office, Claude Design, Claude Slides, and Claude Docs." Design, Slides and Docs aren't available to HIPAA-ready organizations at all yet. Claude for Microsoft 365 has some beta features that aren't covered.
Third-party data flows
Connectors, MCP, Enterprise Search, Claude in Chrome
You can use them, but "sending data to 3rd parties via this feature isn't covered under Anthropic's BAA." Whatever system sits on the other end of a connector needs its own BAA with you.
Covered only with ZDR
Claude Code
The CLI and the desktop app's local mode are covered only with zero data retention, which Anthropic grants to qualified accounts. Remote mode, Claude Code on the web, Code Review, Code Security, Computer Use and Remote Control aren't covered.
The Cowork exclusion matters because Cowork is the feature most office managers want to switch on first: it works with files and runs tasks across apps. In a HIPAA-ready organization it's available and not covered, so either it stays off or PHI stays out of it. We wrote up what Cowork can and can't reach in our note on Cowork and local connectors.
How zero data retention changes the answer
Zero data retention is a separate arrangement from the BAA, and the two interact in a way that surprises people. Per Anthropic's ZDR article, ZDR applies only to eligible APIs, products that use your commercial API key (Claude Code through the API included) and Claude Code on Enterprise plans. It's approved per organization. It doesn't apply to chats in the Claude app, and Anthropic still keeps User Safety classifier results to enforce its Usage Policy.
Then there are Covered Models. Anthropic designated Claude Fable 5 and Mythos 5 on 9 June 2026, and Fable 5.1 and Mythos 5.1 on 31 August 2026. These models keep prompts and outputs for at least 30 days, so ZDR isn't available wherever they run. The BAA article spells out the consequence: "Some services, like Claude Code, are only covered under the BAA when ZDR is enabled, which means those services can't use Covered Models under the BAA."
What that means in practice
A developer on your team using Claude Code on a repository with real patient data has to be on a ZDR-enabled account and on a model that isn't a Covered Model. Anthropic has said a temporary ZDR option for Fable 5 and 5.1 is coming for eligible customers, ahead of a program it calls Enterprise Frontier Safeguards. Until your organization is told it qualifies, plan as if it doesn't.
One more thing ZDR doesn't mean: that nothing leaves the practice. Prompts still travel to Anthropic or to your cloud provider and get processed there. What you can defend in front of an auditor is a signed BAA, training off (Anthropic doesn't train on commercial data by default), the shortest retention your plan allows, and a log of who sent what. Our guide to ZDR on Team versus the API goes deeper on retention.
Want Claude in the practice without guessing?
We set up HIPAA-ready Claude for healthcare teams: the right plan, permissions, which features stay off, connectors to your EHR under BAAs, and a log of what was sent.
Talk to a founder
What a practice still has to set up
The BAA covers Anthropic's side. Everything around it stays with you, and this is the list we work through with a practice before real patient data goes in.
Plan and activation
A HIPAA-ready Enterprise organization with HIPAA turned on by the Primary Owner, or an API organization switched on by Anthropic after the BAA is signed. Record the date and the BAA version you accepted.
Features that stay off
Cowork, beta features, and any connector or MCP server whose other end has no BAA with you. Claude Code only on ZDR accounts for anyone near PHI.
Who can see what
SSO and seats limited to staff who need it, projects split by team so front desk and clinicians don't share a knowledge base, and minimum necessary data in every prompt.
Where the records live
Claude reads from your EHR or document system through a connector you control, scoped to the records a task needs, instead of staff uploading chart exports into chats.
Audit trail
Enterprise offers audit logs and a Compliance API for admins. Add your own log of what each connector read and wrote, kept somewhere staff can't edit.
Human review
Anything that goes into a chart, a claim or a message to a patient is reviewed by a person first. Your policies and training say so in writing.
Where Claude for Healthcare fits
Anthropic announced Claude for Healthcare on 11 January 2026, describing it as tools for providers, payers and health tech companies to use Claude "through HIPAA-ready products." It added connectors to the CMS Coverage Database, ICD-10 and the National Provider Identifier Registry, plus Agent Skills for FHIR development and prior authorization review. Those are reference data sources, and they don't contain your patients. The question this page answers still applies to everything else: your notes, your EHR and your intake forms go through a covered plan or they don't go through Claude.
If you're building a product rather than running a practice, the same rules apply one level down. Your app's calls to Claude need a HIPAA-ready API organization, and the rest of your stack needs its own BAAs. We covered that for the most common AI-built stack in is Supabase HIPAA compliant.
Frequently Asked Questions
Is Claude HIPAA compliant?
Claude can be used with protected health information on Anthropic's HIPAA-ready services under a signed Business Associate Agreement: Claude Enterprise with HIPAA activated by the organization's Primary Owner, and the first-party API in a HIPAA-ready organization. Free, Pro and Max are consumer plans, and Team is not named as a HIPAA-ready service, so they should not hold PHI. Even on a covered plan, some features are excluded from the BAA, and the practice is still responsible for its own policies, access and other vendors.
Can I use Claude Team with patient data?
No. Anthropic's BAA article names the first-party API and Enterprise plans as its HIPAA-ready services. Team isn't on that list. A practice that wants a shared Claude workspace for PHI needs a HIPAA-ready Enterprise organization, or a workflow built on the API under the BAA.
Is Claude Cowork covered by Anthropic's BAA?
No. Anthropic's BAA article lists Cowork as available to use but not covered under the BAA, and makes administrators who enable it responsible for how their workforce uses it. Keep PHI out of Cowork.
Is Claude Code HIPAA compliant?
Claude Code in the CLI and in the desktop app's local mode is covered by Anthropic's BAA only when zero data retention is enabled, and ZDR is available for qualified accounts. Without ZDR it can be used but isn't covered. Remote mode, Claude Code on the web, Code Review, Code Security, Computer Use and Remote Control aren't covered at all.
Are Claude connectors and MCP servers covered by the BAA?
The connector feature can be used in a HIPAA-ready organization, but data sent to third parties through connectors, MCP servers, Enterprise Search and Claude in Chrome isn't covered by Anthropic's BAA. Each system on the other end of a connector needs its own BAA with the practice, and the connector should be configured so it only reaches what it needs.
Does zero data retention mean nothing is stored?
Not quite. Anthropic says that under ZDR arrangements it still keeps User Safety classifier results to enforce its Usage Policy, and ZDR applies only to eligible APIs, products using a commercial API key, and Claude Code for Enterprise. Covered Models, which include Claude Fable 5 and 5.1, require at least 30 days of retention and can't run with ZDR.
Next step
If you want Claude connected to your EHR or practice system under the right BAAs, that's our healthcare AI integration work. If the plan, permissions and staff training are the open question, start with healthcare AI implementation.