Is Claude HIPAA compliant?
No, Claude is not HIPAA compliant by default. Anthropic offers a Business Associate Agreement that covers only its HIPAA-ready services, which means Claude Enterprise after the organization's Primary Owner activates HIPAA compliance and accepts the BAA, and the first-party Claude API once Anthropic enables it on a HIPAA-ready organization. The Free, Pro, Max, and Team plans have no BAA path, so protected health information should not go into them. Even with a BAA in place, only specific listed features are covered, and the practice remains responsible for how its staff actually use the tool.
Which Claude plans can be covered by a BAA
Anthropic does offer a Business Associate Agreement, but it applies only to what Anthropic calls its HIPAA-ready services. On Claude Enterprise, coverage is not automatic and it is not something a sales conversation quietly turns on for you. The organization's Primary Owner has to activate HIPAA compliance in the organization settings under Data and privacy and accept the BAA. Anthropic states plainly that a standard Claude Enterprise plan does not include BAA coverage without that action from a Primary Owner.
For the first-party Claude API, Anthropic's documentation says the Primary Owner needs to sign a BAA and then contact Anthropic or its sales team to have it enabled on the organization. The BAA also covers only the single organization that accepted it, so a second workspace is not automatically in scope.
The consumer plans are a different product line with no BAA path at all. This is the part that catches real practices: if the front desk is doing its work in a personal Pro login, that account cannot be brought under a BAA later, and no setting inside it changes that.
Claude is also available through cloud platforms such as AWS Bedrock and Google Cloud Vertex AI. Those run under that provider's own agreements rather than Anthropic's BAA, so eligibility there is a question to put to that provider directly.
- Claude Enterprise: BAA available, but only after the Primary Owner activates HIPAA compliance and accepts the BAA
- First-party Claude API: BAA available on a HIPAA-ready organization, which Anthropic has to enable
- Claude Free, Pro, and Max: consumer plans, no BAA available, no protected health information
- Claude Team: not listed among the covered surfaces in Anthropic's BAA article and not a HIPAA-ready service
- Claude via AWS Bedrock or Google Cloud Vertex AI: governed by that cloud provider's paperwork, not Anthropic's BAA
What the BAA covers, and what it leaves out
A signed BAA does not put a blanket over every feature. Anthropic publishes a feature by feature breakdown, and the exclusions are the part worth reading before anyone assumes a workflow is in scope. On a covered Enterprise organization, core chat, Projects, Artifacts, Voice, web search, Research, and Skills are listed as eligible services. File creation and code execution are eligible except for network access and use of external websites.
Several things are explicitly outside it. Cowork is not covered. Claude Design and the Claude for Office betas are not covered. Workbench and the Claude Console are excluded. Connectors, MCP servers, Enterprise Search, and Claude in Chrome remain usable, but Anthropic is direct that data sent to third parties through those features is not covered by its BAA, and that the administrator who enables them owns that risk.
On the API side, the Messages API is covered along with a named set of features. The Batch API, Files API, Skills API, code execution, computer use, and web fetch are not covered and are not accessible to HIPAA-ready API users. Claude Code is covered only with zero data retention enabled, and several Claude Code surfaces, including desktop remote mode and the web and review betas, are not covered at all.
Anthropic's own tables carry effective dates tied to when a BAA version was accepted, which tells you this list moves. Read the live article rather than trusting any copy of it, including this page.
What a BAA requires, and what stays your responsibility
A BAA is the contract HIPAA requires before a covered entity lets an outside party create, receive, maintain, or transmit protected health information on its behalf. The required terms are set out in 45 CFR 164.504(e). The business associate has to limit uses and disclosures to what the contract permits, apply appropriate safeguards and comply with the Security Rule for electronic PHI, report any use or disclosure the contract did not provide for including breaches of unsecured PHI, push the same obligations down to subcontractors, make PHI available for individual access and amendment and for an accounting of disclosures, open its relevant records to HHS, and return or destroy PHI at termination where that is feasible. The contract also has to let the covered entity terminate for a material breach.
Here is the part vendors tend to skip. Signing a BAA covers the vendor's obligations. It does not make your practice compliant. Your risk analysis, workforce training, access controls, minimum necessary policy, and audit practices are still yours. A BAA also cannot physically stop a team member from pasting a chart note into an uncovered feature or into a personal account, which is where most real exposure in a small practice comes from.
This page is not legal advice. Anthropic's documentation tells you what the product does and which surfaces it will stand behind. Whether a specific workflow is permissible in your practice is a decision for your HIPAA compliance officer or your attorney, and they are the ones who should review and sign anything.
What a practice can do with Claude without a BAA
Without a BAA the rule is simple: no protected health information goes in. That sounds limiting until you look at how much of the writing in a dental or medical practice has no patient identifiers in it at all. Most of the administrative load is templates, policies, and explanations, and none of that requires a real patient.
One trap worth naming directly. Replying to an online review feels like marketing, but confirming publicly that a named person is a patient is itself a disclosure. Keep public responses generic and move any specifics to a private channel.
- Draft and rewrite patient-facing templates: post-op instructions, recall and reactivation letters, financial policy explanations, new patient welcome packets, all written generically
- Translate a clinical or insurance concept into plain language a patient can actually read
- Write and edit internal SOPs: opening and closing checklists, sterilization workflow documentation, phone scripts, hygiene handoff procedures
- Build job descriptions, interview question sets, onboarding plans, and review structures for front desk and clinical roles
- Write service pages, newsletters, and marketing copy that contains no detail identifying a patient
- Think through a scheduling or staffing problem in the abstract, describing roles and volumes rather than named people
- Summarize published clinical guidance, payer policy documents, or vendor contracts you already have the right to read
De-identification in practical terms
HHS recognizes two ways to de-identify health information. Expert determination has a qualified person apply statistical methods, conclude the re-identification risk is very small, and document the analysis. The Safe Harbor method removes the 18 categories of identifiers listed in 45 CFR 164.514(b)(2). For a practice without a statistician on staff, Safe Harbor is the workable one.
Two conditions are what make casual scrubbing fail. First, Safe Harbor also requires that the covered entity not have actual knowledge that the remaining information could still identify someone. In a small practice that condition does real work: a note describing the patient in her eighties who came in the morning after the fire can name nobody and still point at exactly one person. Second, HHS guidance treats parts and derivatives of those identifiers as identifiers too, so initials and partial dates do not clear the bar.
Be clear-eyed about where this breaks. Hand de-identifying a record, under time pressure, at a busy front desk, is the step that fails. If a workflow only becomes useful with real patient data in it, treat that as a signal to move onto a covered surface with a BAA in place rather than to get better at scrubbing. And again, your compliance officer or counsel makes that call, not a vendor and not this page.
- Names, including names of relatives, employers, and household members
- Any geographic subdivision smaller than a state, including street address, city, county, precinct, and ZIP code, with a narrow exception for the first three ZIP digits when that area holds more than 20,000 people
- All elements of dates except year that relate to the individual, including birth, admission, discharge, and death dates, plus all ages over 89
- Telephone numbers, fax numbers, and email addresses
- Social Security numbers, medical record numbers, health plan beneficiary numbers, account numbers, and certificate or license numbers
- Vehicle and device identifiers and serial numbers, including license plate numbers
- Web URLs and IP addresses
- Biometric identifiers, including fingerprints and voice prints
- Full face photographic images and any comparable images
- Any other unique identifying number, characteristic, or code
Sources
Policies and product details change. Check the source rather than trusting this page indefinitely.
- Anthropic: Business Associate Agreements (BAA) for Commercial Customers
- Anthropic: zero data retention scope, and BAA availability limited to HIPAA-eligible services
- HHS: Guidance Regarding Methods for De-identification of Protected Health Information
- 45 CFR 164.514: de-identification standard and the Safe Harbor identifier list
- 45 CFR 164.504(e): required terms of a business associate contract
- HHS: Business Associate Contracts, sample provisions
Need to send this to someone else?
I will email you this answer with every source linked, so it stands up when it lands in front of IT, legal, or finance. Plus the questions that usually come next. Unsubscribe any time.
Want to know what Claude can actually do in your business?
Four questions, about a minute, and Claude writes three automations for your specific situation with the exact prompts. No account.
Build my plan