A plain-language review of Anthropic's Business Associate Agreement and HIPAA implementation rules for medical and behavioral health practices and health systems. Last reviewed: August 22, 2026.
Key takeaways
- A Claude BAA is never on by default. Anthropic offers one for only two of its products, Claude Enterprise and its developer platform, and coverage starts only after an administrator turns on the HIPAA configuration and accepts the agreement. Even then, features like Cowork and Claude in Office stay outside it, and Claude Free, Pro, Max, and Team cannot be covered at all.
- Coverage depends on your signature date. Older BAAs cover less, and features released after you signed can require an amended or re-executed agreement before PHI touches them.
- Anthropic's BAA protects patient data only when it is handled exactly by the rules in a 14-page guide, and Anthropic can rewrite those rules at any time without telling you.
- Even covered features can leak. Web search sends query content to outside search providers, relying on automated filtering to strip identifying details first. No automated de-identification is perfect, so a large health system running thousands of searches a day may be sending PHI to companies outside your BAA, with each slip a potential reportable breach.
- Even with a BAA, Claude is restricted where many workflow builders in healthcare might expect it: patient communication is barred outright.
- The configuration, training, and monitoring burden sits with the customer. Purpose-built healthcare AI products like BastionGPT provide access to Anthropic's AI models but come with that work already done, so you do not have to take it on yourself.
Does Anthropic sign a BAA for Claude?
Yes, and getting one has never been easier, which is part of the problem. Anthropic publicly offers a BAA covering its HIPAA-ready services: Claude Enterprise and its developer platform (the API that companies use to build software on Claude). On Enterprise, a primary owner can enable a HIPAA configuration in the organization settings and accept the BAA in a click-to-accept flow, with no negotiation and no signature cycle. Anthropic's help center is clear about who is left out: "Team plans and individual plans (Free, Pro, and Max) can't enable HIPAA."
That convenience is exactly why healthcare organizations should slow down. This article reviews the two documents that govern PHI in Claude: Anthropic's Business Associate Addendum (the version provided to customers as of August 19, 2026) and its 14-page HIPAA-Configuration Implementation Guide (dated July 16, 2026). They leave far more of the compliance work with you than the marketing suggests. Here is what to understand before any protected health information (PHI) touches Claude. (For the quick verdict on the consumer apps, see our companion guide: Is Claude HIPAA compliant?.)
Which Claude products does the BAA cover?
The BAA applies only to "eligible services," which Anthropic's public documentation identifies as Claude Enterprise and the developer API. Everything else in the Claude ecosystem sits outside the agreement, including the consumer Free, Pro, and Max plans and the Team plan.
Within HIPAA-ready Enterprise itself, Anthropic's help center explains that features fall into three categories: covered by your BAA, available but not covered, and disabled. The middle category is the trap. Anthropic publicly names exclusions such as Claude Cowork and beta features like Claude in Office and Claude Design, and the gated implementation guide adds more: connectors that send data to outside tools, the Claude in Chrome browser extension, and Claude Code (Anthropic's programming tool) are outside the BAA or covered only in narrow configurations. On the developer side, Anthropic publishes a feature-by-feature eligibility table; several API features are excluded outright.
The available-but-not-covered features are one toggle away. They ship disabled for new HIPAA-ready customers, but administrators can enable them in the admin console, and responsibility for what happens next belongs to the customer. A single admin action can quietly route PHI outside your BAA. The reverse surprises buyers too: turning the HIPAA configuration on switches those features off for every user, and a few, like the Web Fetch tool and several developer features, become permanently unavailable.
Cowork, Anthropic's agentic desktop product, deserves its own caution. Anthropic says plainly that it is not yet covered under the BAA, and the implementation guide warns against using it for regulated workloads at all. Per the guide we reviewed, its activity does not show up in audit logs, compliance reporting, or data exports, and Compliance API coverage for Cowork is only now arriving in beta. If staff use it with PHI, you may have no record of what happened.
The warranty that should scare your lawyers
The BAA does not stand alone. It binds your organization to the 14-page implementation guide, and the customer-obligations section of the version we reviewed contains the most consequential language in either document: the customer represents and warrants that anything submitted or used out of line with that guide is not PHI.
If a staff member pastes patient data into a non-compliant feature, field, or configuration, your organization has already warranted, in writing, that the data is not PHI. A contract cannot actually strip data of its status under HIPAA, and the BAA elsewhere requires ambiguities to be read in favor of compliance. The bite is contractual. You are in breach of your own warranty, and you can no longer count on the BAA's protections for that data: Anthropic has a ready argument that its obligations never attached. All of this lands at the same moment you may be managing an impermissible disclosure. The same section puts configuration and day-to-day usage choices squarely on the customer, and Anthropic's public guidance repeats the point that PHI belongs only in covered features.
The guide you are warranting compliance with is also a moving target. The BAA binds you to the guide as Anthropic updates it, the guide says its requirements may be revised over time, and the version we reviewed had already been updated since its initial release. Your compliance obligations can change without your signature. Nothing in either document commits Anthropic to email you or otherwise flag a change; it only has to make the current copy available. Monitoring for revisions is your job. Pull your own copy of the current BAA and guide from the enablement flow and have counsel read them before anyone clicks accept. Acceptance is also one-way: Anthropic's public documentation notes that once HIPAA readiness is enabled, an administrator cannot disable it. A hasty click permanently locks in the standard terms, and the feature restrictions that come with the HIPAA configuration, for that organization.
Not cleared for patient care
Despite the healthcare branding, the implementation guide restricts clinical use. Its guidance is that the covered services should not be used for diagnosis, treatment, or direct patient interactions; should is the guide's word, a caution rather than an outright ban. Two things are barred outright: communicating with patients, family members, plan members, or employers through the services, and adding any of those people as users or guests.
For the clinical-adjacent work Anthropic markets, which the guide describes in terms of billing, coding, charting, claims work, and clinical research, three duties land on you first: test the services for accuracy in your own use cases, confirm the use complies with applicable law, and ensure the people doing that work are trained and hold whatever licenses or certifications it requires. These are reasonable requirements. They are also entirely your burden, and they attach to exactly the use cases Anthropic advertises.
There are field-level rules, too. The guide permits PHI in chats, attachments, artifact content, and project names, but prohibits it in user profile fields, skill names, workspace names, and billing fields. PHI that lands in a prohibited field falls outside HIPAA-compliant processing. Expecting busy staff to remember which text boxes are PHI-safe is a real training and auditing burden, and it falls hardest on small practices.
The short version: a signed BAA is where the compliance work starts. If you want the power of Anthropic's AI models without staffing a team of compliance experts, that is the problem BastionGPT was built to solve. See how BastionGPT handles this for you.
How quickly must Anthropic report a breach?
The BAA we reviewed commits Anthropic to report a breach promptly, with an outer limit of ten business days after discovery. That fits comfortably inside HIPAA's sixty-day ceiling for business associates under 45 CFR 164.410, but ten business days is two calendar weeks. Your own notification deadlines generally start when you learn of a breach rather than when your vendor does, unless regulators treat the vendor as your agent, in which case its discovery date becomes yours. Either way, every day a vendor holds a breach is a day of patient exposure you cannot act on, and once notice arrives, California clinics and health facilities owe the state health department and affected patients notification within fifteen business days of detection under Health and Safety Code section 1280.15. In our experience, provider-side counsel push for notice within five business days or less in the BAAs they sign downstream.
Retention, records, and audit gaps
Several provisions matter for records management and oversight:
Claude cannot be a system of record. Under the BAA, Anthropic keeps no Designated Record Set on your behalf, and you must keep your own copy of everything sent.
Retention runs on Anthropic's terms, not the BAA. Prompts and outputs are retained under the standard commercial terms rather than anything negotiated in the BAA. Enterprise plans include some retention controls, but the terms govern the edges: Anthropic's public documentation notes that content flagged by safety systems can be kept for up to two years.
Exit is on their terms. You get thirty days to export data after termination. After that, getting data back or destroyed happens if Anthropic deems it feasible; where destruction is infeasible, Anthropic keeps the data under the BAA's protections instead.
Audit logs have a one-year ceiling. The guide describes audit log retention as capped at one year, while HIPAA requires you to retain compliance documentation for six years (45 CFR 164.316). Continuous log export is mandatory in practice.
Monitoring is self-serve. Anthropic provides a Compliance API, with coverage of newer products like Cowork still in beta, and expects customers to build their own monitoring and data loss prevention on top of it. The BAA itself grants no customer audit rights; it makes records available to the HHS Secretary, not to you.
Role-based access controls have gaps. Per the guide, permissions accumulate across group memberships, and some features cannot be governed by custom roles at all. Any such feature enabled for anyone is enabled for everyone, PHI handlers included; the only complete wall is leaving it off for the whole organization.
Where your data can still go
Anthropic's commercial terms state that Anthropic may not train models on customer content. For healthcare buyers, that is the right baseline.
The exceptions, described in the implementation guide and Anthropic's data-handling pages, still belong in your risk analysis:
- Anthropic can use limited customer content, and that includes PHI you have submitted, to support its trust and safety controls and to perform debugging and support work on its platform.
- Organization-level product improvement means PHI can be indexed and processed to tailor features for your organization.
- Zero Data Retention (ZDR) is not absolute. Anthropic's public documentation notes that safety classifier results are retained, that retention can occur where required by law or to enforce its usage policy, and that flagged content can persist for up to two years.
- Anthropic has not signed sub-BAAs with the third parties behind Enterprise Search connectors. If you enable connectors, obtaining BAAs from those vendors is your responsibility.
- Anthropic's newest models, Claude Fable 5 and Claude Mythos 5, require thirty-day data retention and are not available with ZDR, per Anthropic's public documentation. Customers whose BAA coverage depends on ZDR cannot use the newest models with PHI.
Web search shows how a covered feature can still leak
Web search is a covered feature under the HIPAA configuration, and it is also the clearest example of why covered does not mean risk-free. When a chat triggers a search, some query content travels to outside search providers that are not party to your BAA. Anthropic's control is automated: identifying details are designed to be detected and stripped before the query leaves. No automated de-identification is perfect, and at the scale of a large health system, thousands of searches a day, even a small failure rate would mean PHI reaching outside companies again and again. Each slip is a potential impermissible disclosure, which HIPAA presumes to be a reportable breach unless your risk assessment shows otherwise.
Your signature date decides your coverage
Coverage also depends on when you signed. Per the implementation guide's version table:
- BAAs signed before December 2, 2025 cover only the developer API with ZDR enabled, and no other surfaces.
- Later signatures add Claude Enterprise (chat, projects, artifacts, and related features) under the HIPAA configuration, plus, for qualified accounts, Claude Code with ZDR.
- From April 1, 2026 onward, new BAAs add HIPAA-configuration coverage for the API and certain API features that do not require ZDR.
If a feature postdates your BAA signature, expect to amend or re-execute the agreement before PHI touches it. Anthropic's public docs describe the same mechanics: enablement binds you to the specific BAA version you download. An organization that signed in 2025 and assumes this year's features are covered is simply wrong.
What to do before you click accept
For health systems: the self-serve BAA is take-it-or-leave-it. Anthropic's help center describes it as a standard agreement that cannot be modified; negotiated or custom terms go through Anthropic's sales team. And acceptance cannot be undone, so if you want modified terms, do not click accept at all. Route through your Anthropic account team first and ask for faster breach notice (five business days or less, tighter where state law demands it), softening of the not-PHI warranty, advance notice of implementation guide changes, audit rights or third-party assurance reports, and indemnification or breach-cost coverage. Before go-live, disable every non-covered feature, restrict admin console rights, and stand up compliance log export and monitoring. Track your BAA signature date against the guide's version table.
For smaller practices: assume you will get these documents as-is. The compliance program they presuppose, including workforce training on PHI-eligible fields, locked-down configurations, exported audit logs, documented accuracy testing, and licensed-user restrictions, is yours to build and evidence. Our guide to what makes an AI tool HIPAA compliant walks through the criteria. If that is not realistic, the guide itself offers the honest alternative: organizations that cannot comply should not provide any PHI to the services.
The simpler way to use Claude in healthcare
Everything above is the vendor-side configuration work BastionGPT does so healthcare teams do not have to.
BastionGPT is a secure AI assistant built for healthcare, serving medical and behavioral health practices since 2023. It works with leading AI models, including licensed access to Claude, inside a platform where the platform-side compliance work is already done:
- A BAA comes with every plan, including the free trial. No enterprise sales cycle, no minimum seat counts, no negotiation queue. Plans start at $20 per user per month.
- No configuration project. The feature restrictions, data controls, and safeguards described in this article are handled at the platform level. There is no HIPAA configuration to get wrong and no implementation guide to police.
- Built for healthcare work. Notes, letters, coding support, and administrative tasks, with a library of documentation templates designed for real workflows.
- Your data stays yours. PHI is never used to train AI models, and it stays in a private, isolated environment. Read more on our security page.
- Proven at scale. More than 10,000 healthcare organizations use BastionGPT.
BastionGPT takes on the AI-specific configuration and monitoring burden described above; your organization keeps its usual HIPAA duties, such as workforce training and risk analysis.
Start your 7-day free trial. The BAA is included from day one.
Frequently asked questions
Does Anthropic sign a BAA for Claude?
Yes, but only for Claude Enterprise with the HIPAA configuration turned on, and for Anthropic's developer platform (its API). An Enterprise primary owner can accept the BAA in a self-serve, click-to-accept flow. Consumer plans (Free, Pro, Max) and the Team plan cannot enable HIPAA coverage.
Is the free or Pro version of Claude HIPAA compliant?
No. Anthropic does not offer BAA coverage for Claude Free, Pro, or Max, so entering PHI into those products is an impermissible disclosure under HIPAA. Turning off training or chat history in the app's settings does not change that, because no business associate agreement exists for those plans.
Can I use Claude Team with PHI?
No. Anthropic's help center states that Team plans cannot enable HIPAA, and the same is true of individual plans. Organizations that want BAA-covered chat access from Anthropic must move to HIPAA-configured Claude Enterprise, or use a healthcare platform that provides its own BAA.
Does Anthropic train Claude on PHI?
Anthropic's commercial terms state that it may not train models on customer content, PHI included. Narrow exceptions allow use of customer content for trust and safety controls, support, and organization-specific product improvement, which is why the details still belong in your risk analysis.
Can doctors use Claude to diagnose patients?
Not according to Anthropic. Its implementation guide says the covered services should not be used for diagnosis, treatment, or direct patient interactions, even under a signed BAA, and it bars patient communication outright. Clinical-adjacent work like coding and charting carries added duties: accuracy testing, legal confirmation, and appropriately licensed users.
What happens if staff paste PHI into regular Claude?
PHI entered into a product with no BAA in place is an impermissible disclosure, and it can trigger breach analysis, notification duties, and penalties. The practical fixes are workforce training, blocking unapproved AI tools, and providing a compliant alternative like BastionGPT that staff actually want to use.
Does Claude web search send PHI to third parties?
Web search is covered under Anthropic's BAA, but query content travels to outside search providers that are not party to your BAA. Identifying details are stripped by an automated filter that is designed, not guaranteed, to catch them. If PHI slips through, you are facing a potential reportable breach.
What is the fastest compliant way to use Claude in healthcare?
A healthcare AI platform with a BAA included is the fastest route. BastionGPT works with leading models, including Claude, inside a HIPAA-compliant assistant. A BAA comes with every plan, including the free trial, there is no configuration project, and more than 10,000 healthcare organizations already use it.
The bottom line
While Anthropic's HIPAA paperwork can be serviceable if your legal team is willing to accept the risk, Anthropic defines what is covered, updates the definitions over time (with no obligation to notify you), and assigns responsibility for everything outside that scope to the customer. These documents will protect the organizations that read them, and that have trained staff with time to configure them accordingly. For everyone else, the most dangerous feature of the product may be the one-click button that accepts the BAA without understanding all the risks that they are exposed to.
This article is general information, not legal advice. It reflects the author's August 2026 review of Anthropic's Business Associate Addendum (the version provided to customers as of August 19, 2026) and HIPAA-Configuration Implementation Guide (dated July 16, 2026), alongside Anthropic's public documentation. Those documents may have changed since; the current versions on Anthropic's Trust Center control. Consult qualified counsel before executing a BAA or processing PHI in any AI service. BastionGPT is a product of Bastion Intelligence and is not affiliated with or endorsed by Anthropic, PBC; product names are used for identification only.
Sources (click to expand)
- Anthropic Privacy Center, "Business Associate Agreements (BAA) for Commercial Customers": privacy.claude.com/en/articles/8114513
- Anthropic Help Center, "HIPAA-ready Enterprise plans": support.claude.com/en/articles/13296973
- Anthropic Help Center, "Covered Models under a Business Associate Agreement (BAA)": support.claude.com/en/articles/15455031
- Anthropic Platform Docs, "API and data retention" (ZDR, HIPAA configuration, feature eligibility): platform.claude.com/docs/en/manage-claude/api-and-data-retention
- Anthropic, "Advancing Claude in healthcare and the life sciences" (Jan 2026): anthropic.com/news/healthcare-life-sciences
- Anthropic Commercial Terms of Service (confidentiality, publicity, liability, training): anthropic.com/legal/commercial-terms
- Anthropic HIPAA-Configuration Implementation Guide, via Anthropic Trust Center (access request required): trust.anthropic.com
- 45 CFR 164.410 (business associate breach notification): law.cornell.edu/cfr/text/45/164.410
- 45 CFR 164.316 and 164.530 (six-year documentation retention): law.cornell.edu/cfr/text/45/164.316
- Cal. Health & Safety Code 1280.15 (15-business-day notification): leginfo.legislature.ca.gov
