Is Claude HIPAA compliant?
Yes on Claude Enterprise or the first-party API, once an organization owner has activated HIPAA compliance and accepted the agreement — consumer plans are not covered, and Anthropic excludes a long and specific list of features from the plans that are.
Applies to Claude Enterprise and the Claude API. Last reviewed against Anthropic's own documentation. Next review November 5, 2026.
Reviewed by Lisa Tran, CISSP — Healthcare Information Security Executive.
What you must do
- Use Claude Enterprise or the first-party API. Anthropic offers the agreement for its HIPAA-ready services, and the consumer plans are not among them.
- On Enterprise, the Primary Owner accepts the agreement directly while activating HIPAA compliance in organization settings, under Data and privacy.
- On the API it is not self-serve: the Primary Owner signs the agreement and then asks an Anthropic contact or its sales team to turn the configuration on.
- Check which version of the agreement you hold. Anthropic states that versions accepted after 2 December 2025 carry expanded Claude Enterprise coverage.
- If you were planning on zero data retention, you cannot have both: Anthropic states covered models require 30-day data retention and are not available with zero data retention enabled.
- Stay inside the covered features. On Enterprise those are chat, Projects, Artifacts, file creation and code execution excluding network access, voice, web search, Research and Skills.
- Treat prompts as disclosures of patient information, subject to the same minimum-necessary judgement as anything else you send outside the practice.
Does Claude sign a business associate agreement?
Yes. Anthropic offers one. Claude Enterprise, or the first-party API. Consumer plans are not covered. Enterprise: the Primary Owner accepts the agreement while activating HIPAA compliance in organization settings under Data and privacy. API: the Primary Owner signs, then contacts an Anthropic representative or the sales team to enable it.
What this means in practice
Anthropic publishes the most granular covered-and-excluded lists of any vendor on this site, which is helpful and also the thing that catches people out. The agreement is offered for the HIPAA-ready services — Claude Enterprise and the first-party API — and the consumer plans are simply not among them. Someone doing clinical work in a personal Claude account has nothing in place, exactly as with the consumer versions of Copilot and ChatGPT.
Where it is available, activation differs by product in a way worth knowing before you plan around it. On Enterprise the Primary Owner can accept the agreement themselves while switching HIPAA compliance on under Data and privacy — minutes, no sales conversation. On the API it is not self-serve: you sign, then ask Anthropic to enable the configuration, which is a scheduling problem if you have already committed to a date.
Two details deserve a note in your own records. Coverage changed on 2 December 2025, so the version of the agreement you hold determines what Claude Enterprise features it reaches — a year-old acceptance is not the same document. And zero data retention is not compatible with the covered models, which require 30-day retention; teams who assumed they could have both have to pick one.
How organizations get this wrong
The specific mistakes we see with Claude, not generic advice.
- Doing clinical work in a personal or consumer Claude account, which is outside the HIPAA-ready services entirely.
- Assuming the API is covered the moment the agreement is signed, when it also has to be turned on by Anthropic.
- Planning on zero data retention alongside the covered models, which Anthropic states are unavailable with it enabled.
- Using Claude in Chrome for something clinical — excluded by name, exactly as Gemini in Chrome is, and for the same reason.
- Relying on an agreement accepted before 2 December 2025 for the expanded Claude Enterprise coverage that came after it.
What the agreement does not cover
- Consumer Claude plans, which are not among the HIPAA-ready services the agreement is offered for.
- On Enterprise: Cowork, Claude Design (beta), the beta Claude for Office features, MCP connectors, Enterprise Search, and Claude in Chrome.
- On the API: the Batch API, Files API, Skills API, code execution, computer use and web fetch.
- On Claude Code: desktop remote mode, the web version, Review, Security, computer use and remote control. The Claude Code paths that are covered all require zero data retention.
Alternatives
Listed on merit. We take no payment for placement and use no affiliate links.
The other general assistant with a published list of HIPAA-eligible products
Covered by default inside a commercial Microsoft 365 tenant, with nothing to activate
Covered inside Google Workspace once an administrator accepts the agreement
Signing the agreement is step one. Proving it is step two.
Once you have the agreement with Claude, someone has to know it exists, where the copy is, when it needs revisiting and who owns it. That register is what a client's security questionnaire is actually asking about, and it is the section of an evidence pack most organizations cannot produce on request.
$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.
Sources
Every statement above comes from Anthropic’s own published documentation, read on the date shown.
- Business Associate Agreements (BAA) for Commercial Customers — Anthropic. No publication date given. Read August 10, 2026.
- What certifications has Anthropic obtained? — Anthropic. No publication date given. Read August 10, 2026.
Change history
- — First published.
This page is information, not certification and not legal advice. It reflects Anthropic’s published documentation as read on August 10, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.
Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.