Is Claude HIPAA Compliant?
Not the app your staff downloaded. But Claude has more BAA-covered routes into healthcare than almost any model, if you pick the right one.
The Verdict
No. Claude Free, Pro, Max, and Team cannot lawfully carry PHI. Anthropic's HIPAA settings cannot be enabled on those plans at all.
Yes, with conditions, on four routes that each carry a business associate agreement: Anthropic's HIPAA-ready API, HIPAA-ready Claude Enterprise, Claude through AWS Bedrock under the AWS BAA, and Claude through covered Google Cloud products under the Google BAA.
A training opt-out is not a BAA. SOC 2 and ISO 42001 are not a BAA. Verified 5 August 2026.
| Route | BAA | Trains on your data | Verdict for PHI |
|---|---|---|---|
| Claude Free, Pro, Max | No. HIPAA cannot be enabled | Yes, if the model improvement setting is on. Up to 5 years, de-identified | Never |
| Claude Team | No. HIPAA cannot be enabled | No. Commercial Terms bar training on Customer Content | Never, whatever the training policy says |
| Claude Enterprise, HIPAA-ready | Yes. Click-to-accept in org settings, Primary Owner only | No | Permitted, once enabled and configured |
| Anthropic API, HIPAA-ready organization | Yes. Self-serve in Claude Console, or a negotiated BAA through sales | No | Permitted, for eligible features only |
| Claude via AWS Bedrock | Yes, the AWS BAA. Anthropic's HIPAA readiness does not apply | No | Permitted, but check your model ID. See note below |
| Claude via covered Google Cloud products | Yes, the Google Cloud BAA. Anthropic's HIPAA readiness does not apply | No | Permitted only for named covered products |
| Claude in Microsoft Foundry | Not from Anthropic. Anthropic states HIPAA readiness is not available on Microsoft Foundry | No | Do not assume coverage. Resolve in writing first |
This is not legal advice, and your counsel makes the call for your organization.
The trap on Bedrock is in the model ID. AWS's HIPAA-eligible services list, updated 3 August 2026, reads: "Amazon Bedrock [excluding Fable and Mythos models]." Claude Fable 5 and Claude Mythos 5 are Anthropic's current generation, generally available since 9 June 2026. Read literally, AWS's own list puts the newest Claude models outside Bedrock's HIPAA eligibility. A 2025-era architecture decision that said "Bedrock is HIPAA-eligible, Claude is on Bedrock, done" does not survive a model upgrade. Check the exact model ID against the AWS list before it carries PHI, and re-check it after every upgrade.
The trap on Google Cloud is in the naming. Google Cloud's BAA covers named products, and "Vertex AI" by that name is not on the covered-products list. Vertex AI Workbench instances are, as are the Gemini Enterprise generative products. Match your exact workload to a named product. We wrote that up separately in is Google Vertex AI HIPAA compliant.
Does Anthropic Sign a BAA?
Six things a compliance officer needs on file before Claude touches PHI
Yes. Anthropic signs a business associate agreement on two of its own services, and since late 2025 you can execute it yourself without a sales cycle. The full procedure is six steps.
Confirm your plan can hold a BAA at all.
Only two Anthropic services are eligible: the HIPAA-ready Claude API and HIPAA-ready Claude Enterprise. Anthropic's own wording on the plan limit is flat: Team plans and individual plans, meaning Free, Pro, and Max, cannot enable HIPAA. There is no upgrade path and no add-on. A Team organization that needs PHI has to move to Enterprise.
Have the right person click it.
Enterprise: only the Primary Owner of the organization can accept the BAA and enable HIPAA. Other Owners and Admins cannot complete the flow on the organization's behalf. API: an organization admin holding the HIPAA management permission enables it in Claude Console under Settings, then Privacy. If your Primary Owner is a founder who left, fix that before you start.
Download both documents, then accept.
The flow makes you download the BAA and the HIPAA Implementation Guide before the accept button unlocks, and your enablement is bound to the exact BAA version you downloaded. Clicking "Accept and Enable HIPAA" is the signature. If a negotiated or custom BAA is required by your legal team, that path still exists through Anthropic sales.
Know that it is one-way and organization-wide.
Once HIPAA readiness is on, it is permanent and an administrator cannot turn it off. It is enforced at the organization level, and Anthropic's guidance is to run separate organizations if you need both HIPAA-ready and general-purpose access. This is a real architecture decision, not a checkbox, and it is the step teams get wrong.
Do not buy zero data retention thinking it is the compliance control.
It is a separate arrangement with a separate approval, and Anthropic states plainly that if your organization handles PHI, HIPAA readiness is the arrangement to use and you do not also need ZDR. Buying ZDR instead of a BAA is the same category error as buying a SOC 2 report instead of a BAA. The two also cover different feature sets: ZDR deletes, while HIPAA readiness protects data in place with encryption, access controls, and audit logging.
Keep the paper, not the screenshot.
For an audit file: the downloaded BAA at the exact version you accepted, the HIPAA Implementation Guide from the same download, the identity of the Primary Owner or admin who accepted and the date, the organization ID the setting applies to, and your own record of which features you permitted. Vendor attestations are not audit evidence. A queryable log is.
Inside the BAA, and outside it
Coverage is by feature, not by product. On HIPAA-ready Claude Enterprise, the covered surface is the working core: chat, projects, artifacts, voice, web search, research, and skills. On the HIPAA-ready API it is the Messages API and token counting, plus prompt caching, structured outputs, PDFs sent inline, thinking, and web search.
Outside the BAA: Workbench, Claude Console as a place to process PHI, Cowork, the Batch API, the Files API, the Skills API, code execution, computer use, web fetch, Claude Managed Agents, and beta features generally. Third-party integrations are outside it by definition. Anything you connect through MCP, a connector, or enterprise search moves data to a party Anthropic's BAA does not reach, and that becomes your administrator's problem.
Two mechanical details worth knowing before an architecture review. The API enforces this itself: send a non-eligible feature from a HIPAA-enabled organization and you get a 400 error naming the feature, rather than a silent disclosure. And if you use structured outputs or strict tool use, PHI must not appear in JSON schema definitions, including property names, enum values, and regex patterns, because schemas are cached separately and do not get the same protection.
One thing no arrangement removes: content flagged by Anthropic's automated trust and safety systems may be retained for up to two years, and legal holds override everything. Your BAA is the source of truth for what is covered, so read the version you downloaded against the lists above.
What Anthropic's Certifications Do and Do Not Cover
Anthropic holds real certifications and publishes them. As of a March 2026 update to its own compliance page: SOC 2 Type I and Type II, ISO 27001:2022, and ISO/IEC 42001:2023, the AI management system standard, certified by Schellman in January 2025. None of them lets you send PHI.
SOC 2 describes practice
A SOC 2 Type II report is an auditor's opinion that stated controls operated over a period. It describes how a company runs. Treating it as a BAA is the single most common substitution in healthcare AI procurement, which we argued at length in SOC 2 is not a BAA. The report creates no obligation to you, names no permitted uses of PHI, and gives you no breach notification right.
ISO 42001 governs the model, not your data
ISO/IEC 42001:2023 certifies an AI management system: policies, testing, monitoring, oversight. It is a genuinely useful signal about how a model developer behaves. It says nothing about your protected health information, because it is not a US healthcare instrument and was never written to be one. Anthropic's own certification announcement does not mention HIPAA. ISO 42001 is not a BAA is the longer version.
A BAA allocates liability
A business associate agreement is required by 45 CFR 164.502(e) before a covered entity may disclose PHI to a business associate. It binds the vendor to permitted uses, safeguards under 45 CFR 164.308(b), subcontractor flow-down, breach notification, and return or destruction at termination. It is enforceable by you and by OCR. No volume of controls produces one. Somebody has to sign.
Ask what happens after a breach
Run every attestation through one question: if this vendor discloses our PHI improperly, what does this document require them to do, and what can we do about it? That question is why the answer to "are they SOC 2 compliant" is never the answer to "can we send PHI." A SOC 2 report answers "nothing." An ISO certificate answers "nothing." A BAA answers with a notification clause and a remedy.
The Question Behind the Question, Whose BAA?
Four realities that decide whether a Claude deployment carries PHI legally
A BAA follows the deployment, not the model
"Claude" is one model with at least three contractual routes. The BAA you need is with whoever operates the service your data touches: Anthropic directly, AWS, or Google.
Chained vendors need chained agreements
If you buy a product that uses Claude underneath, your BAA is with that product's vendor, and their BAA with their model provider is their obligation. Ask for evidence of the full chain.
Consumer settings are not contracts
A staff member who opted out of training on a personal Claude account is still outside any BAA. Opt-outs are privacy preferences; HIPAA requires paper.
The commercial no-training default is real but scoped
Anthropic excludes commercial data from training. Confirm which of your account types count as commercial, in the agreement.
Is Claude HIPAA Compliant Because HHS Uses It?
No. A federal agency's own arrangement creates no business associate relationship for your organization. Whatever HHS signed, it is HHS's paper. Yours does not exist until you sign it.
The underlying story has also turned over twice, which is a useful lesson on its own. Anthropic's Claude for Government was made available across the Department of Health and Human Services in December 2025. In March 2026, HHS disabled employee access after the administration designated Anthropic a supply chain risk, alongside similar moves at Treasury and State. Neither event changed a single word of HIPAA.
Federal adoption was never the signal buyers thought it was. Government deployments run on a different authorization track, FedRAMP, which is a federal security authorization, not a HIPAA instrument. HHS in its capacity as a federal agency is not the same actor as a hospital in its capacity as a covered entity. And an agency's contract vehicle is not available to you. If a vendor's healthcare evidence is "a federal agency uses us," you have been handed a logo, not a control.
Ask this instead: can this vendor sign a BAA with us, on the plan we are on, for the features we will use? That is the only sentence in this section your risk register can use. For Claude, the answer is yes on two Anthropic services and no on the rest.
Your Staff Are Already Using Claude
Every route above assumes the person using Claude is inside an account you control. Most of the time, they are not.
A nurse manager pastes a discharge summary into Claude on her own phone to turn it into plain language for a family. A revenue cycle analyst drops a denial letter into a personal Pro account to draft the appeal. A physician uses Claude to rewrite a referral note at 11pm.
None of them are being careless.
Claude is good at exactly the work they are drowning in, and it took ninety seconds to sign up.
That use sits outside every agreement on this page. A personal account cannot be brought inside a BAA retroactively, the org-level HIPAA setting does not reach it, and the training opt-out that person may have toggled is a privacy preference. Your Enterprise agreement covers your Enterprise organization. It does not cover the app on their phone.
Those personal Claude accounts are shadow AI, and it is the part of this problem a per-tool verdict does not solve. Picking the right Claude route is necessary. It is not sufficient, because the people already using the wrong one never asked which route you picked.
Shadow AI is a governance gap. The fix is a sanctioned path that is as fast as the unsanctioned one, plus a policy that names which Claude route is approved and for whom.
Claude is one entry in a longer list of AI tools healthcare organizations are already running without a paper trail. For the fuller HIPAA and AI compliance picture, across every tool your staff might already be using, see HIPAA and AI compliance.
Claude and HIPAA: Common Questions
Does Anthropic sign a BAA?
Yes, on two services: the HIPAA-ready Claude API and HIPAA-ready Claude Enterprise. Both are now self-serve. The Enterprise Primary Owner accepts a click-to-accept BAA in organization settings; an API admin executes the standard BAA in Claude Console under Settings, then Privacy. A negotiated BAA is still available through sales. Free, Pro, Max, and Team cannot enable HIPAA at all, and Workbench, Console-as-a-workspace, Cowork, and beta features sit outside the agreement.
Is Claude Pro HIPAA compliant?
No. Pro is a consumer subscription with no BAA path, and Anthropic's HIPAA setting cannot be enabled on it. The subscription price does not change its status, the same pattern that holds across consumer AI subscriptions in general, including ChatGPT.
Does Claude train on our conversations?
It depends on the account, and the split is the whole point. Consumer accounts, meaning Free, Pro, and Max, are used for model improvement only if the user turns that setting on; with it on, data may be retained de-identified in training pipelines for up to five years, and with it off the standard thirty-day deletion applies. Commercial accounts, meaning the API, Team, Enterprise, and Education, are covered by Anthropic's Commercial Terms, which state that Anthropic may not train models on Customer Content. The consumer default is exactly why personal accounts and PHI cannot mix.
Is Claude through AWS Bedrock HIPAA compliant?
Yes, with a caveat that is new in 2026. Bedrock is a HIPAA-eligible AWS service and under an AWS BAA it can serve PHI workloads. But AWS's eligible-services list, updated 3 August 2026, excludes Fable and Mythos models from that eligibility, which covers Anthropic's current model generation. Check your exact model ID against the AWS list, not the service name, and re-check after every model upgrade. Note also that Anthropic's own HIPAA readiness does not extend to Bedrock; on Bedrock, AWS is the data processor and the AWS BAA is your instrument.
Which path should a hospital pick?
If you are building, Bedrock or a covered Google Cloud product, because cloud BAAs and audit tooling are mature. If you are buying staff access, a governed platform that carries the BAA chain and gives you org-wide logging, rather than direct consumer or single-seat accounts.
Does Anthropic sign a BAA, and how do I get one?
Yes, and you can do it yourself in an afternoon. On Claude Enterprise, the Primary Owner opens organization settings, downloads the BAA and the HIPAA Implementation Guide, and clicks Accept and Enable HIPAA; that click is the signature. On the API, an admin with the HIPAA management permission does the same in Claude Console under Settings, then Privacy. Your enablement is bound to the exact BAA version you downloaded, so keep that file. Enablement is permanent and applies to the whole organization, which is why teams that need both PHI and general workloads run two organizations.
Is Claude Enterprise HIPAA compliant?
Yes, once HIPAA is enabled on it, and not before. Claude Enterprise is the only Claude chat product Anthropic will cover with a BAA. Only the Primary Owner can turn it on, other Owners and Admins cannot, and the switch cannot be reversed by an administrator afterwards. Enabling it also narrows what the plan can do: Cowork is not covered, Claude Code requires a separate zero data retention arrangement to be covered, and third-party connectors move data outside the agreement. An Enterprise seat with HIPAA switched off is exactly as compliant as a Pro seat, which is to say not at all.
Is Claude Team HIPAA compliant?
No, and it cannot be made compliant. Anthropic's own wording is that Team plans and individual plans cannot enable HIPAA. Team is a commercial plan, so your data is not used for training, which helps with confidentiality, but it is not the same instrument and it does not permit PHI. Anthropic has no Team-level BAA and no exception process. A Team organization that needs PHI moves to Enterprise, or moves the workload to the API.
Does HHS using Claude make it HIPAA compliant?
No. A federal agency's arrangement is not your arrangement, and no covered entity inherits a business associate relationship from someone else's contract. Claude for Government reached HHS in December 2025 and HHS disabled access in March 2026 after the administration designated Anthropic a supply chain risk, which is a good illustration of how little a reference deployment guarantees. Ask instead whether the vendor will sign a BAA with your organization, for the features you plan to use.
Is SOC 2 or ISO 42001 enough for PHI?
No. Anthropic holds SOC 2 Type I and Type II, ISO 27001:2022, and ISO/IEC 42001:2023, and none of them permits a disclosure of protected health information. An attestation describes how a company operates; a BAA allocates liability and is required by 45 CFR 164.502(e) before PHI may be disclosed at all. The test is what happens after a breach: a SOC 2 report obliges the vendor to nothing, a BAA obliges them to notify you. SOC 2 is not a BAA, and neither is a DPA, an ISO certificate, or a compliance-automation validation report.
Is this legal advice?
No. This is not legal advice, and your counsel makes the call for your organization.
Related Reading
AI Tool HIPAA Compliance Directory
BAAs, training policies, and verdicts for the AI tools your staff actually use, in one place.
Read article →Is ChatGPT HIPAA Compliant?
Consumer, Plus, Team, and Enterprise tiers each answer differently.
Read article →Is Gemini HIPAA Compliant?
Google's consumer, Workspace, and Vertex AI postures are three different answers.
Read article →Is Copilot HIPAA Compliant?
The assistant most hospitals already have deployed, and the tenant settings that decide the answer.
Read article →Is Google Vertex AI HIPAA Compliant?
Google's BAA covers named products, and "Vertex AI" by that name is not one of them.
Read article →One Model, Three Contracts, Zero Shortcuts
Before any Claude path carries PHI, your policy needs to name which one is sanctioned and for whom. Generate a healthcare-ready draft in minutes.