More on the topic...
Generating detailed summary...
Failed to generate summary. Please try again.
Anthropic lets qualifying commercial customers sign a Business Associate Agreement (BAA) that covers HIPAA-ready services on its Claude for Work and Anthropic API products. Under the BAA, core chat features—like chat history (“Projects”), saved outputs (“Artifacts”), voice, web search, and research—are fully covered. File creation and code execution count as covered too, but you can’t reach external networks or websites. On the API side, the Messages API (with prompt caching, structured outputs, memory, web search, Bash and text-editor tools), plus the Token Counting, Models, Org Management and Compliance APIs, all fall under the BAA.
Several features remain off-limits. Third-party integrations—MCPs/Connectors, Enterprise Search (“Ask Your Org”), and Claude in Chrome—can be enabled but any data sent outside Anthropic isn’t covered. Beta features like Cowork and Claude for Office (Excel, PowerPoint) are also excluded. On the Claude Code front, only the CLI tool with Zero-Data-Retention (ZDR) enabled is covered, and only for accounts that qualify. The web, desktop, review and security betas for Claude Code don’t support ZDR and sit outside the BAA.
Other API endpoints aren’t protected either. The Batch API, Files API (beta), Skills API (beta), Code Execution, Computer Use (beta), Web Fetch and any External MCP calls fall outside the BAA’s scope. If your team needs PHI handling with unsupported features, you’ll have to work out additional data-handling safeguards. To get started on the BAA, Anthropic asks you to submit deployment details to their Sales team via the provided form and check the Trust Portal for deeper compliance info.
Questions about this article
No questions yet.