CertSafari
    CCAR-P · Lessons

    Domain 5 · Lesson 29/38

    HIPAA on Claude: BAAs, Eligible Services and Zero Data Retention

    Ensure compliance with regulations

    8 min read
    2.8% of exam
    3 sources
    Published 27 Sep 2026
    Docs as of 26 Sep 2026

    What you will be able to do

    • Explain who needs the HIPAA-ready Enterprise offering and how its BAA is accepted
    • Sort Claude features into covered, available-but-not-covered and disabled under the BAA
    • Choose a configuration that keeps PHI under the BAA while reasoning about ZDR and Covered Models

    Key concept

    Eligible (covered) services — Signing a BAA does not make every Claude surface safe for protected health information. PHI may only flow through the specific features and configurations the BAA covers, so HIPAA compliance is a question of routing, not of having an agreement on file.

    1.The HIPAA-ready Enterprise offering and its BAA

    HIPAA is the regulation most concretely documented for Claude, so start there. Anthropic offers a HIPAA-ready version of Claude for Enterprise organizations that choose to process protected health information (PHI). It is aimed at HIPAA-covered entities and their business associates: healthcare providers such as hospitals and clinics, health plans and insurers, healthcare data processors, and any business associate handling PHI on a covered entity's behalf. The support article reduces the qualifying test to one question: will you be processing PHI through Claude? If yes, you need the HIPAA-ready offering with a Business Associate Agreement (BAA).

    A standard Enterprise plan is not HIPAA-ready by default. BAA coverage only begins when the organization's Primary Owner activates HIPAA compliance under Organization settings > Data and privacy and accepts the BAA. That enablement is self-serve: there is no sales or legal cycle, the BAA is click-to-accept inside the flow, and clicking "Accept and enable HIPAA" is the acceptance. The self-serve BAA is a standard agreement and cannot be modified.

    Who can and cannot enable HIPAA readiness in Claude
    Actor or planCan enable HIPAA?
    Primary Owner of an Enterprise organizationYes, from Organization settings > Data and privacy > HIPAA Compliance
    Other Owners or Admins of that Enterprise organizationNo, they must ask the Primary Owner to complete enablement
    Team plansNo
    Individual plans (Free, Pro, and Max)No

    Two properties make this a decision to take deliberately. Enabling HIPAA resets certain organization settings to defaults as part of the transition, and the change cannot be reversed from organization settings. That is why the flow makes the Primary Owner download and review both the BAA and the Implementation Guide for HIPAA Entities before accepting. Once enabled, a checkmark appears in the HIPAA Compliance section; no checkmark means the organization is not enabled.

    Timing of the agreement matters too. A BAA signed for Claude API usage before December 2, 2025 covers API usage only and does not extend to the HIPAA-ready Enterprise plan; adding Enterprise requires a new BAA. Agreements signed after that date can cover both under one agreement.

    Sources12

    2.Covered, available-but-not-covered, and disabled features

    Enabling HIPAA does not pull every feature under the BAA. Features fall into three categories, and the Implementation Guide on the Anthropic Trust Center is the authoritative list of each feature's status. The support article on BAAs gives the current breakdown for Claude Enterprise:

    Claude Enterprise features by BAA status
    CategoryFeaturesWhat it means for PHI
    Covered as Eligible ServicesChat, Projects, Artifacts, Voice, Web Search, Research, Skills, File creation & code execution (excluding network access and use of external websites)PHI may be processed here
    Available but sending data to 3rd parties is not coveredMCPs / Connectors, Enterprise Search / "Ask Your Org", Claude in ChromeUsable, but data leaving to third parties falls outside the BAA
    Available but not coveredCowork; beta parts of Claude for Microsoft 365Usable, but not for PHI
    Not available yet for HIPAA-ready organizationsClaude Design [beta], Claude Slides [beta], Claude Docs [beta]Disabled

    The middle rows are where compliance is actually won or lost. For those features, responsibility shifts explicitly to the customer's administrators: if they enable a connector or Claude in Chrome, it is on them to make sure staff do not send PHI to third parties through it. The BAA also covers only the single organization that accepted it, and it excludes the Claude Console as well as Cowork and beta features. For the first-party API, not all features are covered either, and turning on PHI use requires the Primary Owner to sign a BAA and then contact Anthropic to enable it.

    It is not. The connector is available, but sending data to a third party through it sits outside the BAA, and the administrator who enabled the connector owns that risk.

    A digital health startup wants to route protected health information (PHI) from patient intake forms through Claude to summarize clinical notes. The compliance team confirms Anthropic has signed a Business Associate Agreement (BAA) with the company, but must choose where in the Claude product surface this workflow can legally process PHI. Which deployment satisfies the BAA?

    Sources12

    3.Claude Code, zero data retention and Covered Models

    Claude Code is the surface most often misread. Enabling HIPAA readiness does not bring it under the BAA. Claude Code is covered only with zero data retention (ZDR) enabled, and ZDR is available to qualified accounts only; without ZDR, Claude Code stays usable but uncovered, even when bundled into Enterprise seats. Several Claude Code surfaces, including desktop remote mode, Claude Code in the web, Code Review and Remote Control, are incompatible with ZDR and therefore never covered.

    ZDR collides with a second rule. Covered Models, such as Claude Fable 5, require 30-day data retention on every platform where they are offered, as part of Anthropic's safety work, and cannot be reached from a ZDR-enabled organization or workspace. The result is a configuration matrix you should be able to read:

    BAA eligibility versus Covered Model access by configuration
    Product and accessRetentionEligible under BAA?Covered Models?
    Chat on Claude EnterpriseStandardYesYes
    Claude Code on Claude EnterpriseZero data retentionYesNo
    Claude Code on Claude EnterpriseStandardNoYes
    Claude Code on 1P API orgZero data retentionYesNo
    Claude Code on 3P API (Google Vertex only)StandardNoYes
    Cowork on Claude EnterpriseStandardNoYes
    Claude API, HIPAA-ready APIStandardYesYes
    Claude API, regular APIZero data retentionYesNo
    Claude API, regular APIStandardNoYes

    Read across the rows and the design choices follow. For PHI plus Covered Models, use a HIPAA-ready API organization or Chat on a HIPAA-ready Enterprise plan. Claude Code with PHI means ZDR, which means no Covered Models. HIPAA readiness and ZDR cannot live on the same 1P API organization, so a team needing both runs separate organization IDs and is responsible for keeping PHI inside the eligible one. A ZDR organization that wants Covered Models for non-PHI work can enable standard retention in one dedicated workspace while its other workspaces keep ZDR. Finally, Anthropic's BAA does not apply to services bought through a third-party cloud provider; coverage there is a conversation with that provider.

    An engineering organization runs under a zero data retention (ZDR) arrangement. One team wants to pilot a Covered Model that requires 30-day data retention in a single workspace, without changing the ZDR posture of the rest of the organization. What should they do?

    Sources13

    Exam traps

    Each one states something that sounds right. Open it to see what is actually true.

    1. 1.Once the Primary Owner enables HIPAA on the Enterprise plan, Claude Code used through those seats is covered by the BAA.Why is that wrong?

      HIPAA enablement alone does not cover Claude Code; it is covered only with zero data retention enabled, on qualified accounts.

      Covered in Claude Code, zero data retention and Covered Models

    2. 2.An organization that signed a BAA for the Claude API in 2024 already has its Enterprise plan covered.Why is that wrong?

      A pre-December 2, 2025 API BAA covers API usage only; Enterprise coverage needs a new BAA.

      Covered in The HIPAA-ready Enterprise offering and its BAA

    3. 3.Because MCP connectors are available in a HIPAA-enabled org, PHI sent through them is covered.Why is that wrong?

      Connectors stay available, but data sent to third parties through them is outside the BAA and administrators carry responsibility for its use.

      Covered in Covered, available-but-not-covered, and disabled features

    4. 4.A ZDR-enabled organization can call a Covered Model as long as it has signed a BAA.Why is that wrong?

      Covered Models require 30-day retention; calls from a ZDR-enabled organization or workspace fail.

      Covered in Claude Code, zero data retention and Covered Models

    Sources

    Every claim above is drawn from one of these pages, quoted as it was written on the date shown.

    1. 1.
      “Only the Primary Owner of the organization can accept the BAA and enable HIPAA.”
      ↩︎ The HIPAA-ready Enterprise offering and its BAA
      “Team plans and individual plans (Free, Pro, and Max) can't enable HIPAA.”
      ↩︎ The HIPAA-ready Enterprise offering and its BAA
      “The Business Associate Agreement (BAA) is included in the flow as click-to-accept”
      ↩︎ The HIPAA-ready Enterprise offering and its BAA
      “BAAs signed after December 2, 2025 can cover both API usage and the Enterprise plan under a single agreement.”
      ↩︎ The HIPAA-ready Enterprise offering and its BAA
      “PHI should only be processed through covered features”
      ↩︎ Covered, available-but-not-covered, and disabled features
      “Enabling HIPAA readiness alone doesn't bring Claude Code under your BAA.”
      ↩︎ Claude Code, zero data retention and Covered Models
      “PHI should only be processed through covered features”
      ↩︎ Key concept
      “Enabling HIPAA readiness alone doesn't bring Claude Code under your BAA.”
      ↩︎ Exam trap 1
      “If your organization signed a BAA for Claude API usage before December 2, 2025, that agreement only covers API usage”
      ↩︎ Exam trap 2
    2. 2.
      “Standard Claude Enterprise plans do not include BAA coverage without action from a Primary Owner.”
      ↩︎ The HIPAA-ready Enterprise offering and its BAA
      “Administrators who enable these features are responsible for ensuring their workforce uses them in compliance with applicable legal obligations.”
      ↩︎ Covered, available-but-not-covered, and disabled features
      “the BAA only covers the single organization that accepted it”
      ↩︎ Covered, available-but-not-covered, and disabled features
      “Administrators who enable these features are responsible for ensuring their workforce uses them in compliance with applicable legal obligations.”
      ↩︎ Exam trap 3
    3. 3.
      “Requests to a Covered Model from a ZDR-enabled organization or workspace return an error.”
      ↩︎ Claude Code, zero data retention and Covered Models
      “HIPAA readiness and ZDR cannot coexist on a single 1P API organization.”
      ↩︎ Claude Code, zero data retention and Covered Models
      “Enable standard retention in a dedicated workspace (Workspace > Manage > Privacy Controls).”
      ↩︎ Claude Code, zero data retention and Covered Models
      “services purchased through a third-party cloud provider”
      ↩︎ Claude Code, zero data retention and Covered Models
      “Requests to a Covered Model from a ZDR-enabled organization or workspace return an error.”
      ↩︎ Exam trap 4

    Continue to page 2 of 2

    GDPR, Data Residency and FedRAMP for Claude Deployments