What you will be able to do
- Explain who needs the HIPAA-ready Enterprise offering and how its BAA is accepted
- Sort Claude features into covered, available-but-not-covered and disabled under the BAA
- Choose a configuration that keeps PHI under the BAA while reasoning about ZDR and Covered Models
Key concept
Eligible (covered) services — Signing a BAA does not make every Claude surface safe for protected health information. PHI may only flow through the specific features and configurations the BAA covers, so HIPAA compliance is a question of routing, not of having an agreement on file.
1.The HIPAA-ready Enterprise offering and its BAA
HIPAA is the regulation most concretely documented for Claude, so start there. Anthropic offers a HIPAA-ready version of Claude for Enterprise organizations that choose to process protected health information (PHI). It is aimed at HIPAA-covered entities and their business associates: healthcare providers such as hospitals and clinics, health plans and insurers, healthcare data processors, and any business associate handling PHI on a covered entity's behalf. The support article reduces the qualifying test to one question: will you be processing PHI through Claude? If yes, you need the HIPAA-ready offering with a Business Associate Agreement (BAA).
A standard Enterprise plan is not HIPAA-ready by default. BAA coverage only begins when the organization's Primary Owner activates HIPAA compliance under Organization settings > Data and privacy and accepts the BAA. That enablement is self-serve: there is no sales or legal cycle, the BAA is click-to-accept inside the flow, and clicking "Accept and enable HIPAA" is the acceptance. The self-serve BAA is a standard agreement and cannot be modified.
| Actor or plan | Can enable HIPAA? |
|---|---|
| Primary Owner of an Enterprise organization | Yes, from Organization settings > Data and privacy > HIPAA Compliance |
| Other Owners or Admins of that Enterprise organization | No, they must ask the Primary Owner to complete enablement |
| Team plans | No |
| Individual plans (Free, Pro, and Max) | No |
Two properties make this a decision to take deliberately. Enabling HIPAA resets certain organization settings to defaults as part of the transition, and the change cannot be reversed from organization settings. That is why the flow makes the Primary Owner download and review both the BAA and the Implementation Guide for HIPAA Entities before accepting. Once enabled, a checkmark appears in the HIPAA Compliance section; no checkmark means the organization is not enabled.
Timing of the agreement matters too. A BAA signed for Claude API usage before December 2, 2025 covers API usage only and does not extend to the HIPAA-ready Enterprise plan; adding Enterprise requires a new BAA. Agreements signed after that date can cover both under one agreement.
Two things. Only the Primary Owner can accept the BAA and enable HIPAA, so the admin cannot complete the flow. And enablement is one-way: once the BAA is accepted it cannot be reversed from organization settings, and some settings reset to defaults on the way in.
2.Covered, available-but-not-covered, and disabled features
Enabling HIPAA does not pull every feature under the BAA. Features fall into three categories, and the Implementation Guide on the Anthropic Trust Center is the authoritative list of each feature's status. The support article on BAAs gives the current breakdown for Claude Enterprise:
| Category | Features | What it means for PHI |
|---|---|---|
| Covered as Eligible Services | Chat, Projects, Artifacts, Voice, Web Search, Research, Skills, File creation & code execution (excluding network access and use of external websites) | PHI may be processed here |
| Available but sending data to 3rd parties is not covered | MCPs / Connectors, Enterprise Search / "Ask Your Org", Claude in Chrome | Usable, but data leaving to third parties falls outside the BAA |
| Available but not covered | Cowork; beta parts of Claude for Microsoft 365 | Usable, but not for PHI |
| Not available yet for HIPAA-ready organizations | Claude Design [beta], Claude Slides [beta], Claude Docs [beta] | Disabled |
The middle rows are where compliance is actually won or lost. For those features, responsibility shifts explicitly to the customer's administrators: if they enable a connector or Claude in Chrome, it is on them to make sure staff do not send PHI to third parties through it. The BAA also covers only the single organization that accepted it, and it excludes the Claude Console as well as Cowork and beta features. For the first-party API, not all features are covered either, and turning on PHI use requires the Primary Owner to sign a BAA and then contact Anthropic to enable it.
It is not. The connector is available, but sending data to a third party through it sits outside the BAA, and the administrator who enabled the connector owns that risk.
A digital health startup wants to route protected health information (PHI) from patient intake forms through Claude to summarize clinical notes. The compliance team confirms Anthropic has signed a Business Associate Agreement (BAA) with the company, but must choose where in the Claude product surface this workflow can legally process PHI. Which deployment satisfies the BAA?
Correct answer: A — A dedicated HIPAA-enabled organization calling the Claude API with only BAA-eligible features enabled
- A. Correct. HIPAA readiness is provisioned as a dedicated HIPAA-enabled organization on the Claude API, restricted to BAA-eligible features, which is the arrangement that legally covers PHI processing.
- B. The Console and Workbench interfaces are explicitly excluded from HIPAA readiness even when the underlying organization has a signed BAA.
- C. Claude Free, Pro, Max, and Team consumer plans are not covered under the BAA regardless of who uses them.
- D. Enterprise coverage requires an administrator to activate HIPAA-ready settings and sign the BAA; a default, unconfigured workspace is not covered.
3.Claude Code, zero data retention and Covered Models
Claude Code is the surface most often misread. Enabling HIPAA readiness does not bring it under the BAA. Claude Code is covered only with zero data retention (ZDR) enabled, and ZDR is available to qualified accounts only; without ZDR, Claude Code stays usable but uncovered, even when bundled into Enterprise seats. Several Claude Code surfaces, including desktop remote mode, Claude Code in the web, Code Review and Remote Control, are incompatible with ZDR and therefore never covered.
ZDR collides with a second rule. Covered Models, such as Claude Fable 5, require 30-day data retention on every platform where they are offered, as part of Anthropic's safety work, and cannot be reached from a ZDR-enabled organization or workspace. The result is a configuration matrix you should be able to read:
| Product and access | Retention | Eligible under BAA? | Covered Models? |
|---|---|---|---|
| Chat on Claude Enterprise | Standard | Yes | Yes |
| Claude Code on Claude Enterprise | Zero data retention | Yes | No |
| Claude Code on Claude Enterprise | Standard | No | Yes |
| Claude Code on 1P API org | Zero data retention | Yes | No |
| Claude Code on 3P API (Google Vertex only) | Standard | No | Yes |
| Cowork on Claude Enterprise | Standard | No | Yes |
| Claude API, HIPAA-ready API | Standard | Yes | Yes |
| Claude API, regular API | Zero data retention | Yes | No |
| Claude API, regular API | Standard | No | Yes |
Read across the rows and the design choices follow. For PHI plus Covered Models, use a HIPAA-ready API organization or Chat on a HIPAA-ready Enterprise plan. Claude Code with PHI means ZDR, which means no Covered Models. HIPAA readiness and ZDR cannot live on the same 1P API organization, so a team needing both runs separate organization IDs and is responsible for keeping PHI inside the eligible one. A ZDR organization that wants Covered Models for non-PHI work can enable standard retention in one dedicated workspace while its other workspaces keep ZDR. Finally, Anthropic's BAA does not apply to services bought through a third-party cloud provider; coverage there is a conversation with that provider.
An engineering organization runs under a zero data retention (ZDR) arrangement. One team wants to pilot a Covered Model that requires 30-day data retention in a single workspace, without changing the ZDR posture of the rest of the organization. What should they do?
Correct answer: A — Enable 30-day data retention in that workspace's privacy controls while other workspaces remain on ZDR
- A. Correct. Workspace-level privacy controls let a single workspace opt into 30-day retention to access Covered Models while the rest of the organization stays on ZDR.
- B. Disabling ZDR organization-wide is unnecessary and overly broad when a workspace-level override achieves the same goal.
- C. HIPAA readiness addresses PHI safeguards, not the retention-length requirement of Covered Models; it does not by itself unlock the model.
- D. The API does not silently change retention; a workspace still under ZDR receives a 400 error until 30-day retention is explicitly enabled for it.
Exam traps
Each one states something that sounds right. Open it to see what is actually true.
1.Once the Primary Owner enables HIPAA on the Enterprise plan, Claude Code used through those seats is covered by the BAA.Why is that wrong?
HIPAA enablement alone does not cover Claude Code; it is covered only with zero data retention enabled, on qualified accounts.
Covered in Claude Code, zero data retention and Covered Models
2.An organization that signed a BAA for the Claude API in 2024 already has its Enterprise plan covered.Why is that wrong?
A pre-December 2, 2025 API BAA covers API usage only; Enterprise coverage needs a new BAA.
3.Because MCP connectors are available in a HIPAA-enabled org, PHI sent through them is covered.Why is that wrong?
Connectors stay available, but data sent to third parties through them is outside the BAA and administrators carry responsibility for its use.
Covered in Covered, available-but-not-covered, and disabled features
4.A ZDR-enabled organization can call a Covered Model as long as it has signed a BAA.Why is that wrong?
Covered Models require 30-day retention; calls from a ZDR-enabled organization or workspace fail.
Covered in Claude Code, zero data retention and Covered Models
Sources
Every claim above is drawn from one of these pages, quoted as it was written on the date shown.
- 1.
“Only the Primary Owner of the organization can accept the BAA and enable HIPAA.”
↩︎ The HIPAA-ready Enterprise offering and its BAA“This is a one-way decision.”
↩︎ The HIPAA-ready Enterprise offering and its BAA“Team plans and individual plans (Free, Pro, and Max) can't enable HIPAA.”
↩︎ The HIPAA-ready Enterprise offering and its BAA“The Business Associate Agreement (BAA) is included in the flow as click-to-accept”
↩︎ The HIPAA-ready Enterprise offering and its BAA“BAAs signed after December 2, 2025 can cover both API usage and the Enterprise plan under a single agreement.”
↩︎ The HIPAA-ready Enterprise offering and its BAA“PHI should only be processed through covered features”
↩︎ Covered, available-but-not-covered, and disabled features“Enabling HIPAA readiness alone doesn't bring Claude Code under your BAA.”
↩︎ Claude Code, zero data retention and Covered Models“PHI should only be processed through covered features”
↩︎ Key concept“Enabling HIPAA readiness alone doesn't bring Claude Code under your BAA.”
↩︎ Exam trap 1“If your organization signed a BAA for Claude API usage before December 2, 2025, that agreement only covers API usage”
↩︎ Exam trap 2 - 2.https://support.claude.com/en/articles/8114513-business-associate-agreements-baa-for-commercial-customersOfficial docs
“Standard Claude Enterprise plans do not include BAA coverage without action from a Primary Owner.”
↩︎ The HIPAA-ready Enterprise offering and its BAA“Administrators who enable these features are responsible for ensuring their workforce uses them in compliance with applicable legal obligations.”
↩︎ Covered, available-but-not-covered, and disabled features“the BAA only covers the single organization that accepted it”
↩︎ Covered, available-but-not-covered, and disabled features“Administrators who enable these features are responsible for ensuring their workforce uses them in compliance with applicable legal obligations.”
↩︎ Exam trap 3 - 3.https://support.claude.com/en/articles/15455031-covered-models-under-a-business-associate-agreement-baaOfficial docs
“Requests to a Covered Model from a ZDR-enabled organization or workspace return an error.”
↩︎ Claude Code, zero data retention and Covered Models“HIPAA readiness and ZDR cannot coexist on a single 1P API organization.”
↩︎ Claude Code, zero data retention and Covered Models“Enable standard retention in a dedicated workspace (Workspace > Manage > Privacy Controls).”
↩︎ Claude Code, zero data retention and Covered Models“services purchased through a third-party cloud provider”
↩︎ Claude Code, zero data retention and Covered Models“Requests to a Covered Model from a ZDR-enabled organization or workspace return an error.”
↩︎ Exam trap 4