Skip to main content

Anthropic Details Segmented HIPAA Compliance for Enterprise and Claude Code

18 SEPTEMBER 2026·2 MIN READ·2 SOURCES·Trusted source

Anthropic has outlined its HIPAA compliance requirements, offering Business Associate Agreements for specific AI services rather than universal coverage for all Claude interactions.

Anthropic Details Segmented HIPAA Compliance for Enterprise and Claude Code

Key takeaways · 3

  • 01

    Enterprise coverage applies to BAA versions accepted after December 2, 2025.

  • 02

    Claude Code CLI requires a separately enabled Zero Data Retention (ZDR) configuration.

  • 03

    Third-party connector and external MCP data flows are excluded from BAA coverage.

HIPAA configurations and limits

Anthropic offers Business Associate Agreements for specific AI services, not every Claude interaction. [2] Enterprise Primary Owners must accept the BAA and activate HIPAA readiness. [2] API documentation describes eligible organizations accepting a standard BAA in Console settings, while the Privacy Center still instructs customers to contact sales for API activation. [2] The feature table identifies Enterprise coverage under versions accepted after December 2, 2025 and specified API features after April 1, 2026. [2]

Claude Code CLI and Desktop local mode require a qualifying account, applicable BAA and separately enabled ZDR. [2] Enterprise HIPAA activation alone does not cover Claude Code. [2] Covered Models require 30-day retention and generally cannot use ZDR. [2] Third-party connector, browser and external MCP data flows are outside Anthropic's BAA. [2]

What it means

The nuanced rollout of HIPAA readiness highlights the complexity of healthcare compliance in generative AI tools. Rather than providing blanket platform certification, Anthropic’s approach segments coverage by interface and timeline, differentiating Enterprise coverage following the December 2, 2025 version from specified API features active after April 1, 2026. Organizations must actively manage their configurations, as features like the Claude Code CLI demand distinct Zero Data Retention activation, while Covered Models simultaneously require a 30-day retention period. Furthermore, the explicit exclusion of external MCP data flows places the burden of third-party risk management entirely on the user. What the sources don't address: Whether Anthropic plans to reconcile the conflicting API activation instructions between its Console and Privacy Center.

Understanding Anthropic's segmented HIPAA compliance is critical for organizations deploying Claude in regulated environments. Failure to configure features like Zero Data Retention or relying on external MCPs could lead to unintended compliance violations.

Why it matters
Daily session

Put this to work — one session a day, built for your industry.

Create a free account for a daily session — eight questions and one real-work challenge, on the news that affects your role.

Start free

How this developed

  1. 18 September 2026

    Anthropic Details Segmented HIPAA Compliance for Enterprise and Claude Code

  2. 18 September 2026

    Event created from source cluster.

Sources

AI fluency, one session a day, built for your work.