1 link tagged with all of: compliance + business-associate-agreement + enterprise-chat + hipaa
Click any tag below to further narrow down your results
Links
This article details which Anthropic commercial products and API features qualify under a HIPAA Business Associate Agreement. It breaks down covered and non-covered services, notes beta and third-party integration exclusions, and highlights ZDR requirements for handling PHI in Claude Code.
- Core Claude for Work features (chat history, Artifacts, voice, web search, research, file creation/code execution without external network access) are BAA-covered, but third-party integrations like MCPs/Connectors, Enterprise Search, and Claude in Chrome are not once data leaves Anthropic.
- On the API side, Messages API and related tools (prompt caching, structured outputs, memory, web search, Bash/text-editor) plus Token Counting, Models, Org Management, and Compliance APIs are covered, while Batch API, Files API, Skills API, Code Execution, Computer Use, and Web Fetch are excluded.
- For Claude Code, only the CLI with Zero-Data-Retention enabled qualifies for BAA coverage—the web, desktop, review, and security betas don't support ZDR and fall outside it.
- Beta features like Cowork and Claude for Office are entirely excluded from BAA coverage, requiring separate data-handling safeguards for any PHI use.