Click any tag below to further narrow down your results
Links
This article details which Anthropic commercial products and API features qualify under a HIPAA Business Associate Agreement. It breaks down covered and non-covered services, notes beta and third-party integration exclusions, and highlights ZDR requirements for handling PHI in Claude Code.
- Core Claude for Work features (chat history, Artifacts, voice, web search, research, file creation/code execution without external network access) are BAA-covered, but third-party integrations like MCPs/Connectors, Enterprise Search, and Claude in Chrome are not once data leaves Anthropic.
- On the API side, Messages API and related tools (prompt caching, structured outputs, memory, web search, Bash/text-editor) plus Token Counting, Models, Org Management, and Compliance APIs are covered, while Batch API, Files API, Skills API, Code Execution, Computer Use, and Web Fetch are excluded.
- For Claude Code, only the CLI with Zero-Data-Retention enabled qualifies for BAA coverage—the web, desktop, review, and security betas don't support ZDR and fall outside it.
- Beta features like Cowork and Claude for Office are entirely excluded from BAA coverage, requiring separate data-handling safeguards for any PHI use.
This article explains how healthcare organizations can get a HIPAA-compliant Business Associate Agreement with OpenAI to process protected health information via the API. Email baa@openai.com with your company details and use case; most requests are approved within a few business days. If your request is denied, you can seek reconsideration through your sales contact.
- Emailing baa@openai.com with company details and use case gets most BAA requests approved within a few business days.
- Denied requests can only be reconsidered if you already have an OpenAI sales rep or account director to escalate through.
- Nearly all API services are covered under the BAA (exceptions listed in the platform docs), and no enterprise agreement is required to get one.
OpenAI’s ChatGPT Health adds a HIPAA-compliant wrapper over its regular models but delivers no new technology and raises doubts about data use and fine-tuning. It feels like another marketing stunt as Big Tech probes the healthcare market without real change.
- ChatGPT Health is just a HIPAA-compliant wrapper on existing models—no new underlying technology despite the marketing push.
- OpenAI's promise not to "train" on patient data leaves open whether they still fine-tune on it behind closed doors, echoing 23andMe's fine-print bait-and-switch on DNA data.
- This fits a pattern: AI Consult was human-curated ChatGPT, HealthBench was just a dataset, and GPT-5's health story was retracted amid lawsuits—all flash, no substance.
- The real goal is likely market-testing healthcare economics to undercut purpose-built HIPAA-compliant competitors, using hype to gauge demand before committing.
The article provides official guidance on how the Health Insurance Portability and Accountability Act (HIPAA) applies to online tracking technologies. It emphasizes the importance of protecting patient privacy and ensuring compliance when using digital tools for tracking purposes. The content is aimed at professionals navigating these regulations.
- Tracking tech on healthcare websites/apps (cookies, web beacons, pixels) can transmit PHI to third parties like Google or Meta, triggering HIPAA obligations even without login credentials
- Covered entities must have a valid HIPAA authorization or a Business Associate Agreement with tracking vendors before allowing them access to PHI, not just a general privacy policy disclosure
- IP addresses combined with visits to health-related pages can count as PHI, so even "de-identified" or aggregate analytics tools carry compliance risk
- Organizations face liability exposure if third-party trackers disclose PHI without proper safeguards, making an audit of existing tracking tools and vendor contracts a practical necessity
ChatGPT Health may be a marketing strategy rather than a genuine innovation, potentially allowing tech giants to dominate the healthcare sector. The article questions OpenAI's claims of enhanced security and adherence to HIPAA standards, drawing parallels to past controversies with data privacy in the tech industry.
- OpenAI's claims of HIPAA compliance and enhanced security for ChatGPT Health may be more marketing spin than substantive privacy protection
- The move could let a tech giant leverage user trust to gain a dominant foothold in the healthcare data market
- The situation echoes past tech industry controversies over data privacy, raising skepticism about the sincerity of OpenAI's promises
Anthropic offers Business Associate Agreements (BAA) for its HIPAA eligible services, specifically for commercial products like Claude for Work and the Anthropic API. However, the BAA does not cover certain services and has specific configuration requirements and limitations. To start the BAA process or learn more, customers should contact the sales team.
- Anthropic only offers BAAs for Claude for Work and the Anthropic API, not for Claude.ai Free/Pro/Max or standard Claude for Work plans and beta/chat products
- HIPAA-eligible use requires zero data retention agreements as part of the BAA setup
- Features like web search, batch processing, prompt caching, and Files API uploads are excluded from BAA coverage
- Interested customers must contact Anthropic's sales team directly to start the BAA process
This guide explains how to configure Google Workspace and Cloud Identity services to handle protected health information under a HIPAA Business Associate Addendum. It lists which core services support PHI, outlines customer responsibilities, and shows how to separate user access via organizational units to meet compliance requirements.
- Only specific Workspace services (Gmail, Calendar, Chat, Drive apps, Cloud Search, Groups, Keep, Meet, Sites, Tasks, Vault, managed Voice, Gemini app) are covered for PHI under the BAA—Contacts, YouTube, Photos, and Gemini in Chrome are excluded.
- Admins, not Google, are responsible for determining Business Associate status, securing agreements, and handling HIPAA access/amendment/accounting requests.
- Organizational units must be used to separate PHI users from non-PHI users and restrict which services each group can access.
- Recommended safeguards include auditing third-party integrations, monitoring account activity, and locking down sharing settings across Docs, Drive, Chat, and Meet.