Judging AI governance

Is Claude HIPAA compliant?

Short answerClaude can support a HIPAA-regulated workflow through Anthropic’s HIPAA-ready Enterprise offering or eligible first-party API services when the organization accepts a Business Associate Agreement, or BAA, and uses covered features with the required configuration. Team, Free, Pro, and Max plans cannot enable the HIPAA-ready Enterprise configuration.

Anthropic calls the offering HIPAA-ready because it is configured to support an organization’s obligations under its BAA. Anthropic states that compliance remains the organization’s responsibility. Coverage depends on the organization, product surface, feature, and configuration.

Which Anthropic products can be covered

As of October 7, 2026, Anthropic offers a HIPAA-ready configuration for self-serve and sales-assisted Claude Enterprise plans. The organization’s Primary Owner activates HIPAA in Data and privacy settings and accepts Anthropic’s BAA. Anthropic also offers BAA coverage for eligible first-party API services after the organization signs a BAA and has the service enabled through Anthropic or its sales team.

Anthropic says Team and individual Free, Pro, and Max plans cannot enable HIPAA. Its BAA page also identifies features and surfaces that remain outside coverage. A standard Enterprise plan has no BAA coverage until the Primary Owner activates the HIPAA configuration and accepts the agreement.

What to verify before entering PHI

  1. Confirm that the organization has accepted Anthropic’s BAA for the organization that will process PHI.
  2. Confirm that the Enterprise HIPAA configuration or eligible first-party API access is active.
  3. Check the implementation guide for the exact product surface and feature used in the workflow.
  4. Keep PHI out of features Anthropic lists as uncovered or unavailable under the BAA.
  5. Document the organization’s access, review, incident, and workforce procedures for the workflow.

Where Sentinel fits

SUPERWISE® Sentinel replaces emails, phone numbers, account numbers, and API keys with placeholders before a prompt leaves the PC, and logs every request. This changes the supported data in a prompt and creates a record. Sentinel does not make Claude, an Enterprise organization, an API deployment, or an organization HIPAA compliant.

Removing those supported values is also different from HIPAA de-identification. HHS describes Expert Determination and Safe Harbor as the two routes under the Privacy Rule. Sentinel’s documented replacement of four data types does not establish either route. Review where AI data goes, browse the Learn library, and use the AI glossary for terms used in this assessment.

Frequently asked questions

Does Anthropic sign a BAA?
Yes. Anthropic offers a BAA for its HIPAA-ready Enterprise configuration and eligible first-party API services. The BAA covers the organization that accepts it and the eligible features used under its requirements.
Is Claude Enterprise HIPAA compliant?
Claude Enterprise can support HIPAA-regulated use after the Primary Owner activates the HIPAA configuration, accepts Anthropic’s BAA, uses covered features, and follows the implementation requirements. A standard Enterprise plan has no BAA coverage until those steps are complete.
Can Claude handle PHI?
Anthropic permits PHI through covered features in a HIPAA-ready Enterprise organization or eligible API service after the BAA and required configuration are in place. PHI should stay out of features Anthropic identifies as uncovered.
Is the Claude API HIPAA eligible?
Eligible first-party Claude API services can be covered by Anthropic’s BAA. The organization must sign the BAA, have HIPAA access enabled, and use the eligible features and configuration identified in Anthropic’s implementation guide.

Sources

  1. Anthropic Help Center, HIPAA-ready Enterprise plans. Read October 7, 2026.
  2. Anthropic Help Center, Business Associate Agreements for commercial customers. Read October 7, 2026.
  3. U.S. Department of Health and Human Services, Guidance on HIPAA and cloud computing. Read October 7, 2026.
  4. U.S. Department of Health and Human Services, Guidance regarding methods for de-identification of protected health information. Read October 7, 2026.

Reviewed