DEV Community

Manu Shukla
Manu Shukla

Posted on • Originally published at ecorpit.com

2026 Claude HIPAA guide: what the BAA covers (API, Enterprise, Code) and what's still on you

2026 Claude HIPAA guide: what the BAA covers (API, Enterprise, Code) and what's still on you

Summary. As of July 2026, Anthropic's HIPAA-ready Business Associate Agreement (BAA) covers three ways of using Claude: the Claude API, the Claude Enterprise plan, and Claude Code, but Claude Code only with zero data retention (ZDR) on qualified accounts. It does not cover Cowork, Pro, Max, Team, or Free. Getting the paperwork right matters because the numbers are large. IBM put the 2025 average healthcare data breach at $7.42 million, the highest of any industry for the 14th year running, and United States civil penalties for HIPAA violations rose on 28 January 2026 to a maximum of $2,190,294 per identical provision in a year. A BAA signed before 2 December 2025 covers only the API, not the Enterprise plan. This guide sets out exactly what is covered, how to turn it on, and the safeguards that stay your job, not Anthropic's.

There is a persistent misreading of what a BAA does. Signing one with Anthropic does not make your product HIPAA compliant. It makes Anthropic a business associate that has agreed, in a contract, to handle protected health information (PHI) according to HIPAA when it processes your data. Everything on your side of the line, access control, audit logging, staff training, and breach response, remains yours to build and prove. The BAA is the floor, not the finish line.

The short answer: what "HIPAA-ready Claude" actually means

Anthropic launched Claude for Healthcare on 11 January 2026 at the J.P. Morgan Healthcare Conference, following Claude for Life Sciences in October 2025. The healthcare offering adds HIPAA-ready infrastructure for enterprise customers, models tuned for healthcare tasks, and native connectors to systems clinicians already use, including the CMS Coverage Database, ICD-10 codes, the National Provider Identifier Registry, and PubMed. For the first time, that lets an organization run PHI workflows such as prior authorization through Claude under contract.

Eric Kauderer-Abrams, head of biology and life sciences at Anthropic, framed the compliance posture directly to Fierce Healthcare: "A big part about being useful in healthcare and life sciences is respecting the intense compliance requirements that are there, and with good reason. We're offering our solutions in a HIPAA-compliant way so that you can build applications around them, and so that you can do so in a way that respects all the relevant regulations."

The key phrase is "so that you can build applications." Anthropic supplies a compliant surface. Your obligations as a covered entity or business associate do not transfer.

What the BAA covers, and what it does not

This is the table to bookmark. It reflects Anthropic's own support documentation as of July 2026.

Claude surface Covered by Anthropic's BAA? Condition
Claude API Yes Sign the API BAA and enable HIPAA readiness in data-retention settings
Claude Enterprise (HIPAA-ready) Yes Enterprise plan only; Primary Owner enables and accepts the BAA
Claude Code Conditionally Only with zero data retention (ZDR) on qualified accounts
Cowork No Not yet covered under Anthropic's BAA
Claude Pro No Individual plan; cannot enable HIPAA
Claude Max No Individual plan; cannot enable HIPAA
Claude Team No Team plans cannot enable HIPAA
Claude Free No Not eligible

Two traps hide in that table. First, Claude Code is not automatically covered when you turn on HIPAA readiness. It falls under the BAA only when ZDR is enabled on a qualified account, and it stays outside the BAA even when Claude Code access is bundled into your Enterprise seats. If your engineers paste PHI into an un-ZDR Claude Code session, that use is not covered. Second, Cowork is not yet under the BAA at all, so it is off-limits for PHI regardless of your plan.

How to actually enable it

For Enterprise organizations, enablement is self-serve and fast, with three constraints worth planning around before you click.

Only the Primary Owner of the organization can accept the BAA and enable HIPAA. Other Owners and Admins cannot complete the flow. Enabling HIPAA resets certain settings across the organization back to defaults as part of the transition, so read the onboarding modal and the downloadable Implementation Guide first. And the change is one-way: once HIPAA is enabled and the BAA accepted, you cannot reverse it from organization settings. The self-serve BAA is a standard agreement and cannot be modified.

The flow itself is short. Sign in as the Primary Owner, open Organization settings, then Data and privacy, then HIPAA Compliance. Click Enable, download and review the BAA, download and review the Implementation Guide, then click "Accept and enable HIPAA." Clicking that button constitutes acceptance of the BAA, so there is no separate document to sign and return. A checkmark in the HIPAA Compliance section confirms the org is configured to process PHI.

The API path and the 2 December 2025 cutoff

If you use the Claude API rather than the Enterprise app, HIPAA readiness is configured through the API's data-retention settings under a separate API BAA. The date to watch is 2 December 2025. A BAA signed for API use before that date covers only API usage and does not extend to the HIPAA-ready Enterprise plan; to add Enterprise you must sign a new BAA. BAAs signed on or after 2 December 2025 can cover both the API and the Enterprise plan under a single agreement. Teams that signed early in 2025 for an API pilot and now want to roll out the Enterprise app are the ones most likely to be caught by this.

What HIPAA still requires from you

The BAA covers Anthropic's handling of data. It does not cover yours. This is the shared-responsibility split that trips up teams who assume a signed BAA closes the compliance question.

Responsibility Anthropic (under the BAA) You (covered entity or business associate)
Platform and model data handling Yes No
Access controls and authentication No Yes
Audit logging and monitoring No Yes
Workforce training No Yes
Minimum-necessary enforcement No Yes
Documentation retention (six years) No Yes
Security risk analysis No Yes
Breach notification to patients and regulators No Yes

HIPAA's Security Rule requires covered entities to run a security risk analysis, keep required documentation for six years, and enforce access controls, audit logging, and the minimum-necessary principle. None of that moves to Anthropic under the BAA. Practically, that means single sign-on and role-based access on your side, logging of who prompted Claude with which record, workforce training on what may and may not be pasted into a model, and an incident-response plan that treats an over-broad prompt as a potential disclosure. Our note on healthcare AI deployment mistakes in Indian hospitals covers the operational failures that turn a technically compliant tool into a breach.

The penalty math, and why it drives the decision

Compliance spending looks expensive until you price the downside. The 28 January 2026 adjustment lifted HIPAA civil penalties by about 2.6 percent across four tiers.

HIPAA penalty tier (2026) Per violation Annual cap (identical provision)
Tier 1, did not know from $145 $36,505.50
Tier 2, reasonable cause up to $73,011 $146,053
Tier 3, willful neglect, corrected $14,602 to $73,011 $2,190,294
Tier 4, willful neglect, not corrected from $73,011 $2,190,294

Those are per-violation figures, and a single incident touching thousands of records can be counted many times. Set against them, IBM's 2025 Cost of a Data Breach report put the average healthcare breach at $7.42 million, down from $9.77 million the year before but still the costliest sector for the 14th consecutive year, ahead of financial services at $5.56 million. Healthcare breaches also take the longest to contain, 279 days on average. The economic case for enabling the BAA, turning on ZDR for Claude Code, and keeping PHI out of Cowork is not close.

Building for both the US and India

Indian healthtech companies and global capability centres rarely serve one regulator. A team in Gurugram building for US hospitals answers to HIPAA, while the same team's Indian deployments answer to the Digital Personal Data Protection Act 2023 and, for clinical software, to CDSCO device rules. The controls overlap more than they conflict.

India's DPDP framework sets a maximum penalty of ₹250 crore, roughly $30 million, for failing to keep reasonable security safeguards that lead to a personal data breach, plus ₹200 crore for failing to notify the Data Protection Board and affected users. Under Rule 6, "reasonable" is defined as a baseline of encryption, access controls, and one-year log retention. Notice that this is a subset of what HIPAA already asks for, so a HIPAA-grade control set generally satisfies DPDP's technical floor, with one addition: data residency. If Indian patient data must stay in India, pin your deployment to an in-country region and confirm the cloud region backing your Claude access. For the full India picture, see our clinical AI deployment guide for CDSCO and DPDP and the data architecture patterns for clinical AI.

One practical note for Indian buyers: Anthropic describes Claude as available through all major cloud providers, which gives you room to place workloads on the provider and region your data-residency policy already allows. Match the Claude access path to that decision rather than the other way around.

A decision checklist by workflow

Map the surface to the sensitivity of the data before you build, not after.

For any workflow that touches PHI, such as prior authorization, clinical documentation, or claims appeals, use Claude Enterprise with HIPAA enabled, or the Claude API under an API BAA. For engineering work where developers might expose PHI, use Claude Code only with ZDR on a qualified account, and block the un-ZDR path in policy. Keep PHI out of Cowork, Pro, Max, Team, and Free entirely, since none is covered. For non-PHI work, de-identified analytics, drafting public content, internal engineering that never sees patient data, any plan is fine, but write down the boundary so staff know which tool to open for which task. Teams standing this up from scratch will find the sequencing in our healthcare AI CDSCO and DPDP deployment steps useful.

FAQ

Is Claude HIPAA compliant in 2026?

Claude offers a HIPAA-ready configuration, not blanket compliance. Anthropic will sign a BAA covering the Claude API, the Enterprise plan, and Claude Code with zero data retention. Compliance is a shared responsibility: the BAA covers Anthropic's data handling, while access control, audit logging, training, and breach response remain the customer's obligation under HIPAA.

Which Claude products are covered by the BAA?

As of July 2026, Anthropic's BAA covers the Claude API, the HIPAA-ready Claude Enterprise plan, and Claude Code when zero data retention is enabled on a qualified account. Cowork is not yet covered. Individual plans, Pro and Max, plus Team and Free, cannot enable HIPAA and must not be used for protected health information.

Does enabling HIPAA automatically cover Claude Code?

No. Enabling HIPAA readiness alone does not bring Claude Code under the BAA. Claude Code is covered only with zero data retention enabled on a qualified account, and it stays uncovered even when Claude Code access is bundled into Enterprise seats. Without ZDR, developers must not paste protected health information into Claude Code sessions.

How do I enable the HIPAA-ready Enterprise plan?

Only the organization's Primary Owner can enable it, from Organization settings, then Data and privacy, then HIPAA Compliance. You download and review the BAA and the Implementation Guide, then click "Accept and enable HIPAA," which accepts the BAA. Enabling resets some settings to defaults and is a one-way change that cannot be reversed from settings.

What does the BAA not cover that I still have to do?

The BAA covers Anthropic's handling of data only. You remain responsible for access controls, authentication, audit logging, workforce training, minimum-necessary enforcement, six years of documentation retention, a security risk analysis, and breach notification to patients and regulators. A signed BAA is the starting point of a compliance program, not a substitute for one.

How much can a HIPAA violation cost in 2026?

United States civil penalties rose on 28 January 2026 to a range from $145 to $2,190,294 per violation depending on culpability, with a $2,190,294 annual cap for all violations of an identical provision. Because penalties are counted per violation, one incident affecting many records can multiply quickly. The average healthcare breach cost $7.42 million in IBM's 2025 report.

Does a Claude BAA help with India's DPDP Act?

It helps but does not satisfy DPDP by itself. DPDP Rule 6 defines reasonable safeguards as encryption, access controls, and one-year log retention, a subset of HIPAA controls, so a HIPAA-grade setup generally clears DPDP's technical floor. You must still address data residency, keeping Indian patient data in-country, and the Act's ₹250 crore maximum penalty makes documented safeguards worthwhile.

I signed a Claude API BAA in early 2025. Does it cover the Enterprise plan?

Not if it was signed before 2 December 2025. A BAA signed before that date covers only API usage and does not extend to the HIPAA-ready Enterprise plan, so you need a new BAA to add Enterprise. BAAs signed on or after 2 December 2025 can cover both the API and the Enterprise plan under a single agreement.

How eCorpIT can help

eCorpIT is an ISO 27001:2022 certified, CMMI Level 5 engineering organization that builds healthcare and life-sciences applications for Indian and global providers. We design applications aligned with HIPAA and DPDP requirements, wire up the access controls, audit logging, and data-residency architecture that a Claude BAA leaves on your side, and choose the right Claude surface for each PHI workflow. See our clinical AI deployment service and healthcare app development service, or contact us to scope a compliant deployment.

References

  1. HIPAA-ready Enterprise plans — Anthropic (Claude Help Center), coverage, enablement, and the 2 December 2025 BAA cutoff.
  2. Covered Models under a Business Associate Agreement (BAA) — Anthropic.
  3. JPM26: Anthropic launches Claude for Healthcare — Fierce Healthcare, 11 January 2026 (Kauderer-Abrams quote).
  4. HIPAA-ready Claude API access and data retention — Anthropic API documentation.
  5. HIPAA violation fines, updated for 2026 — HIPAA Journal (penalty tiers effective 28 January 2026).
  6. Average cost of a healthcare data breach falls to $7.42 million — HIPAA Journal, IBM 2025 data.
  7. Data breach cost by industry, IBM 2025 — healthcare the costliest sector at $7.42 million.
  8. DPDP Act penalties and enforcement — TCSA (₹250 crore maximum penalty, Rule 6 baseline).
  9. Business Associate Agreements (BAA) for commercial customers — Anthropic.
  10. What is the Enterprise plan? — Anthropic.
  11. Anthropic Trust Center — Implementation Guide for HIPAA entities and compliance resources.

Last updated: 27 July 2026.

Top comments (0)