Is Claude Code HIPAA Compliant?
Decide whether your coding tool will receive real patient information. The question “is Claude Code HIPAA compliant?” has a conditional answer: the account, agreement, and developer surface matter.
Protected health information (PHI) is individually identifiable health information protected by HIPAA. A business associate agreement (BAA) sets the applicable obligations for a service provider handling PHI for a regulated customer. Zero data retention (ZDR) limits storage of inputs and outputs under an approved arrangement, with exceptions related to law or misuse.
Imagine two people building a remote-monitoring MVP. Using fictional fixtures and sending real patient records to the coding tool are separate decisions. Your vendor’s agreement does not replace your risk analysis.
Can my developers send patient information to Claude Code?
Yes, but only through eligible surfaces on a qualified account with an applicable signed BAA and approved ZDR configuration. That coding-tool coverage does not make your healthcare app compliant by itself or replace your organization’s risk analysis and safeguards.
Key takeaways
- Claude Code’s HIPAA coverage depends on your setup. PHI use requires an applicable signed BAA, approved ZDR, a qualified account and an eligible coding surface. A paid subscription alone does not establish coverage.
- Runtime API coverage and coding-tool coverage are separate. Teams needing HIPAA-ready runtime API access alongside ZDR coding usage need separate organization IDs.
- Check features and models before sending patient information. Some Code surfaces remain outside Anthropic’s BAA. Any model exception needs written confirmation of the account, surface, retention arrangement and agreement scope.
- Your startup still owns the app’s compliance responsibilities. Vendor agreements do not replace risk analysis, safeguards or engineering review. Use fictional patient records whenever real information is unnecessary.
Why founders use Claude Code to build a healthcare MVP
You can use an AI coding assistant without making it part of your patient-data workflow. For healthcare founders, that distinction is useful well before choosing a subscription: it lets you decide which development work can stay entirely on fictional records.
Consider a hypothetical digital health startup with two people building a remote-monitoring MVP. The development team could work through screens, permissions and test cases using invented patients. Its source code need not contain exports from electronic health records or examples copied from live support tickets. Assign engineering review and compliance ownership within the team.
The same separation matters in telehealth app development and mental health app development. A health tech startup can explore a workflow using fictional fixtures; replacing a real patient’s name does not automatically make an existing record safe to share.
Treat your coding-tool choice as one part of healthcare app development. Decide what developers need to send it.
What changes when the coding tool sees patient data
Your first question is whether the startup’s work brings it within HIPAA’s requirements. Covered entities and businesses performing applicable services involving PHI for them have different responsibilities from a company that merely makes a health-related product. Have a healthcare attorney confirm your role and proposed workflow.
For a non-technical founder evaluating Claude HIPAA requirements, ask developers to show where patient data could enter their work: prompts, attachments, repository fixtures, debugging output and contractor handoffs. A risk assessment should examine those paths alongside the MVP’s production environment. The vendor agreement does not replace your risk analysis or data security controls, and buying a tool does not make the app HIPAA compliant.
Retention deserves the same scrutiny. Anthropic’s zero data retention scope includes exceptions related to law and misuse, and safety classifier results may remain. Your own laptops, files and connected services need separate controls.
A business associate agreement also does not make an improvised de-identification process sufficient. Assess any protected health information before sending it out of the controlled workflow.
When considering HIPAA violation penalties, start with HHS HIPAA enforcement: HHS investigates complaints and conducts compliance reviews. Those processes warrant attention without assuming a universal fine or inventing a breach probability.
Which Claude Code setups have a BAA path
Check the access route your developers will actually use. Calling Claude HIPAA compliant without naming that route leaves the purchase decision unresolved. A Claude BAA for HIPAA must cover the relevant organization, coding surface and retention configuration.
Default public guidance (verified in October 2026):

Claude Code through Claude Enterprise
Buying Enterprise starts the conversation. You still need to verify the agreement and the coding configuration. Anthropic’s HIPAA-ready Enterprise plans guidance says enabling HIPAA readiness alone does not bring Code under the BAA, even if coding access comes with your seats.
If you are asking “is Claude Enterprise HIPAA compliant?”, make the purchase discussion specific: which organization, which signed agreement version, and which developer login route? For HIPAA compliant Claude usage in the eligible Code surfaces, ZDR must be enabled on a qualified account. Standard-retention Code remains outside Anthropic’s BAA.
Treat the Claude Enterprise HIPAA configuration and Code eligibility as separate items to confirm. Before anyone sends PHI, have Anthropic identify the account’s covered coding surfaces in writing. Share the confirmed boundary with your engineering lead.
Claude Code through the first-party Claude API
Decide separately how the finished app calls Claude and how developers use Code. A HIPAA-ready Claude API organization for runtime workloads does not make Code an eligible service in that organization. Teams needing that runtime configuration alongside ZDR coding usage need separate organization IDs.
When you request an Anthropic HIPAA BAA, describe both data flows. Anthropic’s HIPAA BAA must be paired with the approved coding configuration: the published default matrix permits Code through a regular first-party API organization with ZDR and the applicable agreement.
Use Covered Models under a BAA and API and data retention to confirm the distinction with your account team. Then document which organization employees and contractors use for each job. Keep runtime permission separate from developer access.

Claude Code through AWS Bedrock or Google Cloud Vertex AI
If your team already operates on AWS Bedrock or Google Cloud Vertex AI, evaluate that route against the environment you know how to manage. Anthropic’s BAA does not govern services bought through a third-party cloud provider; the provider’s agreement and service scope need review.
Bedrock appears in AWS HIPAA-eligible services, but regulated PHI use still requires the AWS BAA and compliant customer configuration. Google’s current documentation also uses Agent Platform terminology. Check Google Cloud HIPAA guidance for the exact service, model and feature route you intend to use.
A request for private HIPAA-compliant Claude access should therefore include the complete developer workflow. The cloud service’s eligibility does not certify local files or connected tools. Choose this path when your team can assess and operate it, rather than assuming it is universally safer or cheaper.
Plans that do not provide this BAA path
A developer’s paid personal subscription does not settle the PHI question. If the team asks “is Claude Pro HIPAA compliant?”, the relevant answer is that Free, Pro and Max do not provide the covered Enterprise or approved first-party ZDR coding route. Team is not the Enterprise HIPAA offering either.
That does not prevent developers from working on a healthcare product with a strictly non-PHI workflow. Assess what reaches the assistant, keep production information out, and retain responsibility for reviewing the resulting app. Use fictional fixtures deliberately; a lightly edited patient record is not automatically de-identified.
Which features stay outside the agreement
Check the feature as carefully as the subscription. The public Anthropic’s BAA feature table, checked October 1, 2026, excludes these Code surfaces from the listed coverage:
- Claude Code in the web.
- Desktop remote mode.
- Code Review and Code Security.
- Computer Use and Remote Control.
Desktop local mode is a different surface: it can be covered with ZDR on a qualified account. Switching from local to remote is therefore a coverage decision, even when the developer experiences both as part of the same product.
For teams asking “is Claude Cowork HIPAA compliant?”, Cowork remains outside Anthropic’s BAA. Third-party data flows through connectors or integrations require their own assessment. Do not interpret the Code web exclusion as a blanket prohibition on every Enterprise Web Search feature; the current Enterprise table lists Web Search as eligible.
Keep these distinctions in your team’s approved-tool policy. ZDR also does not erase information from a developer’s device or a connected service, and Anthropic’s arrangement retains legal and misuse-related exceptions. Review those locations too.
Check model access before accepting the retention trade-off
Before choosing a model for PHI-related coding work, confirm what retention setting that model needs. Covered Models such as Fable 5 and Fable 5.1 normally require 30-day retention, which conflicts with ZDR. Anthropic’s newer Covered Models policy also describes temporary, expressly authorized Fable ZDR arrangements while Enterprise Frontier Safeguards rolls out.
That development needs a narrower reading than “the newest models are now covered.” Anthropic’s public BAA guidance still says Covered Models cannot be accessed in covered Code configurations. The documented default Code path remains an applicable BAA with ZDR; standard-retention Code is outside that coverage.
If your organization receives an exception, obtain written confirmation identifying the model, account, coding surface, retention arrangement and BAA scope before sending PHI. An authorization about retention should not be treated as an automatic expansion of eligible services.
Until those details are confirmed, use the documented covered configuration with a permitted model. Keep separate model experimentation on fictional data.
Choose the setup for the data your MVP actually uses
Choose your route from the information entering the tool, then consider your launch stage. For a Claude Code HIPAA decision, “we are only a prototype” is less useful than a clear account of whether developers send it patient information. The signed agreement and eligible configuration matter when PHI enters the coding workflow.
The three stages below are a planning framework. They do not grant or remove obligations by themselves; keep risk analysis and operating controls alongside the purchase decision.
For a cloud route, verify the AWS or Google agreement and service scope. For prototypes, check that fictional or properly de-identified examples meet the intended boundary.

Prototype with synthetic data
For the hypothetical two-person remote-monitoring team, use completely fictional patient records to explore the product. Keep the prototype’s synthetic data separate from production traces, including the examples someone might paste into a prompt while debugging. A non-PHI development workflow is a different decision from buying a PHI-capable coding setup.
If you want to use de-identified data instead, apply the actual standard. HHS de-identification guidance describes Safe Harbor and Expert Determination; replacing a name is not sufficient. Creating a de-identified dataset from PHI is itself a PHI use requiring an appropriate route.
Document where prototype examples came from. Include that boundary in your risk review, so a demo that starts with fictional fixtures does not quietly acquire real patient records later.
An MVP that touches real PHI
Map production and developer data flows separately before a real-patient launch. If the app uses a HIPAA-ready runtime API, that agreement does not cover Code in the same organization; a team needing both that runtime arrangement and ZDR coding usage needs separate organization IDs.
You may decide developers should continue using fictional fixtures even when production handles PHI. If Code itself needs patient information, obtain confirmation of the signed BAA, qualified account, ZDR setting and eligible surface first.
Assign responsibility for maintaining that boundary in the launch plan. Budget for engineering review, safeguards and the subscription. The vendor agreement supports a defined relationship; your organization still needs its own risk analysis of the app and the surrounding workflow.
Scaling and selling to hospitals or payers
Prepare an evidence packet you can use when investors ask about due diligence or enterprise customers send a security questionnaire. Treat it as practical preparation rather than a promise that every buyer asks the same questions.
Include:
- Applicable agreements and their service scope.
- The organization used for each data flow.
- Your risk assessment.
- Access controls and audit logs.
- Contractor access and incident-handling ownership.
Your analysis needs to cover the full workflow, not just the coding vendor.
When discussing Anthropic HIPAA compliance, distinguish the vendor’s configuration from your startup’s controls. For example, explain what stays on developer devices and which connected services receive information. ZDR does not eliminate those storage locations or its own legal and misuse-related exceptions.
Keep the packet aligned with your actual setup so you can explain agreements and responsibilities when a buyer asks.
Budget for the workflow, not just the coding seat
Start with eligibility, then ask for a quote. For Claude Code HIPAA compliance planning, a cheap seat that does not support your intended PHI workflow is not a substitute for the required agreement and configuration.
As checked in October 2026, Claude pricing lists Enterprise at US$20 per seat per month, billed annually, plus usage at API rates. Pro is $20 monthly or $200 billed annually; Max starts at $100 monthly. Prices exclude tax and do not establish qualified ZDR eligibility or the total price of your deployment.
When requesting Claude’s HIPAA-compliant pricing, build your startup budget around these categories:
Usage depends on the model, repository size and work patterns; API-based charges follow token consumption. Avoid turning a subscription price into a forecast for the whole team.
Compare time to market against the work your team must still own. Risk analysis and reasonable safeguards remain your responsibility alongside vendor contracts, so include that effort before selecting a route.
Six decisions before your developers use Claude Code
Give your engineering lead a documented boundary before PHI-related coding begins. Use this checklist to turn Claude HIPAA compliance requirements into decisions with owners, rather than leaving contractors to interpret a subscription name.
- Map the data. Have the engineering lead identify what prompts, files, fixtures and logs could reach the assistant. Use fictional examples where real information is unnecessary; removing a name alone does not establish de-identification.
- Choose the route. Have the founder and technical owner distinguish coding access from runtime API access. If you need HIPAA-ready runtime API usage and ZDR coding usage, plan separate organization IDs.
- Confirm the agreement and retention. Have the authorized buyer secure the applicable BAA and confirm approved ZDR, account eligibility and coding surfaces with Anthropic before PHI use.
- Restrict surfaces and models. Have the technical owner document allowed features. Excluded remote or web surfaces should not become casual substitutes; any Fable ZDR exception needs explicit contractual confirmation before PHI use.
- Govern employee and contractor access. Have the engineering lead specify the account for each job and assess connected tools separately. Third-party transfers and local files remain part of the data flow, even with ZDR.
- Record the assessment and review changes. Have the compliance owner document responsibilities using HHS risk analysis guidance. Revisit the workflow when accounts, models, contractors or services change.
Watch for shortcuts that defeat those decisions: treating paid access as covered, assuming the runtime API agreement covers Code, pasting live logs, mixing organizations, or changing a model without reviewing its scope. For each exception, ask who approved the route and what information it permits. Have the responsible owner document that decision so the next contractor does not have to infer permission from an earlier debugging session.
What to compare across AI coding tools
Compare the workflow you would operate, not a broad compliance label. When asking “is Claude AI HIPAA compliant?”, specify the contract, retention and surface. Claude Code’s documented covered path depends on an applicable BAA, ZDR and eligible account and surface.
Apply the same buying questions across tools:
- What services does the agreement cover?
- Where does data go?
- Who controls access?
- Who owns engineering review?
For a cloud-provider route, check the provider’s scope rather than assuming the model vendor’s BAA carries over.
Compare remaining team effort. Usage costs vary with model and workload, while risk analysis remains an organizational responsibility. A coding assistant and an application-building service are different purchasing decisions; assess each against the work you want your team to own.
How Specode can help you move from code to a healthcare app
With Specode, you retain rights in your data, content, generated code and applications, exportable during your subscription and for 60 days after termination. Those rights do not transfer Specode’s platform IP or third-party services.
Specode’s healthcare app builder accepts plain-English requirements for responsive web apps, including UI, workflows, data models, permissions and integrations. Its healthcare technology and compliance specialists provide Pro’s senior product-manager consultation, weekly support, bug fixes and small implementations.
Production requires Pro or higher and runs on your own Convex account under the standard hosting BAA you sign with Convex. On Pro, patient data stays in that production account, so Specode does not handle it; real patient data may not be used in building, testing or preview on any plan. The team helps identify separate agreements for added services.
Specode’s Custom plan is another option for complex projects requiring advanced integrations, such as EHR connections or legacy systems. Specode’s team builds and maintains your app with managed services and dedicated support, and Specode signs a BAA with you. You retain clinical, legal, privacy, product, validation and compliance ownership, including risk analysis and third-party agreements; you manage added integrations’ configuration, maintenance, security and costs.
To move beyond “is Claude HIPAA compliant?” and decide who will build your app, Book a demo to discuss your launch requirements.
Frequently asked questions
Yes, in eligible configurations. When asking “can Claude be HIPAA compliant?”, distinguish the product: Code requires an applicable BAA, approved ZDR and eligible account and surface. Your organization still owns its compliance obligations.
Yes, for eligible configurations. The documented Claude Code path requires an applicable signed BAA and approved ZDR. Enterprise HIPAA enablement alone does not cover Code, so confirm your account and coding surface with Anthropic before sending PHI.
Yes, for a strictly non-PHI development workflow. Pro and Max do not provide the covered Enterprise or approved first-party ZDR coding route. Keep real patient information out of prompts, files and debugging examples on those plans.
A completely fictional-data workflow is different from sending PHI to a service. Verify that examples contain no patient information. If you create de-identified data from PHI, that processing itself requires an appropriate route before the dataset is shared.
Bedrock is a HIPAA-eligible AWS service. PHI use requires the AWS BAA and compliant configuration; Anthropic’s BAA does not apply to services bought through AWS. Verify the complete coding workflow rather than assuming the listing covers everything.
Claude Code can be part of the development workflow, but choosing it does not establish app compliance. Use fictional fixtures or a confirmed PHI-eligible coding configuration, and retain responsibility for risk analysis, safeguards and applicable agreements.








