Is Claude HIPAA Compliant?
Not the app your staff downloaded. But Claude has more BAA-covered routes into healthcare than almost any model, if you pick the right one.
The Verdict
Claude's consumer products (Free, Pro, and Max) are not HIPAA compliant. Anthropic's BAA explicitly excludes them, along with Team plans, and consumer conversations are used for model training unless the user opts out.
Compliance is possible on commercial paths where a BAA exists, Anthropic's API for eligible customers, and Claude served through AWS Bedrock or Google's covered cloud products, each carrying its own BAA chain.
| Path | BAA | Trains on your data | Verdict for PHI |
|---|---|---|---|
| Claude app, Free / Pro (consumer) | No | Possible, per user training-preference setting | Never |
| Claude Team | No (excluded from Anthropic's BAA, along with Free, Pro, and Max) | No (commercial data excluded from training) | Never, until Anthropic changes eligibility |
| Claude Enterprise | Yes: HIPAA-ready plan setting plus signed BAA | No | Possible, with controls in place |
| Anthropic first-party API (HIPAA-ready) | Yes: admin signs BAA, sales enables | No | Possible, for vetted applications |
| Claude via AWS Bedrock or Google Cloud covered products | Yes, through the cloud provider's BAA | No (zero-retention configurations available) | Possible; this is how most healthcare Claude deployments run |
The cloud path explains something buyers notice: several healthcare Claude products, including tools in our platform comparison, are built on Bedrock-hosted Claude precisely because the AWS BAA chain is mature.
The Question Behind the Question, Whose BAA?
Four realities that decide whether a Claude deployment carries PHI legally
A BAA follows the deployment, not the model
"Claude" is one model with at least three contractual routes. The BAA you need is with whoever operates the service your data touches: Anthropic directly, AWS, or Google.
Chained vendors need chained agreements
If you buy a product that uses Claude underneath, your BAA is with that product's vendor, and their BAA with their model provider is their obligation. Ask for evidence of the full chain.
Consumer settings are not contracts
A staff member who opted out of training on a personal Claude account is still outside any BAA. Opt-outs are privacy preferences; HIPAA requires paper.
The commercial no-training default is real but scoped
Anthropic excludes commercial data from training. Confirm which of your account types count as commercial, in the agreement.
Claude is one entry in a longer list of AI tools healthcare organizations are already running without a paper trail. For the fuller HIPAA and AI compliance picture, across every tool your staff might already be using, see HIPAA and AI compliance.
Claude and HIPAA: Common Questions
Does Anthropic sign a BAA?
Yes, for two paths: the HIPAA-ready first-party API (admin signs the BAA, then sales enables it) and Claude Enterprise plans (HIPAA setting in admin data and privacy settings, plus the BAA). Anthropic's own article excludes Free, Pro, Max, Team, Workbench, Console, and beta features from coverage.
Is Claude Pro HIPAA compliant?
No. Pro is a consumer subscription with no BAA path. The subscription price does not change its status, the same pattern holds across consumer AI subscriptions in general.
Does Claude train on our conversations?
Consumer accounts (Free, Pro, Max), training applies unless the user opts out, with users prompted to choose at signup, and opted-in data retained up to five years. Commercial accounts (API, Work, Enterprise, Education) are excluded from training under Anthropic's commercial terms. The consumer-side default is exactly why personal accounts and PHI cannot mix.
Is Claude through AWS Bedrock HIPAA compliant?
Bedrock is a HIPAA-eligible AWS service. Under an AWS BAA with proper configuration, Claude on Bedrock can serve PHI workloads. Your architecture and access controls still decide whether the deployment is actually compliant.
Which path should a hospital pick?
If you are building, Bedrock or a covered Google Cloud product, because cloud BAAs and audit tooling are mature. If you are buying staff access, a governed platform that carries the BAA chain and gives you org-wide logging, rather than direct consumer or single-seat accounts.
Related Reading
AI Tool HIPAA Compliance Directory
BAAs, training policies, and verdicts for the AI tools your staff actually use, in one place.
Read article →Is ChatGPT HIPAA Compliant?
Consumer, Plus, Team, and Enterprise tiers each answer differently.
Read article →Is Gemini HIPAA Compliant?
Google's consumer, Workspace, and Vertex AI postures are three different answers.
Read article →One Model, Three Contracts, Zero Shortcuts
Before any Claude path carries PHI, your policy needs to name which one is sanctioned and for whom. Generate a healthcare-ready draft in minutes.