BAA Generator
HomeResourcesDoes Anthropic Sign a HIPAA BAA?
Vendor BAA Guide

Does Anthropic Sign a HIPAA Business Associate Agreement?

By BAA Generator Research Team  ·  Published Apr 19, 2026  ·  Last reviewed Apr 28, 2026  ·  3 min read

Need a BAA right now?

Generate my BAA → Download Free BAA Template → See pricing →

Key Takeaways

Direct answer: Yes — Anthropic signs a HIPAA Business Associate Agreement for Claude for Enterprise and qualifying API customers who execute a Data Processing Addendum (DPA) including HIPAA BAA provisions. Claude.ai Free, Pro, and Team plans cannot be used with PHI. Contact Anthropic's enterprise team to initiate the BAA process before processing any protected health information.

Anthropic Product HIPAA Coverage at a Glance

Anthropic Product HIPAA BAA Available? Notes
Anthropic API (enterprise) Yes DPA with HIPAA BAA provisions; contact enterprise sales
Claude for Enterprise Yes BAA available through enterprise agreement
Claude.ai Free No Consumer product; not HIPAA eligible
Claude.ai Pro No Consumer subscription; not HIPAA eligible
Claude.ai Team No Not covered by BAA; verify current status with Anthropic

Claude Enterprise BAA Eligibility

Claude Enterprise is Anthropic's offering specifically designed for organizations that need administrative controls, security guarantees, and compliance frameworks — including HIPAA. Unlike consumer Claude.ai plans, Claude Enterprise customers can execute a HIPAA BAA with Anthropic as part of the enterprise contract.

What's covered under the Claude Enterprise BAA:

Common Claude Enterprise healthcare use cases: clinical decision support drafting (with physician review), patient communication drafting, summarizing intake notes for quality review, building internal compliance reports. Always pair with appropriate clinical workflows — Claude is a tool, not a substitute for clinical judgment.

Claude Enterprise pricing is custom (not published) and starts at meaningful annual commitments. Contact Anthropic sales to scope a healthcare-focused deployment.

Anthropic API BAA for Healthcare Customers

The Anthropic API can be used in HIPAA-compliant healthcare applications when you execute a Data Processing Addendum (DPA) with Anthropic that includes HIPAA BAA provisions. This is the most common path for healthcare AI startups, EHR vendors integrating Claude, and digital health applications building Claude-powered features.

What the API BAA covers:

Critical implementation guidance for healthcare API users:

How the Anthropic API BAA Process Works

For organizations building healthcare AI applications on the Anthropic API (using Claude models), the path to HIPAA compliance involves executing a Data Processing Addendum with Anthropic that includes HIPAA Business Associate Agreement provisions.

The typical process:

What Claude.ai Consumer Plans Cannot Do

Claude.ai's consumer tiers — Free, Pro, and Team — are not covered by any HIPAA BAA. This means:

This is a meaningful risk for healthcare organizations where clinicians may personally subscribe to AI tools and begin using them with patient data. Governance policies and staff training are essential to prevent unauthorized PHI exposure through consumer AI tools.

Building HIPAA-Compliant Healthcare AI with Claude

Healthcare technology companies using Claude via the Anthropic API should build their HIPAA compliance framework to include:

Frequently Asked Questions

Does Anthropic sign a HIPAA BAA?

Yes — for Claude Enterprise and qualifying API customers who execute a DPA with HIPAA BAA provisions. Claude.ai Free, Pro, and Team cannot be used with PHI. Contact Anthropic's enterprise team to execute a BAA.

Can I use Claude for healthcare applications?

Yes — via the Anthropic API or Claude Enterprise with an executed BAA. Consumer Claude.ai plans cannot be used with PHI under any circumstances.

Is the Anthropic API HIPAA compliant with a BAA?

The Anthropic API can support HIPAA-compliant applications when you have an executed DPA/BAA. HIPAA compliance is shared — Anthropic covers their infrastructure; you must implement safeguards in your own application and systems.

For a broader look at which AI vendors sign HIPAA BAAs, see our vendor BAA lookup guide.

Note: Vendor BAA policies change. Verify current terms directly with Anthropic before making compliance decisions.

More vendor BAA guides

Generate a compliant BAA in 5 minutes

HHS model BAA provisions · 45 CFR § 164.504(e) compliant · clean PDF + editable Word

No subscription · PDF + Word · Free watermarked preview

Related: AI vendors

Frequently Asked Questions

Does Anthropic sign a HIPAA BAA?
Yes — Anthropic signs a HIPAA BAA for Claude for Enterprise and qualifying API customers who execute a Data Processing Addendum (DPA) that includes HIPAA BAA provisions. Claude.ai Free, Pro, and Team plans are not covered by a BAA and cannot be used with PHI.
Can I use Claude for healthcare applications?
Yes — if you are using the Anthropic API or Claude Enterprise with an executed BAA/DPA, you may build healthcare AI applications that process PHI. The standard consumer Claude.ai plans (Free, Pro, Team) cannot be used with PHI under any plan.
Is the Anthropic API HIPAA compliant with a BAA?
The Anthropic API can be used in HIPAA-compliant healthcare applications when you have executed a Data Processing Addendum (DPA) with HIPAA BAA provisions with Anthropic's enterprise team. Contact Anthropic's sales team to initiate this process.