Bible Network Crypto DeFi Onchain RWA AI Agent Stablecoin Chain SAFU CryptoTax DeFAI AGI Claude Me Claude Skill Claude Design Claude Cowork
Independent Media
Not affiliated with any project
Let Claude Do the Work, Not Just Answer
claudecowork-me.com
LATEST
A Note for Healthcare Teams: Claude Cowork Isn't Covered Under Anthropic's HIPAA BAA, No Matter Your Plan Tier  ·  What Does the Effort Control in Cowork Actually Adjust? It's Not the Same Thing as Switching Models  ·  Claude in Chrome's Side Panel Now Runs Full Cowork Sessions: Start a Task in Your Browser, Finish It on Your Phone  ·  Before You Chain Excel and PowerPoint in Claude Cowork, Understand How Data Actually Flows Between Them on Its Own  ·  When Should You Use Claude Cowork Instead of Just Chatting? Anthropic's Five-Point Checklist  ·  Using Claude Cowork's Legal Plugin Without Reconfiguring It? You Might Be Reviewing Contracts Against the Wrong Country's Law
advanced

A Note for Healthcare Teams: Claude Cowork Isn't Covered Under Anthropic's HIPAA BAA, No Matter Your Plan Tier

30-Second Version · For the impatient
Straight from Anthropic: Cowork isn't an Eligible Service under the BAA in any configuration — it's not a setting you missed, it's excluded at the architectural level.

Full Explanation +
01 · Why did this happen?

If my organization has already enabled HIPAA compliance mode, does that mean we can safely handle patient-related administrative work (not actual medical record content) in Cowork?

That's not recommended. Enabling HIPAA compliance mode covers your Enterprise Chat interface — it doesn't automatically extend to Cowork, and Anthropic's documentation explicitly excludes it. Even if you consider a piece of administrative work to "not involve actual medical record content," the moment it touches a patient's name, appointment time, insurance information, or other personally identifiable information, it already falls under PHI — and Cowork sits entirely outside BAA protection, regardless of how low-risk you personally judge it to be.

The more conservative and safer standard is treating "could this task touch any information that identifies a patient" as the sole criterion, rather than judging for yourself whether something counts as "real" medical record content. If the answer is that it could, the work should go through a Chat interface with HIPAA compliance mode enabled instead of staying in Cowork.

02 · What is the mechanism?

Since Cowork is explicitly not covered under the BAA, does that mean Anthropic completely prohibits using Covered Models in Cowork?

No, it's not a complete prohibition — this is a point that's easy to misread in that official line. The exact wording is: you can use Covered Models in Claude Code or Cowork outside the BAA, but don't submit protected health information. That means the usage itself is permitted; what's actually drawn as a hard line is the specific act of submitting PHI, not the use of Cowork as a tool in general.

This distinction matters in practice: if your organization has general knowledge work that genuinely doesn't touch PHI (organizing internal meeting notes, compiling operational reports with no patient information, say), that work can absolutely continue in Cowork unaffected by this restriction. What genuinely calls for caution are workflows where the work itself touches patient data — no matter how carefully those are handled, if the data is inherently PHI, it already constitutes a disclosure outside BAA protection.

03 · How does it affect me?

If my organization uses Claude deployed through AWS Bedrock or Google Cloud Vertex AI, does this limitation still apply?

The limitation this article discusses refers to the BAA Anthropic signs directly, applicable when using Claude through Anthropic's own channels (the 1P API, Claude Enterprise). If your organization deploys Claude through AWS Bedrock or Google Cloud Vertex AI, that's an entirely separate compliance path — the data processing agreement is signed with AWS or Google Cloud, not directly with Anthropic, and falls under those cloud platforms' own HIPAA compliance mechanisms.

But this also implies something worth noting: Cowork's current product positioning is fundamentally tied to Anthropic's own desktop app and account system. If your organization deploys Claude through a third-party cloud platform like AWS Bedrock or Vertex AI, that typically means you're using an API-level integration rather than the Cowork desktop agent product itself — in other words, this particular limitation may already have limited relevance for organizations deploying through a cloud platform. Still, it's worth confirming directly with your cloud partner or your Anthropic account team whether Cowork specifically is available under your deployment architecture, and which agreement governs it.

04 · What should I do?

If our team has already been handling work in Cowork over the past few months that might involve PHI, and we're only now discovering this limitation, how do we remediate it?

First, don't panic — the first step is honestly taking stock of past usage: specifically which tasks, what level of patient information was involved, and which team members were doing the work. This inventory itself helps you gauge the actual scope and severity of exposure, rather than guessing from memory. If your organization is on an Enterprise plan, you can retrace specific tasks and timing through the Compliance API or any existing OpenTelemetry streaming records you've set up.

Once that inventory is done, the more practical next step is consulting your organization's internal compliance or privacy office to assess whether the situation rises to something requiring formal reporting — that's a compliance-level judgment call this article can't make on your behalf. At the same time, immediately route any future work touching PHI through a Chat interface with HIPAA compliance mode enabled, and clearly communicate to the team the boundary that Cowork can't be used for any task that might involve patient information, to prevent the same situation from recurring. The earlier this gets addressed, the more room there typically is to remediate.

Full Content +

If your organization handles protected health information (PHI), there's one thing to confirm before deciding whether to use Claude Cowork: regardless of which plan tier you're on, Cowork currently isn't covered under Anthropic's HIPAA Business Associate Agreement (BAA). This isn't a matter of some setting not being enabled on an Enterprise plan — Anthropic's own documentation states plainly that Cowork isn't an Eligible Service under the BAA in any configuration. This piece breaks down what that actually means and how to think about your workflow if PHI might come into play.

The Official Wording Is Direct

There's a line in Anthropic's documentation worth quoting exactly: Cowork isn't an Eligible Service under the BAA in any configuration — you can use Covered Models in Claude Code or Cowork outside the BAA, but don't submit protected health information. The key phrase is "in any configuration" — meaning there's no setting to adjust or advanced option to enable that brings Cowork under the BAA's protection. It's excluded at the architectural level.

Even an Enterprise Plan Doesn't Change This

This particular point is easy to misunderstand, because a HIPAA-ready Enterprise plan genuinely does cover Claude's regular chat functionality — an Enterprise Primary Owner can enable HIPAA compliance mode directly from Organization Settings under "Data and Privacy" and accept the BAA. Once enabled, the standard Chat interface can use Covered Models under standard retention with no additional configuration changes needed. But Anthropic's documentation specifically warns that enabling HIPAA readiness alone doesn't bring Claude Code or Cowork along with it — Claude Code requires Zero Data Retention (ZDR) to be additionally enabled before it's conditionally covered, while Cowork is excluded entirely, regardless of whether ZDR is on.

Why Cowork Specifically Gets Excluded

Anthropic's documentation doesn't spell out the technical rationale for the exclusion, but the logic behind this limitation can be inferred from how Cowork actually works. Cowork is an agentic product that proactively reads local files on your computer and connects, via MCP, to authorized SaaS applications you've connected — Slack, Google Drive, Gmail, Notion, Jira, and others. The data sources it touches are distributed and broad, and it's the agent itself that autonomously decides what content to read, which is a fundamentally different data flow than a regular chat interface, where Claude only processes whatever content you actively paste in. This kind of proactive, cross-system access architecture naturally involves more technical and contractual complexity to meet HIPAA's data-processing compliance standards — a reasonable backdrop for why Anthropic hasn't yet brought Cowork under BAA coverage.

Claude Code's Situation Is a Useful, if Different, Comparison

How Claude Code's BAA coverage works offers a useful point of contrast: the CLI (via the official API console or Enterprise OAuth) and Desktop local mode can be covered under the BAA once Zero Data Retention is enabled, while Desktop remote mode, the web version, Code Review, Code Security, and other variants remain excluded. That means "BAA coverage" for Claude Code is a spectrum that depends on configuration and usage mode, not an all-or-nothing question. Cowork's situation is more direct — Anthropic's own wording is "not an Eligible Service in any configuration," with no equivalent path like Claude Code's "enable this one setting and get coverage."

What This Actually Means If You're Already Using Cowork

This doesn't mean Cowork can't be used at all — you can still use Covered Models within Claude Code or Cowork, you just can't submit PHI into them. That line draws a clear usage boundary: if your work genuinely doesn't touch patient data, health records, insurance information, or other protected information, using Cowork for other general knowledge work tasks isn't affected by this restriction. But the moment work might touch PHI — even something as simple as pasting a patient's name alongside a question into Cowork — that already constitutes a data disclosure outside BAA protection, regardless of how carefully or precisely it's configured.

What This Means for Your Work

If your organization is a HIPAA covered entity or business associate, the first step is taking honest stock of which people and which workflows on your team are actually using Cowork today, and assessing whether those workflows could plausibly touch PHI. Often the risk doesn't come from deliberately pasting patient data in — it comes from something like asking Cowork to summarize meeting notes or compile a report, where PHI gets swept in incidentally alongside other information being read. If that assessment turns up a genuine possibility of PHI exposure, the more practical move is routing that workflow back through a BAA-covered interface (an Enterprise Chat with HIPAA compliance mode enabled, say), and reserving Cowork for general work that genuinely doesn't touch PHI. If you're not sure whether a particular workflow is safe, the most conservative and least error-prone approach is assuming it isn't, until you can clearly rule out PHI exposure.

Sources: Covered Models under a Business Associate Agreement (BAA) - Anthropic Help Center, HIPAA-ready Enterprise plans - Anthropic Help Center, Business Associate Agreements (BAA) for Commercial Customers - Anthropic Privacy Center
Ask a Question
Please enter at least 10 characters
Related Articles
Claude Cowork Can Finally Be Audited: Compliance API Now Covers Cowork Sessions — What Changed, and What Gaps Remain
advanced · Sep 02
What Does the Effort Control in Cowork Actually Adjust? It's Not the Same Thing as Switching Models
advanced · Sep 10
Claude Cowork's "Automatically Approve" vs. "Skip All Approvals": One Word Apart, but a Different Safety Net Entirely
advanced · Sep 02
Why Does Your Claude Cowork Connector Keep Asking You to Reauthenticate? Three Real Causes That Aren't What You'd Guess
advanced · Sep 01
More Related Topics