For clinicians
A reading order, not a separate site. These are the same findings the rest of this curriculum carries, with the same chips and the same receipts — sequenced for someone who works with patients and did not build these tools.
This is a teaching aid, not compliance or legal advice — patient-data decisions belong to your organization, its counsel, and its Anthropic contact. Where this comes from: every step below links to its full finding, which carries its own provenance; ✓ items were checked against Anthropic's primary pages on the date shown — see the verification log.
How to read the chips
- Confirmed checked against Anthropic’s own page on the date shown, and the receipt kept.
- Documented not checked against an Anthropic page this round — either carried from the working group’s document, or this curriculum’s own practice recommendation. The source chip says which.
- Stale risk known-volatile, or the check found a discrepancy — treat as a question, not a fact.
- compliance a claim a patient-data decision could hang on — always confirm with your Anthropic contact first.
- our practice a practice recommendation — this curriculum’s or the working group’s — not an Anthropic product fact.
-
start here — most ways of using Claude are never covered for patient data, and that is the first thing to know
Step 1 of 8: Most ways of using Claude are never covered by Anthropic's BAA — and on two cloud platforms, coverage is someone else's call
Two situations, easy to confuse. Most ways of using Claude — Free, Pro, Max, Team, Cowork, Claude Code on the API path, and more — are never covered by Anthropic's BAA: no PHI there. On Amazon Bedrock and Google Cloud's Agent Platform, coverage is the cloud provider's decision under its own BAA — a handoff, not a prohibition.
Confirmed · 2026-07-28 receipt R37 product fact compliance — confirm with your contact source: platform.claude.com also: support.claude.com -
the two configurations that can be covered, and what each requires
Step 2 of 8: A BAA is available in two configurations — and Enterprise self-serve orgs qualify
Anthropic will sign a Business Associate Agreement — the HIPAA contract that must exist before Claude can touch protected health information — in two setups: a HIPAA-ready API organization, or an Enterprise plan with HIPAA turned on. The takeaway: most organizations can set either up themselves, directly — an organization that requires a negotiated BAA works with its Anthropic account team instead. The exact wording and the mechanics are in the detail below.
Confirmed · 2026-08-03 receipt R63 product fact compliance — confirm with your contact source: support.claude.com also: platform.claude.com -
what to check before anything leaves your control — our practice, not a product fact
Step 3 of 8: A de-identification pre-flight — the checks to run before anything is pasted
✎ Our draft checklist, to run in the two minutes before patient-related text goes anywhere near Claude. The check that matters most is not "did I remove the name?" — it is "read what is left as a whole: how many people could this be?" In a rare disease the diagnosis is itself an identifier, so a condition plus a rough age plus a region can point at one person even though none of the three would alone.
Documented our practice source: curriculum synthesis -
what happens to what you type, on a commercial plan
Step 4 of 8: Commercial plans: no training by default and by contract — the exception is data you hand over yourself
On commercial plans (Claude for Work, the API, Claude Gov), your inputs and outputs are not used to train models — stated as a default in Anthropic's policy and as an obligation in the Commercial Terms. The exception is real and worth knowing: if you submit feedback or bug reports, or otherwise opt in, that data may be used for training. So the rule is "not by default — unless you hand it over."
Confirmed · 2026-09-16 receipt R76 product fact compliance — confirm with your contact source: privacy.claude.com also: www.anthropic.com also: platform.claude.com -
the feedback button — and the bug report — change that answer, and for how long
Step 5 of 8: The feedback button hands over the whole conversation for 5 years — and it, or a bug report, permits training
Clicking thumbs-up or thumbs-down is not a small act. It hands Anthropic the entire related conversation — content, settings, everything — for five years, on any plan. And on commercial plans it is one of the acts that permits training on your data, which is otherwise not allowed — filing a bug report does the same thing, and so does agreeing to any other arrangement that allows it. Never rate, and never attach to a bug report, a conversation that contains anything sensitive.
Confirmed · 2026-09-16 receipt R74 product fact compliance — confirm with your contact source: privacy.claude.com/how-long-do-you-store-my-org also: privacy.claude.com/how-long-do-you-store-my-dat also: privacy.claude.com/is-my-data-used-for-model-tr -
if your organization monitors Cowork, the unresolved question of whether that monitoring carries the words your staff typed — two Anthropic pages disagree
Step 6 of 8: Two Anthropic pages disagree on whether the Cowork OpenTelemetry export includes prompt content by default
Anthropic's documentation and Anthropic's help centre currently say opposite things about whether the Cowork monitoring stream carries the actual words your staff typed. The docs say events are metadata only unless you switch content capture on. The help centre says prompt content is included by default. For a group whose prompts may carry patient detail, that is the difference between "your monitoring system is now a store of patient information you have to govern" and "it isn't" — different retention rules, different access controls, different answer when someone asks where patient data lives. Do not settle this by picking whichever page you found first. Turn the export on against a test collector, send a prompt containing a harmless marker word, and look at what actually arrives. Your own collector is the only trustworthy answer.
Stale risk why flagged product fact compliance — confirm with your contact source: claude.com also: support.claude.com -
what Claude must not be trusted with — output risk, which no setting prevents
Step 7 of 8: Check every output before it reaches a person; never put credentials or PHI on an uncovered surface
Most of this site is about what Claude can reach — folders, files, connectors, screens — and how to narrow it. This node is the other half: what you do with what comes back, and what you never hand over in the first place. Two lists, both short, both ours.
Documented our practice source: curriculum synthesis -
the habit that outlives every fact on this site
Step 8 of 8: The three checks: available, eligible, checked
Every fact on this site has a date on it, because facts about these products move. Before you rely on any of it, run three checks — available · eligible · checked. It takes a minute or two, it is the same three checks every time, and it is the one thing here that does not go out of date.
Documented our practice source: curriculum synthesis
What this path deliberately leaves out
It does not cover Skills, secrets handling, connectors, or the working group's own advocacy use cases — and it reaches folder and desktop access at exactly one point, step 6's question about whether Cowork monitoring carries the words your staff typed. Those are not less important — they are a different reader's starting point, and they are all still here. Start at the home page for the full curriculum, or go straight to the open-questions register for what this group is still asking Anthropic.
The clinical use cases on this site are proposals of ours, not clinician-reviewed. They are written to tool posture: where one would assert clinical judgment, it states what the tool does and stops. See Skills.