A BAA is available in two configurations — and Enterprise self-serve orgs qualify
Anthropic will sign a Business Associate Agreement — the HIPAA contract that must exist before Claude can touch protected health information — in two setups: a HIPAA-ready API organization, or an Enterprise plan with HIPAA turned on. The takeaway: you can set either up yourself — no sales call needed. The exact wording and the mechanics are in the detail below.
Detail, source & related
Detail
Do not rule yourself out — on either path.
The API path is self-serve too. “There are two ways to set up HIPAA-ready API access. Most organizations can enable it directly in the Claude Console with Anthropic’s standard BAA; organizations that require a negotiated BAA should work with their account team.” The mechanics: “In Claude Console > Settings > Privacy, organization admins with the HIPAA management permission see a HIPAA compliance card.” For a small technical team — plausibly the cheapest compliant route for a registry project — this matters as much as the Enterprise correction below.
Two API-path facts worth deciding on early:
- You do not need ZDR as well. “Do I still need ZDR if I have HIPAA readiness? No.” HIPAA readiness “applies a broader set of privacy and security safeguards than ZDR … rather than requiring immediate deletion.”
- HIPAA is enforced org-wide, so mixed workloads need two orgs. “HIPAA readiness is enforced at the organization level. If you need both HIPAA-ready and general-purpose API access, use separate organizations for each.” Decide this before you build, not after.
Now the Enterprise path. The source’s own eligibility banner reads: “This feature is available for Enterprise plans only (both self-serve and sales-assisted).” And on getting started: “Eligible Enterprise organizations can enable HIPAA-ready configuration directly from organization settings—no sales or legal cycle required. The Business Associate Agreement (BAA) is included in the flow as click-to-accept, so there’s no separate document to sign and return.”
Who can do it. “Only the Primary Owner of the organization can accept the BAA and enable HIPAA. Other Owners or Admins can’t complete this flow on the org’s behalf.” If you are an admin but not the Primary Owner, the source’s instruction is to ask your Primary Owner to sign in and complete enablement.
Who cannot. “You can enable the HIPAA configuration from organization settings if your organization is on an Enterprise plan. Team plans and individual plans (Free, Pro, and Max) can’t enable HIPAA.” See Most ways of using Claude are never covered by Anthropic's BAA — and on two cloud platforms, coverage is someone else's call.
Two things to know before you click — both are one-way.
- “Enabling HIPAA resets certain settings across your organization. Some configurations return to defaults as part of the transition to a HIPAA-ready state.” The onboarding modal and the Implementation Guide detail what changes.
- “This is a one-way decision. Once HIPAA is enabled and the BAA is accepted, the change can’t be reversed from organization settings.” The source requires reviewing the BAA and the Implementation Guide before accepting, “as this is an irreversible organization transition.” Note also: “The BAA offered through the self-serve flow is a standard agreement and can’t be modified.”
If you already have an API BAA — check the date. “If your organization signed a BAA for Claude API usage before December 2, 2025, that agreement only covers API usage—it does not extend to the HIPAA-ready Enterprise plan. To add this Enterprise plan access, you’ll need to sign a new BAA with your account team.” And: “BAAs signed after December 2, 2025 can cover both API usage and the Enterprise plan under a single agreement.” An org that signed early and assumes it is covered on both surfaces is not.
Coverage is still not automatic on the right plan — the enablement path must be walked (HIPAA coverage must be actively enabled — an Enterprise contract alone is not a BAA) — and enabling HIPAA does not sweep every feature under the BAA (Claude Code: not covered on the API path at all; on Enterprise only with ZDR. Cowork: not yet covered, Most ways of using Claude are never covered by Anthropic's BAA — and on two cloud platforms, coverage is someone else's call). Which configuration fits an advocacy nonprofit’s needs and budget is the group’s first question in this domain: Which BAA configuration fits an advocacy nonprofit's needs. (Scoped at CG4. This read “the group’s first question for the contact” — as did the retention module’s pointer to a different question. Two nodes each claiming the register’s top slot cannot both be right. The register now carries an explicit per-module order: this question leads the HIPAA list, and the plan-and-terms question leads retention’s. Neither claims to outrank the other across the whole register, because the register groups by module and nothing in it can make that claim true.)
Source & currency
- Source: HIPAA-ready Enterprise plans — Claude Help Center (Enterprise path) · API and data retention — Claude Docs (API path, ZDR-not-also-needed, org-level enforcement).
- Status: CONFIRMED — re-verified 2026-07-28 (receipts R11, R12, R36, R37) — every quoted passage verified on the live pages 2026-07-25 and re-verified 2026-07-28, when the API docs page joined the chip list (the API-path claims — the two-ways setup, the Console mechanics, the ZDR-not-also-needed answer, the org-level enforcement — live there, and the chip previously named only the Enterprise article); the Enterprise page itself showed “Updated this week.” Second-pass correction, same day, after independent review: the first rewrite fixed the restrictive error on the Enterprise path but still described the API path without saying it is also self-serve — leaving an API-only organization to infer that a sales cycle was required for theirs. Same error class, smaller blast radius; now stated for both paths. Corrected 2026-07-25 — this was the most consequential error found on this site. The prior version said a BAA required a “sales-assisted Claude Enterprise plan,” which would lead a self-serve Enterprise organization to conclude it was categorically ineligible and stop pursuing a BAA it in fact qualifies for. That is an error in the restrictive direction: it stops care. The self-serve enablement path, the Primary-Owner restriction, the settings-reset, the irreversibility, and the December 2, 2025 BAA cutover were all absent and are now stated.
- ⚑ Compliance-critical: BAA eligibility moves — confirm current specifics with your Anthropic contact before relying on this for a compliance decision. This is a teaching aid, not compliance or legal advice.
Related
- HIPAA & Patient Privacy — parent domain
- Most ways of using Claude are never covered by Anthropic's BAA — and on two cloud platforms, coverage is someone else's call — the complement: what is never BAA-eligible
- HIPAA coverage must be actively enabled — an Enterprise contract alone is not a BAA — coverage must be switched on, even on the right plan
- Claude Code: not covered on the API path at all; on Enterprise only with ZDR. Cowork: not yet covered — enabling HIPAA alone does not bring Claude Code under the BAA
- Which BAA configuration fits an advocacy nonprofit's needs — which of the two fits an advocacy nonprofit
- BAA — Business Associate Agreement — the term, plainly
- Primary Owner — the role that accepts the BAA