What I may and may not do
Built to be printed and handed to someone — a colleague, a compliance officer, an IRB. It carries its own caveats and its own key, because paper cannot link anywhere.
This is a teaching aid, not compliance or legal advice. Decisions about patient data belong to your organization, its counsel, and its Anthropic contact. Anthropic's policies and products change frequently — confirm current specifics with your Anthropic contact before relying on any line of this sheet for a compliance decision.
Every ✓ and ⚠ rule below carries the date it was last checked against an Anthropic page; the newest on this sheet is 2026-09-19, and none is later. The 5 rules with no date were never checked against an Anthropic page. 16 Anthropic primary pages cited in all.
Counted as: distinct Anthropic-published pages cited by the 18 rules on this sheet.
5 lines below are marked ✎ our practice — practice rules from this curriculum and the working group's own document, NOT Anthropic product facts, and not part of that count.
- Confirmed checked against Anthropic's own page on the date shown
- Documented not checked against an Anthropic page — the group's document, or our own practice
- Stale risk treat as a question, not a fact
- compliance a patient-data decision could hang on this
- our practice a practice rule of ours, not an Anthropic product fact
You may
-
Give Claude one dedicated working folder. Never broad access to your desktop or documents.
Confirmed · 2026-07-25
-
Keep credentials in a secrets manager or environment variables — outside any folder Claude can read.
Documented our practice
-
On a commercial plan, what you type is not used to train models — by default and by contract.
Confirmed · 2026-09-16 compliance
-
Get a BAA in place before any patient data goes near Claude. Two configurations qualify — a HIPAA-ready API organization, or an Enterprise plan with HIPAA switched on. Most organizations can set either up without a sales call — one that requires a negotiated BAA works with its account team — and coverage is not automatic on the right plan: on the Enterprise path only the Primary Owner can accept the BAA, and switching HIPAA on cannot be undone from organization settings.
Confirmed · 2026-08-03 compliance
-
Run the de-identification pre-flight before anything is pasted.
Documented our practice
-
Write a simple Skill without any code — it is a Markdown file saying what the Skill does and when Claude should use it. Do not plan around an interactive builder: the skill-creator helper circulates in write-ups, and no Anthropic page we can find describes it.
Confirmed · 2026-07-27
-
Run the three checks every time: is the model available, is the feature eligible today, and did you check the output against a source you opened yourself.
Documented our practice
You must not
-
Never paste a credential into a chat, a shared folder, or an artifact.
Documented our practice
-
Do not rate sensitive conversations or attach them to bug reports. Feedback can send the related conversation; feedback and bug submissions have a five-year retention policy and can permit training. Other explicit opt-ins can also permit training.
Confirmed · 2026-09-16 compliance
-
Do not treat an incognito chat as private on Team or Enterprise. It is still retained, still exported to your account Owners, and — on Enterprise — still visible to the Compliance API.
Confirmed · 2026-07-28 compliance
-
Do not put anything sensitive inside a Skill. Skills sit outside zero-data-retention, and outside HIPAA coverage on the API path.
Confirmed · 2026-07-28 compliance
-
Do not assume your way of using Claude is covered. Most are never covered for patient data, and on two cloud platforms the decision is not Anthropic's to make.
Confirmed · 2026-07-28 compliance
-
Never put patient data into a JSON schema. Cached schemas are not protected the way message content is.
Confirmed · 2026-07-25 compliance
-
Nothing patient- or family-facing goes out without a clinician reading it first — diagnosis, treatment, prognosis, eligibility, what a family should do next. Nothing else goes out without someone who can check it having checked it.
Documented our practice
-
Do not treat outside files, pages, or email as inert — any of them can carry instructions aimed at Claude rather than at you. Narrow what Claude can read, or narrow what it can do — you do not have to do both.
Confirmed · 2026-07-25 compliance
Ask before you assume
-
Verify Enterprise account, session type and settings before attesting Compliance API coverage. Local HIPAA-readiness and ZDR sessions are excluded. Audit-log export and OpenTelemetry are separate routes.
Confirmed · 2026-09-16 compliance
-
If you turn on Cowork monitoring, ask what your collector actually receives. Two Anthropic pages disagree about whether it carries the words your staff typed — which decides whether your monitoring system is now a store of patient information you have to govern.
Stale risk · 2026-09-16 compliance
-
Ask what your administrators can centrally manage about Skills. Two live Anthropic pages disagree — one says Owners can provision Skills for everyone, the other says Skills cannot be centrally managed.
Stale risk · 2026-09-19 compliance
This sheet summarizes a longer curriculum with the evidence behind every line, at rareanthropic-curriculum.vercel.app. Each rule above is one finding there, with its primary source and, where it has one, the date it was checked. Not affiliated with or endorsed by Anthropic; quotations are from Anthropic's published pages.