Justin McKelvey
Fractional CTO · 15 years, 50+ products shipped
Is Claude HIPAA Compliant in 2026? Not on the Plan You're Probably Using
Quick Answer
No — and neither is ChatGPT, because no model is. HIPAA compliance is a contract, not a feature: a Business Associate Agreement (BAA). Anthropic signs one for the Claude API and sales-assisted Claude Enterprise only. Claude Free, Pro, Max, Team, Cowork and self-serve Enterprise are excluded at any price. OpenAI's line is drawn in the same place — and ChatGPT Business is excluded too, which is the one that catches people.
Vendor BAA documentation verified September 2026 · Author: Justin McKelvey, fractional CTO & AI consultant, 15 years in software, 50+ products shipped
Every few weeks someone asks me a version of the same question, usually a little sheepishly, usually after the fact: we've been using ChatGPT to draft patient follow-ups — is that a problem?
The internet answers this badly. Search it and you'll get a wall of confident yes/no verdicts, most of them written by companies selling a "HIPAA-compliant AI wrapper," most of them skipping the one distinction that actually decides your answer. So here it is first, before anything else.
No model is HIPAA compliant. A contract is.
HIPAA compliance is not a property that software has. There is no certification body that inspects a language model and stamps it. What exists is a Business Associate Agreement — a contract in which a vendor handling protected health information on your behalf accepts legal obligations for safeguarding it.
So "is Claude HIPAA compliant?" is the wrong shape of question. The right one is: will this vendor sign a BAA covering the specific product I am about to paste a patient's name into? That question has a precise, checkable answer, and it changes tier by tier within the same brand.
Which is why the yes/no articles are so useless. The answer for Claude is genuinely both. It depends entirely on which Claude you're using — and almost certainly not the one you're using.
What Anthropic will and won't sign for
Anthropic's published BAA documentation draws the line in two places:
| Claude product | Typical price | BAA available? |
|---|---|---|
| Claude Free | $0 | No |
| Claude Pro | $20/month | No |
| Claude Max | $100/mo (5x) or $200/mo (20x) | No |
| Claude Team | $25/seat/month, 5-seat minimum | No |
| Claude Cowork | Bundled with paid plans | No |
| Claude Enterprise (self-serve) | Card checkout | No |
| Claude Enterprise (sales-assisted, "HIPAA-ready") | Quote-based | Yes — must be activated |
| Claude API (first-party) | Metered, pay-as-you-go | Yes |
Two details in that table do real damage if you miss them.
Self-serve Enterprise is not the same product as sales-assisted Enterprise. Reaching the top of the pricing page with a credit card does not put you in BAA territory. The HIPAA-ready plan is the one you get through a conversation with their sales team, and buying the expensive tier yourself is not a shortcut to it.
And HIPAA-ready Enterprise is not automatic once you have it. Anthropic requires the organisation's Primary Owner to actively switch on HIPAA compliance in the workspace's Data and privacy settings and accept the BAA. A standard Enterprise organisation is not covered until somebody does that. If you're on Enterprise today and nobody can tell you who accepted the BAA or when, assume it hasn't happened.
One more piece of housekeeping worth checking if you've been around a while: Anthropic has stated that BAAs signed before 2 December 2025 cover API usage only and do not extend to the HIPAA-ready Enterprise plan. An old agreement in a drawer may not cover what you think it covers.
Is ChatGPT HIPAA compliant? Same answer, different tier names
OpenAI draws the line in the same conceptual place, and the tiers that make it across are the enterprise-and-API ones:
- Covered by a BAA: ChatGPT Enterprise (the sales-managed one), OpenAI's healthcare-specific enterprise products, and the API Platform — and notably the API does not require an enterprise agreement to get a BAA, which matters enormously for small practices.
- Not covered: Free, Plus, Pro, Team, and self-serve ChatGPT Business.
The naming here is genuinely hazardous. OpenAI ships a consumer-facing health product whose name contains the word "health" and which is not BAA-covered, sitting in a catalogue alongside enterprise healthcare products that are. If your compliance reasoning is "well, it's called Health, so presumably…" — stop there. The name is marketing; the BAA is the fact. If you're weighing the two vendors more broadly, Anthropic vs OpenAI for business covers the rest of the comparison.
The plans that trip everyone up: Claude Team and ChatGPT Business
If you take one thing from this page, take this one, because it is the mistake I see most and it is an expensive one.
Claude Team and ChatGPT Business are not HIPAA-eligible.
These are precisely the plans a five-person practice talks itself into. They cost real money. They say team and business on the label. They come with admin controls, shared workspaces, and a contractual promise not to train on your data — and that last one is what does the damage, because "they don't train on our data" feels like the compliance box being ticked.
It isn't. Training policy and BAA coverage are two unrelated things. You can be on a plan that will never train on your inputs and still have no agreement in place governing protected health information, which means every PHI-containing prompt is a disclosure to a vendor who never accepted responsibility for it. Upgrading from Pro to Team moved you into better admin tooling and left your HIPAA position exactly where it was. (I've written separately about what the Claude Team plan actually buys you — it's a good plan. It is not this.)
Signing a BAA doesn't make you compliant either
The other half of the trap sits on the far side of the contract. A BAA is a shared-responsibility document. It covers the vendor's obligations. It says nothing about yours.
Still entirely on you, after signature:
- Access control — who in the practice can open the workspace, and what happens to that access the week someone leaves.
- Minimum necessary — whether the prompt needed the patient's full name and date of birth to do the job, or whether that was just how the front desk happened to paste it.
- Staff training — because the actual breach vector is somebody using their personal ChatGPT on their phone at lunch, not your carefully configured enterprise workspace.
- Breach detection and notification — you need to be able to tell that something went into the wrong tool, and you're on the clock once you know.
- Documentation — a written policy naming which tools are approved for what. If it isn't written down, it doesn't exist in an audit.
A signed BAA is a starting gun, not a finish line.
The cheapest legal answer is usually "don't send PHI at all"
Here's the part the compliance-wrapper vendors would rather not lead with. A large share of what a practice actually wants AI for does not require protected health information in the first place.
Drafting a recall campaign. Explaining what a benefits breakdown means in plain English. Writing a procedure explainer for the website. Turning a messy claims narrative into a reusable template. Rewriting your no-show policy so it sounds like a human wrote it. None of those need a name, a date of birth, or a chart number to work — and the moment they don't, the entire HIPAA question stops applying to that workflow.
The micro-action, and you can do it today: open whatever AI tool your practice is already using, look at the last ten prompts your team ran, and mark each one needed PHI or didn't. In every practice I've done this with, the second pile is much bigger than anyone expected. That exercise takes fifteen minutes and it tells you whether you have a contract problem or a habit problem — and they have very different price tags.
If the workflow genuinely does need PHI, price the API route with a BAA next to the Enterprise quote before you sign anything. For a small practice running modest volume, metered API usage under a BAA is frequently far cheaper than a per-seat enterprise agreement sized for a hospital — and it's the option nobody's sales team is incentivised to mention. For how the consumer tiers price out by comparison, Claude's pricing breakdown has the full ladder.
What I tell owners
Almost nobody who asks me this question has a HIPAA problem. They have an unwritten-rules problem that a HIPAA question finally surfaced.
Staff adopted a tool because it made a genuinely tedious job faster, nobody said not to, and eighteen months later there's no policy, no approved-tools list, no idea which subscriptions are personal versus practice-owned, and no one who can say with confidence what has been pasted where. The compliance exposure is real, but it's a symptom. The disease is that AI arrived in the practice the way a stray cat arrives at a back door — incrementally, affectionately, and with nobody making a decision.
The fix is unglamorous and it is mostly not a purchase: decide which two or three workflows AI is actually for, write down which tool is approved for each and what may never be pasted into any of them, and de-identify by default so the expensive contract question only applies to the small number of workflows that truly need it.
If you'd rather not work out that order yourself, the AI Readiness Assessment ($2,500 flat — two weeks, a written roadmap, fee credited against a build within 90 days) is exactly this exercise done properly: which processes, in what order, on which tools, with the governance written down instead of assumed. The do-it-yourself version is the CFSB Playbook ($397). And if you want to talk through a specific practice, that's what strategy calls are for. Practice-specific workflow examples live in AI for dental practices.
One last thing, and I'd rather say it plainly than hedge it: this is a technology explainer written by a fractional CTO who implements these systems, not legal advice. HIPAA enforcement turns on specifics — your data, your workflows, your risk analysis. Use this to ask your compliance counsel a much sharper question than "is ChatGPT okay?", which is a question nobody can answer well. "Which of our AI tools are covered by a signed BAA, and who accepted it?" is the one worth asking.
Get the Free AI Content Toolkit
The exact system I use to turn one idea into a month of content — atomization framework, voice template, prompt library, weekly system.
Frequently Asked Questions
- Is Claude HIPAA compliant?
- Not by itself, and no AI model is. HIPAA compliance isn't a property a model has — it's a contract, a Business Associate Agreement (BAA), that a vendor signs committing to handle protected health information under the rules. Anthropic will sign one, but only for two things: the first-party Claude API, and sales-assisted Claude Enterprise plans (what Anthropic calls HIPAA-ready Enterprise). Claude Free, Pro, Max, Team, Cowork and self-serve Enterprise are explicitly outside that coverage. So if you're logging into claude.ai on a Pro subscription, the honest answer is no — and no amount of careful prompting changes it.
- Is ChatGPT HIPAA compliant?
- Same structure, different tier names. OpenAI signs a BAA for ChatGPT Enterprise (sales-managed), for its healthcare-specific enterprise products, and for the API Platform. It does not sign one for Free, Plus, Pro, Team, or self-serve ChatGPT Business. Worth knowing because the names actively mislead: ChatGPT Business sounds like the business-grade compliant option and is not BAA-eligible, and OpenAI's consumer health product is a consumer product regardless of what it's called. If you want the comparison across both vendors, I've written that up in Anthropic vs OpenAI for business.
- Can I use Claude Pro or ChatGPT Plus with patient data?
- No. Those are consumer tiers and neither vendor will sign a BAA covering them, which means putting protected health information into one is a disclosure to a party with no agreement in place. That's the part people get wrong — they assume the risk is that the model 'learns' their data, so they turn off training and consider it handled. Training settings aren't the control that matters here. The absence of a signed BAA is the problem, and you can't fix it from inside the settings menu.
- Is Claude Team or ChatGPT Business HIPAA compliant?
- No, and these two are the expensive mistake. They're the plans a small practice naturally buys — they cost real money, they say 'team' and 'business' on the tin, and they come with admin controls and no-training contracts that feel like compliance. Neither is BAA-eligible. Anthropic excludes Claude Team; OpenAI excludes self-serve ChatGPT Business. Paying more did not move you into coverage. It moved you into a plan with better admin settings and exactly the same HIPAA answer as the free tier.
- Does signing a BAA make my practice HIPAA compliant?
- No, and this is where a lot of small practices stop reading too early. A BAA is a shared-responsibility document: it covers the vendor's obligations for the data you send. Everything on your side is still yours — who has access, how staff are trained, what goes into a prompt in the first place, how you'd detect and report a breach, and whether the workflow needed the patient's name at all. I've watched practices treat a signed BAA as a finish line when it's closer to a starting gun.
- What's the cheapest way to actually use AI in a practice legally?
- Usually: don't send PHI at all. A surprising share of what practices want AI for — drafting recall messages, summarising an insurance policy, writing a procedure explainer, cleaning up a claims narrative template — doesn't need a patient's identity to work. De-identify first and most of the compliance question evaporates along with the cost of an enterprise contract. If the workflow genuinely needs PHI, then you're in BAA territory and you should price the API route alongside Enterprise, because for a small practice the API with a BAA is often dramatically cheaper than a per-seat enterprise agreement.
More on AI for Business
Claude Usage Limits in 2026: There Is No Number, and That's the Answer
Anthropic doesn't publish a message count for any Claude plan — not Free, not Pro, not Max. What it publishes are multipliers and two meters. Here's how the 5-hour window and the weekly cap actually work, what each tier is reported to get, and what to do the third time you hit the wall.
Is n8n Free? Yes — If You're Willing to Be the Sysadmin (2026)
Yes, genuinely — n8n's self-hosted Community Edition is free with unlimited executions, which almost nothing else in automation offers. The bill just moves somewhere else. Here's what free costs in practice, what n8n Cloud runs, and how to tell which one you actually want.
Is DeepSeek Free? Yes — And That's the Part to Think About (2026)
Yes. DeepSeek's chat app is free with no paid tier at all — no Plus, no Pro, nothing to upgrade to. That's rarer than it sounds, and it's why the interesting question isn't the price. Here's what free actually costs a business, and the one version of DeepSeek that's free AND private.
How to Use Claude Projects (2026): Stop Re-Explaining Your Business Every Morning
Most Claude Projects tutorials are feature tours. Here's the part that actually pays: a Project is a place to park the context you re-type into a chat box every single day. Set one up properly once and every future conversation starts already knowing your business.
Written by
Justin McKelvey
Fractional CTO & AI consultant in Austin, TX. 15 years building software, 50+ products shipped, $53M+ in client revenue generated. I help $1M–$50M founders ship production software and automate operations with AI — without hiring a full-time executive team.
Work with meIf this was useful, here are two ways I can help:
Before you go
Score your AI readiness in 3 minutes.
Free, no call. 30 yes/no questions show where AI actually pays off in your business — and where it doesn't yet.
Get my readiness score →