HIPAA setup for Claude Code
Preparing developer machines for the HIPAA configuration on Claude Enterprise: eligible connections, versions, network hosts, managed settings and local data.
The HIPAA configuration is an organisation setting on Claude Enterprise for organisations that handle protected health information (PHI) and have a Business Associate Agreement (BAA) with Anthropic. It applies to Claude Code (local mode) and Cowork (local mode) and restricts features in both.
"Local mode" means a session running on the machine, not a cloud session. That is Claude Code in the terminal, Claude Code in the Code tab of Claude Desktop, and Cowork in Claude Desktop. The VS Code and JetBrains extensions are not part of local mode: they keep working once the configuration is applied, but your BAA does not cover them. Anthropic's HIPAA Implementation Guide on the Trust Center lists every Eligible Service.
This page is for the IT or security admin who prepares machines. The Primary Owner of your Claude organisation is the one who applies the configuration, and Anthropic's support article on HIPAA-ready Enterprise plans covers what the BAA includes and how to schedule the switch-over. If you use Cowork, it has its own setup guide covering the Desktop policy and Cowork's local data.
The plan at a glance
| When | Your job |
|---|---|
| Before the configuration is applied | Check how people connect, update apps, open network access, deploy managed settings |
| Once applied | The Code tab is off until an Owner re-enables it. Verify on a machine |
| Ongoing | Manage session data stored on each machine |
Before it is applied
1. Check how developers connect
The configuration only takes effect when a developer signs in with a Claude Enterprise account and Claude Code talks directly to the Claude API. Any other connection keeps working but runs without the HIPAA configuration.
| Connection | Eligible? |
|---|---|
| Claude Enterprise account, direct to the Claude API | Yes |
| Amazon Bedrock, Google Cloud's Agent Platform, Microsoft Foundry, Claude Platform on AWS, or a Claude apps gateway | No |
An LLM gateway or any custom ANTHROPIC_BASE_URL | No |
ANTHROPIC_AUTH_TOKEN or apiKeyHelper with no Enterprise sign-in | No |
| A Claude Console API key or federation credentials | No: these belong to a Console organisation with its own agreement and settings |
To check a machine, run claude and then /status. On the Status tab:
Login methodandOrganizationappear for claude.ai sign-ins. For Enterprise,Login methodreadsClaude Enterprise account.API providerappears only for a cloud provider or Claude apps gateway.Anthropic base URLappears only whenANTHROPIC_BASE_URLis set.
If either of the last two shows up, that machine is ineligible. The managed settings in step 4 can block those routes.
2. Update the apps
The configuration needs Claude Code v2.1.285 or later and Claude Desktop v2.19675.0 or later. Check the CLI with:
claude --version
A supported install prints 2.1.285 (Claude Code) or higher. For Desktop, see Desktop.
For HIPAA organisations, Anthropic's servers reject requests from versions below the minimum, and that minimum rises over time with nothing for you to configure. On an old CLI each request fails with an API Error saying the version is below what your organisation's policy requires. On an old Desktop, an Update required dialog blocks the Code tab. Keep installs current; Setup covers updating.
3. Open the network
Allow these whole hosts over HTTPS on port 443:
| Host | Used for |
|---|---|
api.anthropic.com | API requests, telemetry, and the organisation policy that tells Claude Code HIPAA is on |
claude.ai, claude.com, platform.claude.com | Sign-in and token refresh |
downloads.claude.ai | Native installer and updates |
mcp-proxy.anthropic.com | Connectors from claude.ai (see MCP) |
That is the minimum for a native install in the terminal. Network configuration lists the hosts for npm and Homebrew installs, plugin installs and custom CA certificates for TLS-inspecting proxies; Desktop lists the extra hosts the Code tab and Cowork need. A corporate HTTPS proxy is fine as long as it can reach these hosts.
Claude Code learns your HIPAA status by fetching the organisation policy from api.anthropic.com at startup and roughly hourly while the session is in use. If that fetch is blocked, the machine never learns the configuration is on.
4. Deploy managed settings
Managed settings let you force Enterprise sign-in, block providers and gateways, and fix how long machines keep session data. They work whether or not HIPAA is in force. Treat the following as a starting point; deciding what your environment needs is your organisation's call.
{
"forceLoginMethod": "claudeai",
"forceLoginOrgUUID": "d3a7c9e2-51f4-4b0e-8a62-7f19c4e0d5b1",
"allowedProviders": ["anthropic"],
"cleanupPeriodDays": 14
}
| Key | Value | Effect |
|---|---|---|
forceLoginMethod | "claudeai" | Sends developers to claude.ai sign-in, not Claude Console |
forceLoginOrgUUID | Your organisation ID, copied by an Owner from claude.ai admin settings | Claude Code exits at startup if the claude.ai sign-in belongs to another organisation |
allowedProviders | ["anthropic"] | Refuses to start on a cloud provider or gateway |
cleanupPeriodDays | Whatever your records policy allows | Every machine deletes old session data after the same number of days |
Warning: Double-check
forceLoginOrgUUID. A wrong value makes Claude Code exit at startup for every developer using a claude.ai account.
The HIPAA configuration does not cap cleanupPeriodDays, so a developer could raise it in their own settings; setting it in managed settings makes Claude Code ignore their value. With forceLoginMethod or forceLoginOrgUUID set, sessions using ANTHROPIC_API_KEY, ANTHROPIC_AUTH_TOKEN or apiKeyHelper are refused too. The settings reference documents each key.
Check they loaded. On a managed machine, sign in with Enterprise and run /status. Setting sources should list Enterprise managed settings with its source in brackets, such as (file), and Allowed providers should read Anthropic API (managed allowedProviders).
What these keys do not block:
- Console sign-ins and federation credentials.
forceLoginOrgUUIDonly checks claude.ai sign-ins; Authentication lists what is checked on each path. - Server-managed settings. If you also use server-managed settings, have an Owner add the same keys there, since the managed sources combine.
- Old versions. Anything before v2.1.285 ignores
allowedProviders. Adding"requiredMinimumVersion": "2.1.285"makes v2.1.163 to v2.1.284 refuse to start. Versions before v2.1.163 ignore both keys, so update them.
After it is applied: verify on one machine
- Restart Claude Code. A running session picks up the change within about an hour; a restart fetches it immediately.
- Startup notice. You should see
Per your organization's policy, some features are limited · /status for details. - Footer. A
HIPAA configuredtag appears at the right of the footer below the prompt (it readHIPAAbefore v2.1.286). - Status.
/statuslistsHIPAAon theOrganization configurationline. - Desktop. Applying the configuration turns the Code tab off organisation-wide. An Owner re-enables it under Organisation settings, Claude Code, using the Desktop toggle. After reloading or signing in again, the title bar shows HIPAA configured (on a Mac, open the sidebar to see it).
If HIPAA is missing from /status, work through these in order:
- Wrong account or route.
Organizationshould be yours, with noAPI providerorAnthropic base URLline. - Policy fetch blocked. An
Organization policyline in/statusgives the reason. Outside a session,claude doctorshows the same line. Allowapi.anthropic.comand restart. - Not applied yet. Ask the Primary Owner.
What developers will notice
| Symptom | Reason |
|---|---|
| WebFetch is unavailable | WebFetch is off; web search still works |
--cloud, /teleport and Remote Control are refused | Cloud sessions and Remote Control are off |
/feedback and /bug are gone | Feedback submission is off |
| Claude cannot publish an artifact | Artifact publishing is off |
An MCP server or hook reading ANTHROPIC_API_KEY stops authenticating | Anthropic credentials are stripped from child processes (below) |
Restrictions persist after /login to another organisation | HIPAA status lasts until Claude Code restarts |
Anthropic's BAA support article has the full feature table for Claude Code and Cowork, including the features an Owner can turn back on.
Credentials in commands, hooks and MCP servers
Under the configuration, Claude Code removes the credentials it uses to reach Anthropic, such as ANTHROPIC_API_KEY and ANTHROPIC_AUTH_TOKEN, from the environment of every shell command, hook and MCP server it starts. Cloud provider and GitHub credentials are left alone, so a git push or a call to another service still works with the developer's own access, and your BAA with Anthropic does not cover data sent there. Use permission rules and the sandbox to limit which commands and hosts Claude can reach.
Local session data
Local sessions store data on each developer's machine. Securing and deleting it is your responsibility.
Claude Code
The .claude directory lists what Claude Code stores, what the retention sweep removes after cleanupPeriodDays, what stays until deleted, and what differs under HIPAA. The sweep only runs when someone starts Claude Code, so an unused machine keeps its data.
The Code tab
- Transcripts sit in
~/.claude/projects/alongside terminal transcripts. - The Desktop data folder is
~/Library/Application Support/Claudeon macOS. On Windows check both%APPDATA%\Claudeand, for the installer downloaded from Anthropic,%LOCALAPPDATA%\Packages\Claude_pzs8sxrjxfjjc\LocalCache\Roaming\Claude. (On Windows,~means%USERPROFILE%.)
Under HIPAA, Desktop deletes Code tab sessions inactive for longer than cleanupPeriodDays, starred ones included, but only while it is running. A deleted session's worktree is removed only if it has no uncommitted changes, is not starred or pinned, and no other session uses it; otherwise it stays.
Deleting data immediately
To clear a developer's session data before the sweep, sign in as them and run, on v2.1.288 or later:
claude purge --all --yes
On v2.1.126 to v2.1.287 the same flags work with claude project purge. Either removes every project's transcripts and auto memory, the contents of tasks/, debug/ and file-history/, history.jsonl, and the project entries in ~/.claude.json. Without --yes it shows the plan and asks first. Some paths, such as paste-cache/, survive; The .claude directory lists what to remove by hand.
Offboarding
Removing a seat or account deletes nothing on the laptop, and neither does /logout. To be certain, wipe the machine with your device management tool.