1> ## Documentation Index
2> Fetch the complete documentation index at: https://code.claude.com/docs/llms.txt
3> Use this file to discover all available pages before exploring further.
4
5# Set up Claude Code (local mode) for a HIPAA-ready organization
6
7> Prepare developers' computers to run Claude Code (local mode) under the HIPAA configuration. Covers versions, network access, managed settings, and local data.
8
9The HIPAA configuration is an organization setting on Claude Enterprise plans, for organizations that handle protected health information (PHI) and have a [Business Associate Agreement (BAA)](https://support.claude.com/en/articles/8114513-business-associate-agreements-baa-for-commercial-customers) with Anthropic. It applies to Claude Code (local mode) and Cowork (local mode), and it restricts features in both products.
10
11<Note>
12 "(local mode)" means a local session, not a [cloud session](/docs/en/claude-code-on-the-web). Local sessions run in one of these places:
13
14 * Claude Code in the terminal
15 * Claude Code in the Code tab of Claude Desktop
16 * Cowork in Claude Desktop
17
18 The Claude Code extensions for VS Code and JetBrains aren't part of (local mode). They keep working with the HIPAA configuration applied, but your BAA doesn't cover them. See the [Implementation Guide](https://trust.anthropic.com/resources?s=rgirr4qe8u7ek8c2igx3\&name=claude-for-enterprise-hipaa-ready-offering-implementation-guide) for the full list of Eligible Services.
19</Note>
20
21This page is for the IT or security administrator who prepares developers' computers. The Primary Owner of your Claude organization applies the configuration itself. [Use Claude Code (local mode) and Cowork (local mode) on a HIPAA-ready Enterprise plan](https://support.claude.com/en/articles/17318731) explains what your BAA includes, how the configuration is applied, and how to schedule the date it's applied.
22
23If members of your organization also use Cowork, follow [Set up Cowork (local mode) for a HIPAA-ready organization](https://claude.com/docs/cowork/hipaa-setup) as well. It covers the Claude Desktop policy and Cowork's local data.
24
25The table shows when to do each part of the setup:
26
27| When | What to do |
28| :- | :- |
29| Before the configuration is applied | [Prepare computers](#prepare-computers-before-the-hipaa-configuration-is-applied): check how developers connect, update the apps, allow network access, and deploy managed settings |
30| After it's applied | The Code tab is off until an Owner turns it back on. [Confirm the configuration on a computer](#confirm-the-configuration-on-a-computer) |
31| Ongoing | [Manage local session data](#manage-local-session-data) |
32
33## Prepare computers before the HIPAA configuration is applied
34
35We recommend you start with the tasks in this section and complete them before the configuration is applied.
36
37### Check how developers sign in and connect
38
39The HIPAA configuration takes effect only in sessions where a developer signs in with a Claude Enterprise account and Claude Code connects directly to the Claude API. On any other connection, developers can keep using Claude Code, but it doesn't apply the [HIPAA configuration](#what-developers-see-in-claude-code).
40
41The table shows which connections are eligible. To find out whether your BAA covers a session in a "No" row, see [Use Claude Code (local mode) and Cowork (local mode) on a HIPAA-ready Enterprise plan](https://support.claude.com/en/articles/17318731).
42
43| How Claude Code connects | Eligible for the HIPAA configuration |
44| :- | :- |
45| A Claude Enterprise account, connecting directly to the Claude API | Yes |
46| Amazon Bedrock, Google Cloud's Agent Platform, Microsoft Foundry, Claude Platform on AWS, or a [Claude apps gateway](/docs/en/claude-apps-gateway) | No |
47| An [LLM gateway](/docs/en/llm-gateway) or any other custom `ANTHROPIC_BASE_URL` | No |
48| `ANTHROPIC_AUTH_TOKEN` or `apiKeyHelper`, on a computer with no Claude Enterprise sign-in | No |
49| A Claude Console API key or [federation credentials](/docs/en/authentication#anthropic-profiles-and-federation-credentials) | No. These sessions belong to a Claude Console organization, which has its own agreement and settings |
50
51#### Check how a computer connects
52
53Open a terminal on the computer, run `claude`, and enter `/status` at the prompt. The **Status** tab shows these lines:
54
55| Line | When it appears |
56| :- | :- |
57| `Login method` and `Organization` | The session is signed in with a claude.ai account. For a Claude Enterprise account, `Login method` reads `Claude Enterprise account` and `Organization` shows your organization |
58| `API provider` | Only when the session uses a cloud provider or a Claude apps gateway |
59| `Anthropic base URL` | Only when `ANTHROPIC_BASE_URL` is set |
60
61If a computer uses a connection that isn't eligible for the HIPAA configuration, you can use [managed settings](#deploy-managed-settings) to block cloud providers, gateways, and credentials set with `ANTHROPIC_API_KEY`, `ANTHROPIC_AUTH_TOKEN`, or `apiKeyHelper`.
62
63### Update Claude Code and Claude Desktop
64
65The HIPAA configuration requires Claude Code v2.1.285 or later and Claude Desktop v2.19675.0 or later. If your organization uses both the terminal and the [Claude Desktop app](/docs/en/desktop), update both.
66
67To read the installed Claude Code version, run this command in a terminal. It's the same in Bash, Zsh, and PowerShell:
68
69```bash theme={null}
70claude --version
71```
72
73A supported installation prints `2.1.285 (Claude Code)` or a higher number.
74
75To read the installed Claude Desktop version, see [Check your version](/docs/en/desktop#check-your-version).
76
77#### What developers see on an older version
78
79For organizations with the HIPAA configuration, Anthropic's servers reject requests from versions older than the minimum version. Anthropic raises the minimum version over time, and there's nothing for you to configure.
80
81| App | What a developer sees on an older version |
82| :- | :- |
83| Claude Code | Each request fails with an [`API Error`](/docs/en/errors#claude-code-does-not-support-this-model) that says the version is older than the minimum version your organization's policy requires |
84| Claude Desktop | An **Update required** dialog that tells the developer to update Claude Desktop to continue using the **Code** tab |
85
86To keep developers on a supported version, [keep Claude Code updated](/docs/en/setup#update-claude-code). For Claude Desktop, see [Update Claude Desktop](https://claude.com/docs/cowork/hipaa-setup#update-claude-desktop).
87
88### Allow network access
89
90Allow the hosts in this table through your proxy and firewall, over HTTPS on port 443. Allow each whole host, not individual paths.
91
92| Host | Needed for |
93| :- | :- |
94| `api.anthropic.com` | Claude API requests, telemetry, and the organization policy that tells Claude Code the HIPAA configuration is on |
95| `claude.ai`, `claude.com`, `platform.claude.com` | Sign-in and token refresh |
96| `downloads.claude.ai` | The native installer and its updates |
97| `mcp-proxy.anthropic.com` | [Connectors from claude.ai](/docs/en/mcp#use-mcp-servers-from-claude-ai) |
98
99This table lists the hosts a native install of Claude Code needs in the terminal to sign in, run, and update. These pages list the rest:
100
101* **Other install methods and optional features**: [Network access requirements](/docs/en/network-config#network-access-requirements) lists the hosts that npm and Homebrew installs check for updates, and the hosts for features such as plugin installs
102* **The Code tab and Cowork**: [Desktop network access requirements](/docs/en/desktop#network-access-requirements) lists the additional hosts Claude Desktop needs
103* **Proxies that inspect TLS**: [Custom CA certificates](/docs/en/network-config#custom-ca-certificates) shows how to trust your proxy's certificate
104
105Sessions that go through a corporate HTTPS proxy are still eligible for the HIPAA configuration, as long as the proxy can reach the hosts in the table.
106
107Claude Code learns that your organization has the HIPAA configuration by fetching your organization's policy from `api.anthropic.com`, when it starts and again about every hour while the session is in use. The policy is a record of your organization's HIPAA status and the feature restrictions that follow from it.
108
109To check whether one computer has fetched the policy, see [Confirm the configuration on a computer](#confirm-the-configuration-on-a-computer).
110
111### Deploy managed settings
112
113You can use [managed settings](/docs/en/managed-settings) to direct developers to sign in with a Claude Enterprise account, to block cloud providers and gateways, and to set how many days every computer keeps local session data. The settings apply whether or not the HIPAA configuration is in effect.
114
115The settings in this section are a sample that we recommend as a starting point. Your organization is responsible for deciding what its own environment needs and for confirming that its configuration meets those needs.
116
117The following sample sets four keys that you could add to the [managed settings](/docs/en/managed-settings#choose-a-delivery-mechanism) your organization deploys:
118
119```json theme={null}
120{
121 "forceLoginMethod": "claudeai",
122 "forceLoginOrgUUID": "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx",
123 "allowedProviders": ["anthropic"],
124 "cleanupPeriodDays": 30
125}
126```
127
128#### What each key does
129
130The table shows what to set each key to and what Claude Code enforces for it.
131
132| Key | Set it to | What Claude Code enforces |
133| :- | :- | :- |
134| [`forceLoginMethod`](/docs/en/settings-reference#forceloginmethod) | `"claudeai"` | Claude Code directs developers to claude.ai sign-in instead of Claude Console |
135| [`forceLoginOrgUUID`](/docs/en/settings-reference#forceloginorguuid) | Your organization ID, which an [Owner](/docs/en/server-managed-settings#access-control) can copy from [claude.ai admin settings](https://claude.ai/admin-settings/organization) | Claude Code exits at startup when the claude.ai sign-in belongs to another organization |
136| [`allowedProviders`](/docs/en/settings-reference#allowedproviders) | `["anthropic"]` | Claude Code refuses to start on a cloud provider or a gateway |
137| [`cleanupPeriodDays`](/docs/en/settings-reference#cleanupperioddays) | The number of days your records policy lets a computer keep session data | Every computer deletes old session data after the same number of days |
138
139<Warning>
140 Check the `forceLoginOrgUUID` value before you deploy it. If it doesn't match your organization ID, Claude Code exits at startup for every developer who signs in with a claude.ai account.
141</Warning>
142
143The HIPAA configuration doesn't limit `cleanupPeriodDays`, so a developer can raise it in their own settings. When you set it in managed settings, Claude Code ignores the developer's value.
144
145With `forceLoginMethod` or `forceLoginOrgUUID` set, Claude Code also refuses sessions that authenticate with `ANTHROPIC_API_KEY`, `ANTHROPIC_AUTH_TOKEN`, or `apiKeyHelper`.
146
147#### Confirm the settings loaded
148
149On a computer that has the settings, run `claude`, sign in with a Claude Enterprise account, and enter `/status`. The `Setting sources` line lists `Enterprise managed settings` followed by the source in parentheses, such as `(file)`, and the `Allowed providers` line reads `Anthropic API (managed allowedProviders)`. If `Setting sources` doesn't list it, or the `Allowed providers` line is missing, see [Check that a policy is in force](/docs/en/managed-settings#check-that-a-policy-is-in-force).
150
151#### Sessions the managed settings keys don't block
152
153Even with these keys deployed, some sessions can still run without the HIPAA configuration:
154
155* **Claude Console sign-ins and federation credentials**: `forceLoginOrgUUID` checks only claude.ai sign-ins. [Restrict login to your organization](/docs/en/authentication#restrict-login-to-your-organization) lists what Claude Code checks for each sign-in path and credential.
156* **Server-managed settings**: if your organization also uses [server-managed settings](/docs/en/server-managed-settings), have an Owner add the same keys there. [How Claude Code combines managed sources](/docs/en/managed-settings#how-claude-code-combines-managed-sources) explains which source applies.
157
158To find out whether your BAA covers a session that runs without the HIPAA configuration, see [Use Claude Code (local mode) and Cowork (local mode) on a HIPAA-ready Enterprise plan](https://support.claude.com/en/articles/17318731).
159
160## Confirm the configuration on a computer
161
162Run this check on one managed computer after the configuration is applied to your organization.
163
164<Steps>
165 <Step title="Restart Claude Code">
166 Quit any running session, open a terminal, and run `claude`. A running session that's in use picks up the configuration within about an hour without a restart. When you restart, Claude Code fetches it right away.
167 </Step>
168
169 <Step title="Check the startup notice">
170 Confirm that Claude Code prints `Per your organization's policy, some features are limited · /status for details` when it starts.
171 </Step>
172
173 <Step title="Check the footer">
174 Confirm that a `HIPAA configured` tag appears at the right of the footer, below the prompt. Before v2.1.286, the tag read `HIPAA`.
175 </Step>
176
177 <Step title="Run /status">
178 Enter `/status` at the prompt. Confirm that the **Status** tab lists `HIPAA` on the `Organization configuration` line.
179 </Step>
180
181 <Step title="Check Claude Desktop">
182 Applying the HIPAA configuration turns the Code tab off for your organization. If your organization uses it, ask an Owner to go to [**Organization settings > Claude Code**](https://claude.ai/admin-settings/claude-code) and turn on the **Desktop** toggle. For Cowork, see [Confirm the HIPAA configuration in Claude Desktop](https://claude.com/docs/cowork/hipaa-setup#confirm-the-hipaa-configuration-in-claude-desktop).
183
184 Reload Claude Desktop or sign in again. Confirm that the title bar shows a **HIPAA configured** label. On a Mac, open the sidebar to see it.
185 </Step>
186</Steps>
187
188If `HIPAA` is missing from `/status`, check these causes in order:
189
1901. **The wrong account or connection**: confirm that `/status` shows your organization on the `Organization` line, and shows no `API provider` or `Anthropic base URL` line. [Check how developers sign in and connect](#check-how-developers-sign-in-and-connect) lists the connections that aren't eligible for the configuration.
1912. **A blocked policy fetch**: look for an `Organization policy` line in `/status`, which gives the cause. Outside a session, run `claude doctor` and read the same line, which says where Claude Code loaded the policy from or why the policy didn't load. Allow `api.anthropic.com` through your proxy, then restart Claude Code.
1923. **The configuration isn't applied yet**: ask the Primary Owner whether they have applied the configuration.
193
194## What developers see in Claude Code
195
196With the HIPAA configuration applied, some Claude Code features are off or behave differently in the terminal. The table lists the changes developers are most likely to ask you about. The [HIPAA feature availability table](https://support.claude.com/en/articles/8114513-business-associate-agreements-baa-for-commercial-customers) lists every Claude Code and Cowork feature, including the ones an Owner can turn back on.
197
198| What a developer notices | Why |
199| :- | :- |
200| The WebFetch tool is unavailable | WebFetch is off. Web search still works |
201| `--cloud`, `/teleport`, and [Remote Control](/docs/en/remote-control) are refused | [Cloud sessions](/docs/en/claude-code-on-the-web) and Remote Control are off |
202| `/feedback` and `/bug` are unavailable | Feedback submission is off |
203| Claude can't publish an [artifact](/docs/en/artifacts) | Artifact publishing is off |
204| An MCP server or hook that reads `ANTHROPIC_API_KEY` stops authenticating | Claude Code [removes Anthropic credentials](#anthropic-credentials-in-commands-hooks-and-mcp-servers) from the processes it starts |
205| Restrictions remain after `/login` to a different organization | The HIPAA status lasts until Claude Code restarts |
206
207### Anthropic credentials in commands, hooks, and MCP servers
208
209With the HIPAA configuration applied, Claude Code removes the credentials it uses to reach Anthropic, such as `ANTHROPIC_API_KEY` and `ANTHROPIC_AUTH_TOKEN`, from the environment of the shell commands, hooks, and MCP servers it starts.
210
211The HIPAA configuration doesn't remove cloud provider or GitHub credentials, so a command that pushes to GitHub or calls another service still works with that developer's access. Your BAA with Anthropic doesn't cover the data it sends there. See the [Implementation Guide](https://trust.anthropic.com/resources?s=rgirr4qe8u7ek8c2igx3\&name=claude-for-enterprise-hipaa-ready-offering-implementation-guide) for the full list of Eligible Services.
212
213To limit which commands and hosts Claude can use, see [permission rules](/docs/en/permissions) and the [sandbox](/docs/en/sandboxing).
214
215## Manage local session data
216
217Claude Code (local mode) and Cowork (local mode) store session data on each developer's computer. Securing and deleting that data is your organization's responsibility.
218
219### Claude Code data
220
221[Application data](/docs/en/claude-directory#application-data) lists what Claude Code (local mode) stores on a computer, what its retention sweep deletes after `cleanupPeriodDays`, and what stays until someone deletes it. The same page states what differs in an organization with the HIPAA configuration applied.
222
223The retention sweep runs only when someone starts Claude Code, so a computer where nobody starts it keeps its data.
224
225### Code tab data
226
227The Code tab stores data in these places:
228
229* **Transcripts**: in `~/.claude/projects/`, alongside terminal transcripts. [Cleaned up automatically](/docs/en/claude-directory#cleaned-up-automatically) states when the retention sweep deletes them.
230* **The Claude Desktop data folder**: `~/Library/Application Support/Claude` on macOS. On Windows, `%APPDATA%\Claude`, or `%LOCALAPPDATA%\Packages\Claude_pzs8sxrjxfjjc\LocalCache\Roaming\Claude` for the installer downloaded from Anthropic, so check both. With the HIPAA configuration applied, Claude Desktop deletes local Code tab sessions that have been inactive for longer than `cleanupPeriodDays`, including starred ones. It deletes them only while it's running. Claude Desktop handles a deleted session's worktree in one of these ways:
231 * **No uncommitted changes, the session isn't starred or pinned, and no other session is using the worktree**: Claude Desktop removes the worktree
232 * **Any other case**: the worktree stays on the computer
233
234On Windows, `~` means `%USERPROFILE%`.
235
236### Cowork data
237
238[Manage Cowork data on each computer](https://claude.com/docs/cowork/hipaa-setup#manage-cowork-data-on-each-computer) lists where Cowork (local mode) stores data and what Claude Desktop deletes.
239
240### Delete session data right away
241
242If your organization needs a developer's session data removed before the retention sweep deletes it, you can remove most of it with one command. Sign in to the computer as that developer, and run this command in any shell:
243
244```bash theme={null}
245claude purge --all --yes
246```
247
248Before v2.1.288, the command was `claude project purge`.
249
250The command deletes every project's transcripts and auto memory, the entries in `tasks/`, `debug/`, and `file-history/`, `history.jsonl`, and the project entries in `~/.claude.json`. Without `--yes`, it prints the plan and asks first.
251
252The purge leaves other paths that can hold session content, such as pasted text in `paste-cache/`. [Clear local data](/docs/en/claude-directory#clear-local-data) lists the paths you can delete by hand. To clear a computer completely, for example before you reassign it, [wipe it](#offboard-a-developer).
253
254### Offboard a developer
255
256Removing a developer's seat or account deletes nothing on their computer, and `/logout` doesn't delete session data either. To remove all of it, you can wipe the computer with your device management tool.
257
258## Related resources
259
260* [Set up Cowork (local mode) for a HIPAA-ready organization](https://claude.com/docs/cowork/hipaa-setup)
261* [Deploy managed settings](/docs/en/managed-settings)
262* [Enterprise network configuration](/docs/en/network-config)
263* [Zero data retention](/docs/en/zero-data-retention)
264* [Legal and compliance](/docs/en/legal-and-compliance)
265* [Data usage](/docs/en/data-usage)