One read of Claude Documentationclaude-docs-20261005T233711Z
4 pages moved out of 262 read.
Pages moved
4
significant first
Pages read
262
in this capture
Captured
23:37 UTC
Corpus hash
263da87f2927
corpus-hash
What this read moved
1-4 of 4cowork/hipaa-setup Changed · +1 / -1 lines
from line 11
1111 * Claude Code in the Code tab of Claude Desktop
1212 * Cowork in Claude Desktop
1313
14 The Claude Code extensions for VS Code and JetBrains aren't part of (local mode). They keep working with the HIPAA configuration applied, but your BAA doesn't cover them. See the [Implementation Guide](https://trust.anthropic.com/resources?s=rgirr4qe8u7ek8c2igx3\&name=claude-for-enterprise-hipaa-ready-offering-implementation-guide) for the full list of Eligible Services.
14 The Claude Code extensions for VS Code and JetBrains aren't part of (local mode). They keep working with the HIPAA configuration applied, but your BAA doesn't cover them. See the [Implementation Guide](https://trust.anthropic.com/resources?s=l1wrssd9hsbi4gak0tp5a6\&name=%5Banthropic%5D-hipaa-ready-offering-implementation-guide) for the full list of Eligible Services.
1515</Note>
1616
1717This page is for the IT or security administrator who manages the macOS and Windows computers where members run [Cowork](/docs/cowork/overview) in Claude Desktop. Other readers start on a different page:
third-party/claude-desktop/connectors-m365 Changed · +2 / -0 lines
from line 31
3131
3232Setup takes about fifteen minutes and requires a Global Administrator or Cloud Application Administrator in your Entra tenant.
3333
34The hosted M365 server has not been evaluated for HIPAA compliance. If your organization follows HIPAA compliance, please use the [local connector](#local-connector) instead.
35
3436### How the connection works
3537
3638Three applications participate in the sign-in chain. Understanding which one each ID refers to makes the setup steps below easier to follow.
third-party/claude-desktop/legal Changed · +1 / -1 lines
from line 30
3030
3131For Anthropic's certifications and compliance reports, see the [Anthropic Trust Center](https://trust.anthropic.com).
3232
33For HIPAA, see [HIPAA](/docs/third-party/claude-desktop/overview#hipaa) on the Overview page. For Google Cloud's Agent Platform and Amazon Bedrock, Anthropic does not interact with PHI; the BAA relationship is between you and your cloud service provider, and any remote MCP servers you connect need your own HIPAA review. For Microsoft Foundry, HIPAA readiness (Anthropic's arrangement of a signed BAA plus safeguards for processing PHI) is not available, as described under [What HIPAA readiness does not cover](https://platform.claude.com/docs/en/manage-claude/api-and-data-retention#what-hipaa-readiness-does-not-cover) in the Claude API documentation.
33For HIPAA, see [HIPAA](/docs/third-party/claude-desktop/overview#hipaa) on the Overview page. For Google Cloud's Agent Platform and Amazon Bedrock, Anthropic does not interact with PHI; the BAA relationship is between you and your cloud service provider, and any remote MCP servers you connect need your own HIPAA review. Anthropic's API accessed through Microsoft Foundry (Hosted on Anthropic or Hosted on Azure) is an Eligible Service, as long as you have the HIPAA configuration enabled. Either option requires a BAA with Anthropic. See our [Trust Center](https://trust.anthropic.com/resources?s=l1wrssd9hsbi4gak0tp5a6\&name=%5Banthropic%5D-hipaa-ready-offering-implementation-guide) for more detail on implementation.
3434
3535## Usage policy
3636
third-party/claude-desktop/overview Changed · +2 / -2 lines
from line 74
7474
7575## HIPAA
7676
77For Google Cloud's Agent Platform and Amazon Bedrock, Claude Desktop on 3P does not send user data, prompts, or completions to Anthropic, so Anthropic does not interact with PHI a user may upload to Claude Desktop on 3P. Claude Desktop on 3P transmits that data only to your cloud service provider and to any remote MCP servers you choose to configure. For a HIPAA-compliant solution, ensure you have a BAA in place with your cloud service provider and review any MCP servers for HIPAA compliance before connecting them to Claude Desktop on 3P. You don't need to disable telemetry to meet HIPAA requirements, because Anthropic's telemetry carries only redacted crash reports and aggregated usage metrics, never user data, prompts, or completions.
77For Google Cloud's Agent Platform and Amazon Bedrock, Claude Desktop on 3P does not send user data, prompts, or completions to Anthropic, so Anthropic does not interact with PHI a user may upload to Claude Desktop on 3P. Claude Desktop on 3P transmits that data only to your cloud service provider and to any remote MCP servers you choose to configure. For a HIPAA-compliant solution, ensure you have a BAA in place with your cloud service provider and review any MCP servers for HIPAA compliance before connecting them to Claude Desktop on 3P.
7878
79For Microsoft Foundry, HIPAA readiness is not available. Anthropic operates the Claude models in Microsoft Foundry and processes conversation data, as described under [Data handling by provider](#data-handling-by-provider), and Anthropic's HIPAA readiness arrangement (a signed BAA plus safeguards for processing PHI through the Claude API) does not cover Microsoft Foundry. See [What HIPAA readiness does not cover](https://platform.claude.com/docs/en/manage-claude/api-and-data-retention#what-hipaa-readiness-does-not-cover) in the Claude API documentation. If your deployment must handle PHI, configure Google Cloud's Agent Platform or Amazon Bedrock as the inference provider and put a BAA in place with that provider.
79Anthropic's API accessed through Microsoft Foundry (Hosted on Anthropic or Hosted on Azure) is an Eligible Service, as long as you have the HIPAA configuration enabled. Either option requires a BAA with Anthropic. See our [Trust Center](https://trust.anthropic.com/resources?s=l1wrssd9hsbi4gak0tp5a6\&name=%5Banthropic%5D-hipaa-ready-offering-implementation-guide) for more detail on implementation.
8080
8181## Next steps
8282