Set up Cowork (local mode) for a HIPAA-ready organization changedcowork/hipaa-setup
Nearest release: v2.1.291, published under an hour after upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Upstream edited this page at 6 Oct 2026 03:05 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 6 Oct 2026 03:07 UTC.
Upstream edited
Recorded here
Lines+5added
Lines−5removed
From line
52
where the diff opens
First seen
5 Oct 2026
this site's first read of the page
Recorded edits3to this page, all time
The whole hunk
from line 52, old and new numbered
/
from line 52
5252
5353### Allow network access for Claude Desktop
5454
55Allow the hosts in this table through your proxy and firewall, over HTTPS on port 443. The table lists the hosts that the tasks on this page depend on, and leaves out the rest.
55Allow the Anthropic hosts listed in [Desktop network access requirements](https://code.claude.com/docs/en/desktop#network-access-requirements) through your proxy and firewall. Claude Desktop reaches them over HTTPS on port 443. The table shows what Claude Desktop uses three of those hosts for. The setup on this page depends on all three.
5656
5757| Host | Needed for |
5858| :- | :- |
from line 60
6060| `api.anthropic.com` | Claude API requests, update checks, and the status that tells Claude Desktop the HIPAA configuration is on |
6161| `downloads.claude.ai` | The virtual machine image that Cowork runs shell commands in, the Claude Code binary, and app updates |
6262
63[Desktop network access requirements](https://code.claude.com/docs/en/desktop#network-access-requirements) lists the Anthropic hosts to allow for Claude Desktop.
64
6563### Deploy the Claude Desktop policy
6664
6765A Claude Desktop policy is a set of settings that your device management tool installs on each computer, as a configuration profile on macOS or as registry values on Windows. You can use one to restrict sign-in to your organization, turn off local MCP servers and desktop extensions, and keep session content out of [Cowork monitoring](/docs/cowork/monitoring) events.
from line 179
181179* **Domain allowlist**: the Owner selects a preset list of domains. With the HIPAA configuration applied, the **All domains** option is unavailable
182180* **Additional allowed domains**: the Owner adds each domain your organization needs
183181
182If **All domains** is still selected when your organization applies the HIPAA configuration, the VM reaches only `anthropic.com` and `claude.com` hosts, plus your OpenTelemetry collector if Cowork monitoring is set up. Entries in **Additional allowed domains** have no effect. To avoid or undo this, ask the Owner to select a different **Domain allowlist** option.
183
184184### Turn off web search in Cowork
185185
186186Web search in Cowork follows your organization's web search setting. Applying the HIPAA configuration doesn't change it. If web search is on and your organization's own policy forbids it, turn it off at one of these levels:
from line 254
254254
255255| Location | What it holds | Deleted automatically |
256256| :- | :- | :- |
257| Task folders in `local-agent-mode-sessions`, in the Claude Desktop data folder | One folder per Cowork task, with the task's transcript, uploaded files, and outputs | Yes, [after `cleanupPeriodDays`](#when-claude-desktop-deletes-cowork-tasks), except for the background sessions that Dispatch creates |
257| Task folders in `local-agent-mode-sessions`, in the Claude Desktop data folder | One folder per Cowork task, with the task's transcript, uploaded files, and outputs | Yes, [after `cleanupPeriodDays`](#when-claude-desktop-deletes-cowork-tasks), with one exception |
258258| Everything else in `local-agent-mode-sessions`, in the Claude Desktop data folder | Data that Cowork keeps between tasks, such as memory and plugins | No |
259259| `vm_bundles`, in the Claude Desktop data folder | The disk images of the virtual machine that runs shell commands | No |
260260| The Cowork files folder, `~/Claude` by default | Artifacts, scheduled tasks, and project files | No |
from line 270
270270
271271If your organization also uses [server-managed settings](https://code.claude.com/docs/en/server-managed-settings), have an Owner set `cleanupPeriodDays` there too. Claude Desktop reads server-managed settings for this check, and [uses one managed source at a time](https://code.claude.com/docs/en/managed-settings#how-claude-code-combines-managed-sources).
272272
273With the HIPAA configuration applied, Claude Desktop deletes Cowork tasks that have been inactive for longer than `cleanupPeriodDays`, including starred and archived ones. Running or opening a task counts as activity.
273With the HIPAA configuration applied, Claude Desktop deletes Cowork tasks that have been inactive for longer than `cleanupPeriodDays`, including starred and archived ones. Running or opening a task counts as activity. Task folders for background sessions that Dispatch created before your organization applied the HIPAA configuration stay until you delete them.
274274
275275Claude Desktop checks for tasks to delete after it starts, and every six hours while it stays open. The check needs all of these conditions:
276276
No line in this hunk matches that.