Sweep 19 Sep 2026 · 02:36Z Build v2.1.278 500 read Stable v2.1.267 Latest v2.1.278 Next v2.1.278 Feeds RSS JSON llms.txt Unofficial
Claude Code v2.1.267 ·

HIPAA org policy now 'latches': restricted features stay off for the rest of the session

Once a HIPAA-regulated organization is detected, Claude Code disables Artifacts, Remote Control, and other gated features for the rest of the session, even after switching accounts

TierYou'll noticehow much it should matter to you
Useful3my rating, 1 to 5
Signal3worth watching, 1 to 5
AreaCompliancewhat it touches
KindImprovementsin v2.1.267,
Group of 5 You'll notice

Once a HIPAA-regulated organization is detected, Claude Code disables Artifacts, Remote Control, and other gated features for the rest of the session, even after switching accounts

What

  • If Claude Code observes that you're signed into a HIPAA-regulated organization's policy during a session, that fact is now "latched" (remembered) even if the server later stops reporting it.
  • Features gated by this policy, including Artifacts and Remote Control, stay disabled for the rest of the session once latched, with a new user-facing message explaining why.
  • This is treated as a distinct "latched" state alongside the existing org_denied/unregistered/route_missing states in policy checks, and maps to the same policy_denied error code.
  • Switching to a non-HIPAA organization afterward does not lift the restriction; it only clears when Claude Code is restarted.

Why This prevents a session from briefly picking up looser settings by switching organizations after a HIPAA-regulated policy was already in effect, closing a potential gap where compliance-restricted features could be re-enabled mid-session.

See this entry in the whole of v2.1.267 →