Sweep 19 Sep 2026 · 02:36Z Build v2.1.278 500 read Stable v2.1.267 Latest v2.1.278 Next v2.1.278 Feeds RSS JSON llms.txt Unofficial
Claude Code v2.1.275 ·

New HIPAA-evidence tracking now gates web-fetch and design-sync policy checks

Claude Code now tracks HIPAA-related evidence per account and can block web-fetch or design-sync access based on it

TierNothing to try yethow much it should matter to you
Useful1my rating, 1 to 5
Signal2worth watching, 1 to 5
AreaCompliancewhat it touches
KindIn Developmentin v2.1.275,
Group of 5 Nothing to try yet

Claude Code now tracks HIPAA-related evidence per account and can block web-fetch or design-sync access based on it

What

  • Session and organization-policy state now track HIPAA-related evidence: whether HIPAA-relevant information has been seen (hipaa_seen), seen but incomplete (hipaa_seen_incomplete), or ruled out (hipaa_ruled_out). This replaces a simpler flat list of "seen identities" with a richer evidence structure that also tracks confirm/refuse timestamps (diskConfirmedAtMs, diskRefusedAtMs) and distinguishes IO failures from content-based unusability.
  • This evidence is now checked before allowing the allow_web_fetch and allow_design_sync actions; if the check fails, the policy verdict returns org_denied, a new failure path that did not exist before.
  • A separate feature gate (tengu_tranquil_crescent) can also force this same check to fail immediately, hard-blocking allow_web_fetch/allow_design_sync regardless of the evidence gathered.

Why

This adds a compliance check so web-fetch and design-sync features can be denied for organizations subject to HIPAA rules until their status is properly established, closing a gap where those actions could otherwise run without that check.

Read from
Feature flag
tengu_tranquil_crescent Off in both readings

The flag server returned off for the account this site reads and for the anonymous baseline. A reading of off cannot rule out a rollout these two readings sit outside of.

This account: off · anonymous baseline: off · compiled default in v2.1.275: not a boolean we can read

These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.

Read once, for one account on one subscription tier, against v2.1.275. It isn't a statement about your account. What a flag value here can and cannot tell you

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtplaceholder

See this entry in the whole of v2.1.275 →