Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.283 ·

Insights, stats and other transcript-scanning features no longer denied by HIPAA taint by default

Four local features that scan your transcripts, including Insights, now run in HIPAA-flagged orgs unless the server restricts them or tengu_hashed_lark restores the deny

Group of 3 You'll notice Improvements
JSON All of v2.1.283
You'll noticeTier: how much it should matter to you
3Useful: my rating, 1 to 5
3Signal: worth watching, 1 to 5
Managed SettingsArea: what it touches
ImprovementsKind: in v2.1.283,
ImprovementsSection of the release

What

Some Claude Code features read your saved conversation transcripts on your own machine. Organisations can control each one through a policy key. Four of these keys are now marked transcriptScan: !0:

  • allow_usage_transcript_scan ("Usage patterns")
  • allow_skill_doctor_transcript_scan ("Skill token counts")
  • allow_insights ("Insights", the /insights report)
  • allow_stats_transcript_scan ("Usage stats")

All four are still listed as denied under HIPAA (deniedUnder: ["hipaa"]). The policy check now has an early step for these keys, which runs after the compliance check and any explicit per-feature restriction:

  • If the server sent an explicit restriction for the key, that restriction is used.
  • Otherwise the feature is allowed unless the key is in the hinted-denied list.

Before, the HIPAA marking on an organisation denied these features. allow_insights was also denied whenever the policy data was not cached yet (onCacheMiss: "deny").

The new step applies only while the remote switch tengu_hashed_lark is not served true. When no value is sent, the switch counts as not true, so the looser behaviour is the default and the switch brings back the old deny.

Why

In organisations marked for HIPAA, local features such as Insights and usage stats can now run unless the server sends an explicit restriction. Insights should also no longer be blocked just because the policy data was not loaded yet. Administrators relying on the old automatic HIPAA deny should know it now depends on an explicit restriction or on the server switch.

Read from
Names in the bundleallow_insights/insights
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not fully clear how the hinted-denied list is filled when no policy has been loaded.

See this entry in the whole of v2.1.283 →

Feedback