Insights, stats and other transcript-scanning features no longer denied by HIPAA taint by default
Four local features that scan your transcripts, including Insights, now run in HIPAA-flagged orgs unless the server restricts them or tengu_hashed_lark restores the deny
You'll noticeTier: how much it should matter to you
3Useful: my rating, 1 to 5
3Signal: worth watching, 1 to 5
Managed SettingsArea: what it touches
ImprovementsKind: in v2.1.283,
ImprovementsSection of the release
What
Some Claude Code features read your saved conversation transcripts on your own machine. Organisations can control each one through a policy key. Four of these keys are now marked transcriptScan: !0:
All four are still listed as denied under HIPAA (deniedUnder: ["hipaa"]). The policy check now has an early step for these keys, which runs after the compliance check and any explicit per-feature restriction:
If the server sent an explicit restriction for the key, that restriction is used.
Otherwise the feature is allowed unless the key is in the hinted-denied list.
Before, the HIPAA marking on an organisation denied these features. allow_insights was also denied whenever the policy data was not cached yet (onCacheMiss: "deny").
The new step applies only while the remote switch tengu_hashed_lark is not served true. When no value is sent, the switch counts as not true, so the looser behaviour is the default and the switch brings back the old deny.
Why
In organisations marked for HIPAA, local features such as Insights and usage stats can now run unless the server sends an explicit restriction. Insights should also no longer be blocked just because the policy data was not loaded yet. Administrators relying on the old automatic HIPAA deny should know it now depends on an explicit restriction or on the server switch.