{"version":"2.1.285","anchor":"hipaa-related-auto-mode-withholding-and-message","canonical_anchor":"hipaa-related-auto-mode-withholding-and-message","heading":"Auto mode at startup now waits for your organization's policy and can be held back for HIPAA","tier":"notice","area":"Auto Mode","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285\/e\/hipaa-related-auto-mode-withholding-and-message","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285","markdown":"### Auto mode at startup now waits for your organization's policy and can be held back for HIPAA\n\nClaude Code now waits for a pending organization policy before starting in auto mode, can withhold auto mode for HIPAA reasons, and skips it in remote sessions\n\n**Unclear.** It is not clear what marks a session as flagged under the HIPAA policy, or whether this behaviour is switched on remotely.\n\n**What**\n\nA permission mode decides how much Claude does without asking you first, and auto mode lets it go ahead on more actions. When a session starts, Claude Code picks a starting mode. Before, it only re-checked that choice when its cache of server settings was empty. It now also waits on your organization's policy verdict, the policy decision for your account:\n\n- Startup now records whether it is waiting on server settings, on a pending policy verdict, or both. It picks the mode again once the verdict arrives. The log line now says \"startup resolved ... against a pending policy verdict\" as well as the empty-cache case.\n\n- The result gains `autoDefaultWithheldForPendingVerdict`, which holds back auto mode as the default while the verdict is pending.\n\n- The result also gains `autoStartWithheldForHipaaTaint`, which holds back starting in auto mode when the session is marked as affected by HIPAA, the US health-data privacy rules. Both flags are false in the default case.\n\n- A new message reads \"Not shown under your organization's policy: measured by scanning the session transcripts saved on this machine.\"\n\n- Remote sessions, those with `CLAUDE_CODE_REMOTE` set, are now skipped when deciding whether to default to auto mode.\n\n- For non-interactive sessions, those run without you at the keyboard, the built-in fallback of `tengu_moss_anchor` is now also on. This fallback is only used when the server sends no value.\n\n**Why**\n\nThis stops auto mode being chosen before your organization's policy is known. Organizations with HIPAA restrictions may find auto mode held back at startup. Scripted or non-interactive runs may now start in auto mode when the server sends no setting.\n\n- Area: Auto Mode\n- Tier: You'll notice\n- Useful: 3\/5\n- Signal: 3\/5"}