Reviewed by Jonathan West · Updated Jul 30, 2026

Is Claude Opus 5 HIPAA Compliant?

What Anthropic's BAA actually covers, which Opus 5 plans qualify, and the retention detail healthcare teams miss.

Reviewed by Jonathan West · Updated Jul 30, 2026

Claude Opus 5 can be used in a HIPAA-compliant way, but only if you sign Anthropic's Business Associate Agreement (BAA) and access the model through a covered surface. The model itself does not make you compliant.

Opus 5 launched July 24, 2026 as Anthropic's second-highest-tier model, running on the same API and Enterprise infrastructure as every other current Claude model. That matters for compliance: Opus 5 inherits the same BAA terms and certifications as the rest of the lineup rather than shipping its own separate policy.

Healthcare teams often assume a signed BAA covers every way of reaching Claude. It does not. Coverage applies only to the first-party API and HIPAA-ready Enterprise plans — Claude.ai Free, Pro, Max, and Team never qualify, regardless of which model answers.


The Honest Answer

Claude Opus 5 can be part of a HIPAA-compliant workflow, but only through a covered plan with a signed Anthropic BAA. No AI model is HIPAA compliant on its own.

Anthropic signs a BAA for two surfaces: the first-party Claude API and HIPAA-ready Enterprise plans. Opus 5 runs on that same API and Enterprise infrastructure, so it is covered wherever those surfaces apply.

Opus 5 is not a Mythos-class model — it is a separate line from Claude Mythos 5 in Anthropic's current lineup. That distinction matters because Anthropic applies a mandatory 30-day safety retention specifically to Mythos-class models on business accounts, which limits their eligibility for full zero-data-retention. Confirm directly with Anthropic, in writing, whether your BAA and any Zero-Data-Retention (ZDR) terms extend to Opus 5 before PHI touches the model.

  • No model is HIPAA compliant by itself
  • Anthropic signs a BAA for the first-party API and HIPAA-ready Enterprise plans
  • Opus 5 runs on the same covered infrastructure as other current Claude models
  • Opus 5 is not Mythos-class — confirm its ZDR eligibility with Anthropic in writing
Claude Opus 5 is not HIPAA compliant by default. It can be used with PHI only on a covered plan, with a signed BAA, and after you confirm retention terms directly with Anthropic.

Want help confirming your Anthropic BAA and ZDR terms cover Claude Opus 5 before you use it with PHI under HIPAA?

Book a Consultation

What HIPAA Requires of an AI Vendor

HIPAA requires a signed BAA plus real safeguards before any vendor can handle protected health information (PHI). The BAA is the contract that makes the vendor legally responsible for protecting patient data.

The safeguards matter as much as the contract. HHS requires access controls, audit logging, breach reporting, and limits on how the vendor may use or disclose the data. For AI vendors, that also means the model must not train on your PHI.

These rules apply to Anthropic the same way they apply to any other vendor. A newer, more capable model does not change what HIPAA asks of it.

  • A signed BAA before any PHI is sent
  • Access controls and audit logging
  • Breach reporting duties defined in the contract
  • No training on your PHI

Anthropic's Compliance Baseline

Anthropic holds the core certifications healthcare buyers look for: SOC 2 Type I and Type II, ISO 27001:2022 for information security, and ISO/IEC 42001:2023 for AI management systems.

Anthropic signs a HIPAA BAA on its first-party API and HIPAA-ready Enterprise plans. Coverage on Enterprise includes chat, projects, artifacts, and tool use; on the API it covers the Messages API, prompt caching, and structured outputs. Opus 5 runs on both, so it inherits this baseline.

That baseline does not extend to Claude.ai Free, Pro, Max, or Team — those plans get no BAA regardless of which model is selected, including Opus 5.

  • SOC 2 Type I and Type II
  • ISO 27001:2022 for information security
  • ISO/IEC 42001:2023 for AI management systems
  • HIPAA BAA on the first-party API and HIPAA-ready Enterprise plans only
Anthropic's certifications prove the platform can support HIPAA. They do not cover Claude.ai Free, Pro, Max, or Team — that gap trips up teams who assume any Claude surface qualifies.

Retention and Zero Data Retention on Opus 5

Zero data retention matters most to healthcare teams with payer contracts or risk analyses that require it. Anthropic offers a ZDR addendum for eligible APIs and Claude Code for Enterprise, where Anthropic does not store inputs or outputs except where law requires.

Claude Opus 4.8, the model Opus 5 succeeded, is not Mythos-class and remains eligible for ZDR on qualifying plans. Because Opus 5 sits in the same non-Mythos line, the same eligibility should reasonably extend to it — but this is a confirmation to get from Anthropic in writing, not an assumption to build a compliance program on.

If your contract requires true zero retention with no exceptions, get that confirmation before PHI reaches Opus 5, the same way you would for any new model release.

  • ZDR is available on eligible APIs and Claude Code for Enterprise plans
  • Opus 4.8 (not Mythos-class) qualifies for ZDR today
  • Opus 5 sits in the same non-Mythos line, but confirm eligibility with Anthropic directly
  • Never assume ZDR terms carry over silently across model releases

A Safe-Use Checklist Before Sending PHI to Opus 5

Follow a short checklist before Opus 5 sees any patient data. Each step closes a gap that a new flagship model release can leave open.

Start by confirming the BAA is signed and that you are using the first-party API or a HIPAA-ready Enterprise plan — never Claude.ai Free, Pro, Max, or Team. Then confirm in writing whether your ZDR terms explicitly extend to Opus 5.

Until every box is checked, keep PHI out of the model. Your team can still use Opus 5 for tasks with no patient data while the paperwork clears.

  • Confirm a signed Anthropic BAA is in place
  • Confirm you are using the first-party API or HIPAA-ready Enterprise — not Free, Pro, Max, or Team
  • Confirm in writing whether ZDR terms extend to Opus 5 specifically
  • Keep all PHI out until every box is checked
One careless paste of patient data into Claude.ai Pro instead of a HIPAA-ready Enterprise seat can create a reportable breach. Check the plan before, not after.

Frequently Asked Questions

  • Not by itself. Claude Opus 5 can be used in a HIPAA-compliant way only on the first-party API or a HIPAA-ready Enterprise plan with a signed Anthropic BAA. Claude.ai Free, Pro, Max, and Team are never covered, regardless of which model answers.
  • Yes. Anthropic signs a HIPAA BAA covering the first-party Claude API and HIPAA-ready Enterprise plans, and Opus 5 runs on those same covered surfaces.
  • Likely, but confirm it directly. Opus 5 is not a Mythos-class model, and Anthropic's Zero-Data-Retention addendum already covers the similarly non-Mythos Opus 4.8 on eligible plans. Get written confirmation from Anthropic that your ZDR terms extend to Opus 5 before relying on it.
  • Claude.ai Free, Pro, Max, and Team plans get no BAA regardless of model. PHI should only ever reach Opus 5 through the first-party API or a HIPAA-ready Enterprise seat.
  • Anthropic holds SOC 2 Type I and Type II, ISO 27001:2022, and ISO/IEC 42001:2023. These apply platform-wide, including to Opus 5, on covered surfaces.
  • Check Anthropic's BAA article and HIPAA-ready Enterprise plans page, and confirm certifications through Anthropic's privacy center. For the HIPAA rules themselves, rely on HHS.gov rather than third-party summaries.

Not sure if your Anthropic BAA covers Claude Opus 5?

Layer3 Labs helps healthcare teams use AI within HIPAA. Book a free AI workflow audit and we will help you confirm BAA scope, plan eligibility, and a safe workflow for Claude Opus 5.

Book a Free AI Workflow Audit