The two lanes
When you’re about to paste, upload, or connect something, ask which lane it’s in. Most work lives comfortably on the left.
- Source code & configs — repos, scripts, infrastructure, queries
- Architecture & technical design — diagrams, trade-offs, decisions
- Internal docs & strategy — plans, roadmaps, org material
- De-identified or synthetic data — “Patient A”,
SAMPLE-001, relative dates - Vendor & market research — dossiers, comparisons, pricing
- Writing & drafts — emails, memos, docs, summaries
- Spreadsheets with no patient identifiers — finance, ops, metrics
- A patient’s name alongside anything health-related
- Member IDs, MRNs, SSNs, DOBs tied to a real person
- Claims data, EOBs, billing with identifying details
- Real records from Athena — appointments, charts, encounters
- Screenshots of the EHR or any screen showing a patient
- Diagnosis or procedure codes linked to an identifiable person
- Any combination that could re-identify an individual
Which lane is this?
Tap an example to see the call. The pattern is always the same: it’s not the topic that’s sensitive, it’s whether the data points back to a real person.
Tap an example above.The verdict and the reasoning will show up here.
What actually counts as PHI
PHI (Protected Health Information) is health, treatment, or payment information tied to someone who can be identified. The trap is the combination: a diagnosis alone is harmless; a diagnosis sitting next to a name, DOB, or member ID is PHI.
Rule of thumb: if a stranger reading it could figure out who the person is, treat it as PHI. Any one of the identifiers below, combined with health or claims information, crosses the line.
What you can let Claude reach
Claude Desktop can connect to files, tools, and your screen. The question is never “is this tool allowed?” — it’s “does what’s behind it contain patient data?”
Files & folders
OK: code repos, design docs, drafts, finance/ops spreadsheets with no patient identifiers.
Not OK: pointing Claude at folders holding patient exports, downloaded reports, scanned charts, or claims files.
Integrations & connectors
Never connect systems that hold PHI — the EHR / Athena, claims, billing-with-patient-data, or member databases. We have no BAA, so these are off-limits.
OK: GitHub, Linear, internal wikis, and Drive folders you’ve confirmed are PHI-free.
Screen & screenshots
Not OK: sharing your screen or pasting screenshots while anything patient-related is visible — a chart, a worklist, an EHR tab in the background.
Close it first. One visible name or MRN makes the whole image PHI.
The 👍 / 👎 rating buttons
Rating a chat is the one action that sends that whole conversation to Anthropic, outside the no-training default. Treat the rating buttons as “send a copy to Anthropic.”
Never rate a chat containing anything sensitive. Admins can switch this off org-wide.
Why business info is safe to use
Your work account runs on Claude Team, which is governed by Anthropic’s Commercial Terms — a different, stronger framework than the consumer plans people use at home.
Not used to train models
By default, Anthropic does not train its models on your inputs or outputs under the commercial plans. Source
Team sits outside consumer terms
The consumer opt-in training and 5-year retention do not apply to Claude for Work (Team & Enterprise). Source
You keep ownership
Anthropic acts as a data processor for the Team plan: Hopper keeps rights to its inputs and owns the outputs.
Short retention, no resale
Deleted conversations are purged on a ~30-day cycle, your data isn’t sold, and Claude is ad-free.
Because business confidentiality is not the same as HIPAA coverage. HIPAA requires a Business Associate Agreement (BAA), and we don’t have one on this plan. The protections above keep your company data safe — they do not make Claude a HIPAA-compliant home for patient data. That’s the whole reason for the one rule. More on commercial data handling
If PHI ends up in Claude anyway
Mistakes happen and we assume good faith. What matters is acting quickly and reporting it — there’s always a path forward.
Quick answers
Can my manager or Anthropic read my chats?
Can I just use my personal Claude or ChatGPT for work instead?
Is de-identified data really OK?
MRN: SAMPLE-001, and relative dates (“3 days post-op”) instead of real ones. If you’re reconstructing a real case, make sure no combination of details could point back to the actual person.