A note before I start: this grows out of my work, but I’m writing on my own behalf. I’m not a spokesperson for any organization, and platform decisions belong to senior leadership.
In May I wrote that two of the three frontier coding CLIs were carved out of their vendor’s HIPAA Business Associate Agreement. A member of my team mentioned in a meeting today that the ground had shifted. In the interest of providing factual information, I asked Claude Opus 5 to research it again. The following is our attempt to document the use of LLMs, including on the command line, in an environment subject to HIPAA at the end of July, 2026.
Every vendor now has a route to covered work. None is unconditional, several are only weeks old, and at each the boundary falls inside the product rather than around it.
| Vendor | Tool | Usable with PHI? |
|---|---|---|
| Anthropic | Claude Code | Yes, with zero data retention on a qualified account |
| OpenAI | Codex | Yes on the healthcare track; barred on standard Enterprise |
| Gemini CLI | By inference only; agent mode barred from PHI | |
| AWS | Kiro | Yes for the IDE and CLI; Kiro Web excluded |
| xAI | Grok Build | Yes with a signed BAA and the zero-retention API |
Two of those five answers were rewritten this month โ reason enough to check the date on anything you read about this.
Anthropic: covered, on one condition
Anthropic’s HIPAA-ready Enterprise plans article now reads:
Enabling HIPAA readiness alone doesn’t bring Claude Code under your BAA. Claude Code is covered under your BAA only with zero data retention (ZDR) enabled, and only on qualified accounts.
Without ZDR, Claude Code remains available to use but isn’t covered โ including when Claude Code access is bundled into your Enterprise seats.
That wording is days old. Archived captures carry the opposite position โ Claude Code “not currently covered as part of the HIPAA-ready offering” โ as late as July 3, with the rewrite in place by July 24. We found no announcement of it.
The condition is the whole story. ZDR is not a checkbox: it “is not included in the standard Claude for Enterprise plan and cannot be enabled from your admin settings,” and your account team switches it on per organization. It also costs capability. Claude Fable 5 and Claude Mythos 5 are Covered Models, a status requiring thirty days of retention wherever they appear โ which zero storage cannot satisfy, so neither is reachable from a ZDR organization. Opus 5, Sonnet 5, and Haiku 4.5 stay available, so the trade costs the newest tier rather than the working lineup.
Three details matter more than the headline.
Coverage attaches to a login, not a product. ZDR applies to sessions authenticating into the ZDR organization. A developer signing in with a personal account, or a key from elsewhere, sits outside it while running the identical binary on the same repository. Anthropic ships forceLoginMethod and forceLoginOrgUUID to pin logins.
HIPAA readiness and ZDR are separate arrangements, and the intuitive reading is wrong. Anthropic states that Claude Code “is not covered under HIPAA readiness.” That setting covers chat and much around it โ Projects, Artifacts, Voice, Research, Skills. ZDR covers the CLI. Cowork rides under neither, being “not an Eligible Service under the BAA in any configuration.” Enabling HIPAA readiness is also permanent, and customers needing both regulated and general access must run separate organizations.
Every beta surface is outside. Desktop remote mode, Claude Code on the web, and the Code Review, Code Security, Computer Use, and Remote Control betas are all uncovered.
OpenAI: covered on one contract, banned on another
OpenAI’s answer is the likeliest to catch somebody out, because the company publishes two live documents that contradict each other about the same product. The current page, “HIPAA Eligible Products and Functionality,” was updated two days ago and puts Codex Local on the covered list:
Codex Local involves the installation of Codex Local Client on a local workstation. The HIPAA eligible local clients include CLI, IDE and Desktop App when signed in with a HIPAA eligible ChatGPT account. When the Codex Local Client transmits PHI to OpenAI for processing, OpenAI will protect the Customer PHI consistent with the BAA.
Coverage is scoped to ChatGPT for Healthcare, Enterprise with Regulated Workspace, the FedRAMP variants, ChatGPT for Clinicians, and the API with Modified Retention. This is recent โ the specification it replaced, still online and stamped “no longer maintained,” had Codex under “Access to Non-Included Functionality,” barred from PHI.
Against that, OpenAI’s HIPAA Implementation and Configuration Guide, posted July 9, governs plain Enterprise and Edu โ the tiers without a Regulated Workspace. Its section 5.1, “Unsupported Features,” says they “may not be used with PHI,” and opens with this:
Codex - Customer can disable this functionality through the “Codex Local” and “Codex Cloud” toggles.
Memory and Search agent mode follow it, so the ban is not specific to coding tools. Identical software, same vendor, two live documents eighteen days apart reaching opposite answers. A developer on plain Enterprise who reads the eligible-products page โ the one search puts first โ will reach a confident, wrong conclusion.
Three cautions come from the configuration guide. Scope stops at your network edge: the BAA “does not apply to the execution of the Codex Local Client on Customer’s client machines or to any Third-Party Services accessed by” it, and an agreement with OpenAI “doesn’t make another vendor a HIPAA-compliant destination” โ which matters the moment somebody adds an MCP server. The cloud variant is excluded outright: “The BAA doesn’t cover Codex cloud. Don’t use Codex cloud with PHI.” And none of it is self-serve; the guide says to contact your account director.
OpenAI also publishes no per-seat price for the healthcare track, saying cost “depends on organization size and deployment needs.”
Google: covered by inference, with agent mode off limits
Gemini Code Assist sits on the Google Cloud HIPAA covered-products list, updated July 24, and the CLI documentation says Code Assist Standard and Enterprise data-protection practices “also apply to Gemini CLI.”
Read closely, that is thinner than it sounds. Neither “Gemini CLI” nor “Antigravity” appears on the HIPAA page. The covered product is the Code Assist license, with the command line riding inside โ a defensible reading, but a reading.
The Pre-GA problem is sharper, because it is written down. Pre-GA is Google’s label for a feature offered ahead of general availability, under separate “as is” terms with limited support. Agent mode and agentic chat both still carry those terms, on pages last revised July 17, and the compliance page instructs customers not to use Pre-GA offerings “in connection with PHI, unless expressly noted otherwise.” So the autonomous half of an agentic tool stays barred from patient data. For a chat sidebar that is a footnote; for a CLI, most of the point.
Pricing takes decoding, because Google publishes hourly rates. Code Assist Enterprise lands near $54 per seat per month on a month-to-month commitment, or $45 on a twelve-month term; Standard runs $23 and $19. Enterprise also requires ten licenses minimum.
Two things cut opposite ways. Code Assist is stateless and “doesn’t store prompts and responses in Google Cloud” โ what Anthropic makes you negotiate, Google gives by architecture. But Gemini CLI is being retired for all but Code Assist licensees, and Antigravity CLI appears on no HIPAA list.
Kiro and Grok Build: the newer entrants
Kiro. On May 26, AWS added its own agentic development tool to the HIPAA Eligible Services Reference, specifying that this “applies to the Kiro IDE and CLI. Kiro Web is not included in HIPAA eligible services at this time.” It is the only covered coding CLI we found needing no zero-retention negotiation, no separate healthcare contract, and no Pre-GA disclaimer, sitting under the AWS Business Associate Addendum you execute yourself in Artifact. Its picker is current and multi-vendor: Opus 5 arrived July 24, Sonnet 5 July 1, plus OpenAI’s GPT-5.6 models. Fable 5 and Mythos 5 are absent, matching the Bedrock exclusion.
Grok Build. xAI shipped an official coding CLI on May 14 and publishes a BAA request process. Section 11.1 of its Enterprise terms bars submitting PHI unless a customer has signed a BAA “and also uses xAI’s ZDR-Enabled API to submit that data” โ both conditions, not either. The catch bites harder than Anthropic’s: xAI’s own guidance discourages ZDR, which disables the stateful Responses API, Files, Collections, and Batch. Its default browser sign-in also authenticates against consumer subscriptions, outside the agreement.
Amazon Bedrock: two vendors’ agents, minus two model families
Bedrock is on the HIPAA-eligible list, and OpenAI’s models reached general availability there on June 1, Codex included. The indirect route now carries two vendors’ agents, and an organization already holding that addendum needs no new signature for either. AWS has drawn one boundary: every feature of an eligible service qualifies “unless specifically noted otherwise,” and the entry reads “Amazon Bedrock [excluding Fable and Mythos models]” โ the same two families fenced off on the first-party path.
One caveat, plainly. Anthropic says its BAA “doesn’t apply to services purchased through a third-party cloud provider,” and that on Bedrock the cloud provider is the data processor. No model vendor certifies “Claude Code via Bedrock” by name; the route rests on AWS’s agreement covering the service, a synthesis of two vendors’ documents rather than one vendor’s assurance.
What we checked and did not find
GitHub Copilot does not appear on Microsoft’s published list of BAA-covered services, under either the Microsoft 365 or Azure agreement, and GitHub advertises SOC and FedRAMP for Copilot Enterprise without mentioning HIPAA. Microsoft 365 Copilot and Copilot Chat are both on that list, which is what makes the omission easy to miss: an organization already under the Microsoft agreement can reasonably assume the coding product came along. It did not. Amazon Q Developer is likewise absent; AWS says it “is not designed to transmit, store, or process ePHI.” Cursor checks out, offering Enterprise customers a BAA with Privacy Mode locked organization-wide, its CLI included.
What I’d tell someone pricing this today
The question underneath all of this โ will anyone sign a BAA covering a real coding tool โ now resolves to everyone, moving the decision from eligibility to cost and capability. Four things I’d carry into the conversation:
- The covered surface is a configuration, not a product name. Anthropic covers a CLI authenticated into one organization with a particular retention setting; OpenAI covers a client signed into an eligible account type. Paying for the tool does not buy the coverage, and the gap is invisible from inside the terminal.
- Write down what is covered and tell people. Every vendor here has an adjacent surface that looks identical and isn’t in scope. If the boundary lives only in an analysis like this one, somebody will cross it in good faith.
- Betas and Pre-GA offerings are the recurring trap. Every vendor excludes them, and every vendor ships them into the same tool the developer already has open.
- Compare what each path takes away, not whether one exists. Anthropic’s costs you Fable 5 and Mythos 5. Google’s costs you agent mode. xAI’s costs you the stateful API. Kiro’s costs you a dependency on a single cloud.
One last thing: Anthropic’s position reversed inside three weeks with no announcement, and we dated it only by pulling archived copies of a help-center page. Assume all of this is stale by autumn.
Sources
- Anthropic โ HIPAA-ready Enterprise plans
- Anthropic โ BAA for Commercial Customers
- Anthropic โ Covered Models under a BAA
- Anthropic โ Zero data retention (Claude Code)
- Anthropic โ API and data retention
- Anthropic โ Claude Code authentication
- OpenAI โ HIPAA Eligible Products
- OpenAI โ HIPAA guide for Codex Local
- OpenAI โ HIPAA Implementation Guide, July 9 (PDF)
- OpenAI โ ChatGPT Regulated Workspace, superseded (PDF)
- OpenAI โ ChatGPT for Healthcare
- Google Cloud โ HIPAA Compliance
- Google โ Gemini CLI for Code Assist
- Google โ Gemini Code Assist agent mode
- Google โ Gemini pricing
- Google โ Gemini CLI to Antigravity CLI
- AWS โ HIPAA Eligible Services Reference
- AWS โ OpenAI models and Codex GA on Bedrock
- AWS โ HIPAA compliance for generative AI
- Kiro โ Now a HIPAA eligible service
- Kiro โ Models changelog
- Microsoft โ HIPAA and HITECH
- xAI โ Enterprise Terms of Service
- xAI โ Grok Build
- Cursor โ Business Associate Agreement
