UChicago Claude Enterprise: Full vs. HIPAA Version


Audience: Faculty, staff, and student users of UChicago Claude Enterprise; unit IT staff determining which version applies to their population.

Summary: This article explains the difference between the full version of UChicago Claude Enterprise and the HIPAA version, which features are available in each, and what your obligations are if you are in the HIPAA version.

Contents

Overview

UChicago Claude Enterprise is provisioned in two versions:

 

 

Full version

HIPAA version

Who

Faculty, staff, and students outside HIPAA-covered functions

Users in HIPAA-covered roles, primarily BSD clinical staff

How assigned

Self-service request through SailPoint

Self-service request through SailPoint, voluntary selection of the HIPAA option

Feature set

Full Claude Enterprise feature set as enabled by the University

Restricted feature set limited to services covered by the University's Business Associate Agreement (BAA) with Anthropic

PHI permitted

No

Yes, with prior approval

 

The University has an executed BAA with Anthropic. The BAA covers a defined list of Claude Enterprise services ("Eligible Services"). Features outside that list are excluded from BAA coverage, and disabled for HIPAA-configured customers. The HIPAA version exists so that users in covered roles operate only within the BAA-covered surface.

What is the same in both versions

The core Claude experience is identical. Both versions include:

These are the services Anthropic designates as Eligible Services under the BAA.

 

What is different in the HIPAA version

The following features are excluded from BAA coverage. They are disabled in the HIPAA version and will not appear, or will not function, for users in that group:

 

Feature

Why it is excluded

Connectors (MCP)

Connector data flows to third-party services. Anthropic's BAA does not cover data sent to third parties. We will only enable connectors with companies we have our own BAAs with.

Enterprise Search ("Ask Your Org")

Built on connector data; same third-party coverage gap.

Claude in Chrome

Browses third-party sites; third-party site data is not covered.

Claude Cowork

Sessions are not captured in audit logs, the compliance API, or data exports, so there is no compliance-grade record of the session.

Claude in Office (Excel/PowerPoint)

Sessions are not captured in audit logs, the compliance API, or data exports, so there is no compliance-grade record of the session.

Claude Design

Beta feature; not covered.

Two limits apply even to covered features:

Claude Code in the HIPAA version

Claude Code is covered under the Anthropic BAA only when Zero Data Retention (ZDR) is in effect for the account. The University does not have this feature enabled, and hence Claude Code is not included in the HIPAA version.

Your obligations in the HIPAA version

If you are provisioned in the HIPAA version:

  1. Use only the features available to you. Disabled features are disabled deliberately. Do not attempt to work around restrictions, including by using a personal Claude account.
  2. Do not enter PHI unless authorized.
  3. Keep PHI out of names. Even where content is covered, do not place patient-identifying information in skill names. Treat project names, artifact titles, and file names with the same care.
  4. Report inadvertent exposure. If PHI is entered into a feature or version where it is not permitted, report it immediately to security@uchicago.edu.
  5. When using sensitive data of any kind, obtain the specific, prior approval of the University's or UChicago Medicine (UCM)'s privacy office and the appropriate data steward before using it with such information.

Which version do I have?

Your version depends on the selection you make during the account request process.

If you believe you are in the wrong version — for example, your role handles PHI but you have Claude Code access — contact the ITS Service Desk. Do not continue using features that expose regulated data.

Future Updates

The features that are covered under the BAA will change as the products evolve. We will add any features that become HIPAA-compliant after the appropriate review. To stay informed of these changes and learn about feature releases, please subscribe to our mailing list.

 

Related information

 

Getting help

Contact the ITS Service Desk at 773.702.5800, or via the Services portal.