CCARP-D5.3 · Domain 5 · Governance, Safety & Risk · 14% of CCA-P

Regulatory Compliance for AI Systems (GDPR, HIPAA, FedRAMP).

10 min read·9 sections·Tier A

Compliance is a match-the-surface-to-the-regime exercise: an architect picks the deployment surface (API direct, AWS Bedrock, GCP Vertex, Microsoft Foundry, Claude for Government) and account tier the workload requires, then explicitly turns on the controls that are not on by default. HIPAA BAA coverage is opt-in, not automatic, and has three distinct paths (Enterprise Primary Owner self-activation, mostly-self-serve API activation in Console, or the cloud provider's own BAA on Bedrock/Vertex), and FedRAMP High/DoD IL4-5 is tied to specific US-only surfaces that are not simultaneously combinable with an EU-resident deployment on the same workload. Anthropic Trust Center

Anthropic Trust Center + compliance pagesCCA-P Domain 5CCA-P + CCA-A
Regulatory Compliance for AI Systems (GDPR, HIPAA, FedRAMP), hero illustration featuring Loop mascot in a warm gallery scene.
Domain CCARP-D5Governance, Safety & Risk · 14%
On this page
01 · Summary

TLDR

Compliance is a match-the-surface-to-the-regime exercise: an architect picks the deployment surface (API direct, AWS Bedrock, GCP Vertex, Microsoft Foundry, Claude for Government) and account tier the workload requires, then explicitly turns on the controls that are not on by default. HIPAA BAA coverage is opt-in, not automatic, and has three distinct paths (Enterprise Primary Owner self-activation, mostly-self-serve API activation in Console, or the cloud provider's own BAA on Bedrock/Vertex), and FedRAMP High/DoD IL4-5 is tied to specific US-only surfaces that are not simultaneously combinable with an EU-resident deployment on the same workload. Anthropic Trust Center

4
Commercial certifications
CCA-P D5 (14%)
Exam domain
5
Deployment surfaces mapped
3 (Enterprise / API / cloud BAA)
HIPAA BAA paths
CCA-A D6
Also tested in
02 · Definition

What it is

An architect's compliance job is to match the deployment surface an organization uses, API direct, AWS Bedrock, GCP Vertex, Azure/Microsoft Foundry, or Claude for Government, and the account tier, to the regulatory regime the workload requires, then explicitly enable the controls that are not on by default. Anthropic's compliance posture is real but conditional: several protections require administrator action rather than automatic inclusion, and the exact certification set differs for consumer versus commercial products.

This is a verify the current tier's paperwork discipline, not a one-time checkbox. GDPR, HIPAA, and FedRAMP are three different kinds of regime, a legal framework, a US healthcare law with a contractual mechanism (the BAA), and a federal authorization program, and each maps to a different artifact or deployment path rather than one universal "Anthropic is compliant" answer.

03 · Mechanics

How it works

Commercial certification baseline. Anthropic's commercial products, Claude for Work and the Anthropic API, maintain HIPAA-ready configuration (BAA available), ISO 27001:2022, ISO/IEC 42001:2023 (AI Management Systems), and SOC 2 Type I & II. These are explicitly scoped to commercial products, not consumer plans, a team prototyping on a free or consumer account cannot point to this certification set at all, regardless of what it builds.

HIPAA BAA coverage is opt-in, and it has three genuinely different paths, not one workflow with two names. (1) On Claude Enterprise, specifically the organization's Primary Owner self-activates HIPAA compliance under "Data & Privacy" settings and signs Anthropic's BAA directly — other Owners or Admins cannot complete this on the org's behalf; standard Enterprise plans do not include this automatically. (2) On the direct 1P API, BAA eligibility is a *separate* path from Enterprise's — but for most organizations it's ALSO self-service: eligible orgs review and execute Anthropic's standard BAA directly in Claude Console (Settings > Privacy), no sales contact required. Only organizations needing a negotiated/custom BAA, or where self-serve isn't available, work through Anthropic's sales team instead. Critically, HIPAA readiness on the API does NOT cover every feature — the Batch API is explicitly NOT HIPAA-eligible, so PHI cannot be sent through Batch even with an active BAA; the API enforces this with a 400 error on non-eligible features. (3) Via a cloud-provider surface (AWS Bedrock, GCP Vertex), coverage runs under that provider's own BAA (the AWS or Google Cloud Business Associate Addendum), not Anthropic's BAA at all, the model provider never sees the raw prompts/completions in that path. Conflating the Enterprise activation workflow with API BAA eligibility, or assuming either one covers a Bedrock/Vertex deployment, is a live compliance gap: a healthcare workload touching PHI before the *specific* path's activation step is complete is uncovered, independent of which model or feature is in use.

FedRAMP High and DoD IL4/5 live on a different surface, not a policy toggle, and that surface is not freely combinable with an EU-resident deployment for the same workload. Claude models are approved for FedRAMP High and DoD Impact Level 4/5 workloads via Amazon Bedrock in AWS GovCloud (US) regions, and Anthropic separately offers Claude Gov models for classified environments plus a dedicated Claude for Government application at FedRAMP High, all US-only, isolated surfaces. EU data/inference residency is a *different* regional deployment (available across AWS Bedrock, GCP Vertex, and Microsoft Foundry EU regions). A single workload runs in one geographic surface at a time, so "FedRAMP High AND EU-resident" isn't a combinable pair of controls on one deployment, it describes two separate workloads on two separate surfaces. Reaching the federal regime means routing through a GovCloud/Government surface, not requesting paperwork against the standard commercial API.

Regional residency and GDPR run on a DPA plus a data-location choice. GDPR itself is not an Anthropic certification but a legal regime; the load-bearing artifact for an EU deployment is typically the Data Processing Addendum governing Anthropic's role as processor, combined with a regional data-residency choice available across AWS Bedrock, GCP Vertex, and Microsoft Foundry. Architects should verify current DPA terms against the live document rather than assume blanket "GDPR compliant" status.

The Trust Center is the canonical, living source. trust.anthropic.com hosts the current SOC 2 Type 2 and CSA STAR L2 reports, the DPA, and security-control documentation, request-gated rather than fully public. Because certifications and terms change, the compliance check is per-deployment verification against that live source, not a fact memorized once.

Regulatory Compliance for AI Systems (GDPR, HIPAA, FedRAMP) mechanics, painterly diagram featuring Loop mascot.
04 · In production

Where you'll see it

Healthcare clinical-notes summarizer

Use Claude for Work/Enterprise or the API, never a consumer plan; on Enterprise, have the org's Primary Owner specifically enable HIPAA compliance and execute the BAA before any PHI touches the system (other Owners/Admins can't do this step); choose a regional deployment matching data-residency requirements.

Federal internal research assistant

Route through Bedrock GovCloud or Claude for Government to land inside the FedRAMP High / IL4-5 boundary, a fundamentally different deployment path than the healthcare case, not just a policy toggle on the same one.

05 · Compare

Side-by-side

SurfaceGeographyHIPAA path if PHI involvedFedRAMP High / IL4-5?Combinable with EU residency on the same workload?
Claude for Work / Enterprise (Primary Owner BAA)Anthropic-hosted, region per Anthropic's offeringPath 1 - Primary Owner specifically self-activates under Data & Privacy, signs Anthropic BAANoN/A - not the FedRAMP surface
Direct 1P API (Console self-serve BAA)Anthropic-hostedPath 2 - eligible orgs self-enable in Console; sales only for negotiated/custom BAAs. Batch API is NOT covered even with an active BAA.NoN/A - not the FedRAMP surface
AWS Bedrock / GCP Vertex (regional)Region-selectable, incl. EUPath 3 - covered under the cloud provider's own BAA, not Anthropic'sNo (this is the commercial regional path, not GovCloud)Yes - this IS the EU-residency surface
AWS Bedrock in AWS GovCloud (US)US-only, isolatedCovered under AWS's GovCloud BAA where applicableYesNo - GovCloud (US) and EU-resident Bedrock are different, non-overlapping regions
Claude for Government / Claude Gov modelsUS-only, isolatedGovernment-contract terms, not the standard BAA paths aboveYesNo - a separate, US-only surface
06 · When to use

Decision tree

01

Does the workload process Protected Health Information (PHI)?

YesIdentify which surface it runs on first: Enterprise needs the Primary Owner specifically to self-activate under Data & Privacy plus Anthropic's BAA (other Owners/Admins can't); the direct 1P API is usually self-service in Console for eligible orgs (sales only for negotiated/custom BAAs) — but even then, check the Batch API is NOT covered by that BAA; AWS Bedrock/GCP Vertex need the cloud provider's own BAA, not Anthropic's. Confirm the matching path, and its feature coverage, before any PHI touches the system.
NoNo BAA activation needed for this regime, continue checking the other regimes below.
02

Does the workload need to sit inside a FedRAMP High or DoD IL4/5 boundary?

YesRoute through Amazon Bedrock in AWS GovCloud (US) regions, or Claude for Government / Claude Gov models for classified environments, a different deployment surface than the commercial API, not paperwork layered on top of it. Note this surface is US-only.
NoNo federal-authorization boundary required for this workload.
03

Does the same workload ALSO need FedRAMP High/IL4-5 AND EU-resident data/inference at once?

YesNot achievable on one deployment - GovCloud (US) and EU-resident Bedrock/Vertex/Foundry are separate, non-overlapping regional surfaces. Split into two workloads on two surfaces, or confirm which requirement actually governs this specific data flow.
NoProceed with whichever single surface matches the workload's actual regime.
04

Does the workload require EU or cross-border data-residency guarantees?

YesChoose a regional deployment (available across AWS Bedrock, GCP Vertex, and Microsoft Foundry) and verify the current Data Processing Addendum against the live Trust Center document, GDPR is not a certification Anthropic grants, the DPA plus residency choice are the artifacts.
NoRegional residency choice is not a blocking requirement here.
05

Is the workload currently running on a consumer Claude plan rather than Claude for Work/Enterprise/API?

YesStop, none of the HIPAA BAA path, the ISO 27001/ISO 42001/SOC 2 certification set, or the FedRAMP surfaces apply to consumer plans, move to a commercial surface before layering on any of the checks above.
NoCommercial surface confirmed, the regime-specific controls above are reachable from here and can combine on the same deployment.
07 · Per certification

How each cert tests this

CCA-P

CCARP-D5-O4 (Governance, Safety & Risk, 14%): tests matching deployment surface, API direct, Bedrock GovCloud, Enterprise plus admin-activated BAA, or a regional choice, to the specific regulatory regime a workload requires, and knowing which controls need explicit activation versus which are automatic.

CCA-A

CCAOF-D6-O2 (Governance, Risk & Responsible Use, 15%): tests applying data-sensitivity, regulatory, and privacy considerations at the business-user level, recognizing when a task touches PHI, regulated data, or cross-border residency before routing it to Claude, without necessarily architecting the deployment surface.

08 · On the exam

Question patterns

Regulatory Compliance for AI Systems (GDPR, HIPAA, FedRAMP) exam trap, painterly cautionary scene featuring Loop mascot.

6 V2 questions wired to this concept. Tap an answer to check it instantly - you'll see whether it's right and why - then expand the full breakdown for the mental model and all four rationales.

A healthcare provider wants to route patient clinical notes through a Claude-based summarization tool hosted via a cloud provider's managed API. Which compliance question must be resolved before this is deployed, specific to handling protected health information (PHI)?

Tap your answer to check it.

A European customer asks whether their data, processed by a Claude-based feature, will remain within the EU for GDPR data-residency purposes. The architect confirms the application servers are hosted in an EU region but has not verified where the underlying model inference actually runs or where any logged prompts/completions are stored. What is the compliance risk being overlooked?

Tap your answer to check it.

A product team wants to reduce GDPR exposure before sending customer-support conversations to an LLM. Which design most directly applies the data-minimization principle?

Tap your answer to check it.

A customer validly requests erasure under GDPR. Their support messages were copied into raw archives, an LLM conversation store, and a semantic search index. What should the erasure workflow do?

Tap your answer to check it.

A hospital's scheduling assistant needs appointment dates and department names but not diagnoses. Staff often paste entire clinical notes into chat. Which control best supports HIPAA's minimum-necessary principle?

Tap your answer to check it.

A federal agency operates an application inside a FedRAMP-authorized cloud boundary. A developer proposes sending unclassified but sensitive prompts from that application to a separate commercial LLM endpoint that is not included in the authorization package. What is the primary governance issue?

Tap your answer to check it.

09 · FAQ

Frequently asked

Does using the Anthropic API automatically give me a HIPAA BAA?
No, it must be explicitly enabled, but for most orgs it's a self-serve step: review and execute Anthropic's standard BAA directly in Claude Console (Settings > Privacy). Sales involvement is only needed for a negotiated/custom BAA, or if self-serve isn't available for your org. Neither this nor Enterprise activation applies to consumer plans, and neither is pre-enabled. Note that even an active API BAA doesn't cover every feature — Batch API is explicitly excluded.
If I use Claude via AWS Bedrock or GCP Vertex, do I need Anthropic's BAA?
No - coverage there runs under the cloud provider's own BAA (AWS's or Google Cloud's), not Anthropic's. It's a third, separate path from the Enterprise and direct-API BAA workflows.
Can one deployment be both FedRAMP High and EU data-resident?
No. FedRAMP High/IL4-5 (AWS GovCloud US, Claude for Government) and EU residency (regional Bedrock/Vertex/Foundry) are different, non-overlapping geographic surfaces - a single workload runs on one or the other, not both at once.
Does Google Cloud Vertex AI have any FedRAMP authorization of its own?
Yes, a separate and lower one: Claude on Vertex AI holds FedRAMP High and DoD IL2 authorization (IL5 is a stated future target), distinct from AWS GovCloud's higher FedRAMP High + IL4/5. A workload requiring IL4/5 specifically needs AWS GovCloud or Claude for Government - Vertex's current authorization does not reach that level.
Where do I find current compliance artifacts like SOC 2 reports or the DPA?
The Anthropic Trust Center (trust.anthropic.com) is the canonical source. SOC 2 Type 2, CSA STAR L2, and the DPA are request-gated there, not on public marketing pages, and terms should be verified per deployment since they change.
10 · Practice with AI

Work this with your AI

Work this concept hands-on with Claude Code, Codex, or claude.ai. Copy a prompt, paste it into your assistant, and practise in tandem. Each one keeps you active (explain it back, get drilled, or build) rather than just reading.

  • Drill it like the exam (scenario MCQs)
    Practice in the exam's scenario-MCQ format with trap awareness.
  • Explain it back (Feynman)
    Build durable, transferable understanding of a concept you can half-state.
  • Test me, adapting the difficulty
    Active recall practice on a concept you think you know.
  • Check my prerequisites first
    Before studying a concept that keeps not sticking.
  • Find the high-leverage 20%
    When a domain feels too big and you are short on time.
Self-check

Test yourself

Three diagnostic questions on this primitive. Reveal each answer when you have a guess. Want a full 60-question mock? Open the mock hub →

Q1A healthcare startup is on Claude's standard Enterprise plan and starts processing PHI without any additional setup. Are they covered by a BAA?
No. HIPAA BAA coverage is opt-in on Enterprise: specifically the organization's Primary Owner must explicitly enable HIPAA compliance under Data & Privacy settings and execute Anthropic's BAA before it applies (other Owners or Admins cannot complete this on the org's behalf); standard Enterprise plans do not include BAA coverage automatically. Named distractor: "Enterprise plans always include HIPAA BAA coverage by default" - the opposite of Anthropic's documented opt-in mechanism.
Q2A team already has an Anthropic BAA signed for their Claude Enterprise seats. They now start sending PHI through the direct 1P API for a separate internal tool. Does the Enterprise BAA cover the API usage?
Not automatically - Enterprise BAA activation (Primary Owner self-service under Data & Privacy) and direct API HIPAA readiness are two separate paths, each activated independently (though for most orgs the API path is ALSO self-service in Console, not sales-mediated). Named distractor: "one signed BAA with Anthropic covers all surfaces, Enterprise and API alike" - it conflates two distinct activation workflows into one.
Q3An organization has HIPAA readiness enabled on its direct 1P API and wants to run a nightly PHI-processing job through the Message Batches API to save 50% on cost. Is this covered under the BAA?
No - Batch processing is explicitly excluded from HIPAA eligibility (it requires 29-day async storage, which HIPAA readiness does not cover), regardless of whether the organization's API BAA is active. The API enforces this: a HIPAA-enabled org gets a 400 error on non-eligible features in the request. Named distractor: "any feature is covered once the organization-level BAA is active" - HIPAA readiness covers a SPECIFIC list of eligible features per request, not everything the organization does.
CCARP-D5.3 · CCARP-D5 · Governance, Safety & Risk

Regulatory Compliance for AI Systems (GDPR, HIPAA, FedRAMP), complete.

You've covered the full ten-section breakdown for this primitive, definition, mechanics, code, false positives, comparison, decision tree, exam patterns, and FAQ. One technical primitive down on the path to CCA-F.

More platforms →