HIPAA readiness on,and the record still kept.
With HIPAA readiness enabled, Anthropic captures no local session data. OpenWatch records Claude Desktop and Cowork sessions on the device, so clinical, operations and privacy teams can still answer what happened.
The safeguardremoves the record.
01
Local sessions leave no vendor log
HIPAA readiness stops Anthropic capturing local session data, so there's nothing server-side to review later.
02
PHI rules live in a policy document
Staff are trained on what not to paste into AI tools. Nobody checks what actually gets pasted.
03
Patients ask what systems hold
An access request that touches AI tools needs evidence of where the data is.
Scenarios
Questions privacy teams face,answered from the record.
How OpenWatch answers
Filter sessions by person and time, see which documents each session referenced by name, and export the list from the dashboard.
How OpenWatch answers
Write your PHI rules into the AI policy. Claude reviews recent prompts against it every morning and files a ticket for each likely breach, citing the messages. It's a policy check, not an automatic PHI classifier.
How OpenWatch answers
Open an access request with a 30-day deadline, cite the sessions and chats involved, and record the attestation when Attri's team has prepared the export.
What the organisation gets.
- Coverage where vendor logs stopLocal Desktop and Cowork sessions recorded on the device.
- PHI rules checked dailyYour written policy compared with real prompts, with findings as tickets.
- Access requests with evidenceDeadlines, citations and attestation on every request.
- Operated by AttriAttri, which deploys and runs OpenWatch, states it is HIPAA compliant with a BAA available.
Safeguards
Handles sensitive datawith restraint.
Documents by reference
Files are recorded by name, path and size. Their contents stay on the laptop.
Secrets redacted on the device
API keys, private keys, tokens and password values are removed before upload.
Encrypted uploads
Each upload from a laptop is encrypted with AES-256-GCM over HTTPS.
Entra sign-in and roles
People see their own activity. Admins see the organisation.
Append-only evidence
Ticket events and citations are added, never edited.
In your cloud account
Attri deploys and runs OpenWatch inside your own cloud subscription.
Questions from healthcare teams
Does OpenWatch detect PHI automatically?
No. It checks prompts against the PHI rules you write into your AI policy, using Claude. It isn't a trained PHI classifier.
Will Attri sign a BAA?
Attri states on attri.ai that it is HIPAA compliant with a BAA available. Your deployment's compliance also depends on how it's configured and operated in your environment.
Does it capture document contents?
No. Documents are recorded by name, path and size only.
Which Claude apps are covered?
Claude Desktop and Cowork on macOS and Windows, Claude Code sessions run inside Desktop, and claude.ai through Anthropic's Compliance API.
Someone will ask what happened.Have the answer ready.
Run OpenWatch on sample data in minutes, or have Attri deploy it inside your cloud with live data from your organisation.