零数据保留的真实真相:AI 编码工具在 HIPAA 合规世界中实际承诺了什么
The Real Truth About Zero Data Retention: What AI Coding Tools Actually Promise in a HIPAA-Compliant World
Anand Chandrasekaran, Arya Health 人工智能主管/首席工程师你团队中的一名开发人员正在调试一个调度算法。他们将一个引用患者医疗补助资格窗口的函数粘贴到 AI 编码工具中。这些数据是否被保留?是否被记录?是否用于训练?对于大多数工程负责人来说,诚实的答案是:他们不知道。
这种知识差距是有代价的。IBM 的《数据泄露成本报告》发现,63% 的组织缺乏正式的 AI 治理政策,而随着 AI 工具嵌入日常开发工作流程,风险只会越来越大。
你遇到最多的术语是“零数据保留”(ZDR),虽然它确实很重要,但被广泛误解。在深入审查了 Claude Code、OpenAI Codex 和 Google Vertex AI 实际如何处理数据之后,以下是 ZDR 在实践中的含义、每个工具的不足之处,以及医疗技术团队和工程师现在需要做什么。
ZDR 实际上意味着什么(以及它不意味着什么)
零数据保留听起来不言自明:发送提示,获得响应,不存储任何内容。现实情况更加微妙。真正的 ZDR 意味着提供商实时处理你的数据并立即丢弃:不记录提示、不保留输出、不用于训练。主要提供商实际提供的是合同性 ZDR,仅适用于专门谈判获得的企业客户,并且有重要的例外条款。
每个主要提供商都出于安全监控义务至少保留一段时间的部分数据。即使根据 ZDR 协议,如果某个会话被标记为违反服务条款,输入和输出可被保留长达两年。ZDR 并不是对每个请求都绝对保证临时性。更重要的是,ZDR 和 HIPAA 合规是相关但不同的义务。你可以拥有其中之一而没有另一个,两者都不是自动的。
Claude Code:医疗团队需要了解的细微差别
Claude Code 是目前最强大的代理式编码工具之一,但其 HIPAA 相关情况带来的复杂性需要团队在部署前理解。Anthropic 的 ZDR 产品是真实的,但它明确与 Anthropic API 绑定,需要通过直接商业合同获得。
Claude Code 捆绑席位目前不包括在 Anthropic 的 HIPAA 就绪产品中。如果你希望 Claude Code 的使用覆盖 HIPAA 相关服务,必须直接联系 Anthropic 的客户团队。这不是标准的自助路径。
在医疗场景中还有额外的例外情况。通过 Files API 上传的文件在被明确删除前会一直被保留,无论是否有 ZDR 协议,这在上传实验室报告或护理计划时是一个重大风险。如果启用了用于成本跟踪的指标记录,该数据明确豁免于 ZDR,并可能被保留。关键是,ZDR 不适用于通过 AWS Bedrock 或 Google Vertex AI 访问的 Claude。这些平台通过架构隔离和云 BAA 提供自己的数据保护,这是一条合法的 HIPAA 合规路径,但有所不同。
OpenAI Codex:企业 ZDR 存在,但请阅读细则
OpenAI 为企业 API 客户提供了可靠的 ZDR 方案,Codex 支持在 ChatGPT Enterprise 层级启用 ZDR 的组织。但标准 API 端点会将输入和输出保留最多 30 天以进行滥用监控,并且 ZDR 不是自助服务。企业客户必须专门请求并获得批准。
云与本地之间的区别至关重要:Codex 云(任务在 OpenAI 托管的容器中运行)与 ZDR 不兼容。ZDR 实际上仅适用于 ZDR 批准组织内的本地 Codex CLI 和 IDE 扩展。如果你的团队将工作委派给 Codex 云代理,即使是在启用 ZDR 的组织中,该流量也不受 ZDR 保护。
医疗保健组织面临的最大风险:面向消费者的 ChatGPT 产品,包括 Free、Plus、Pro 和 Team 层级,在任何情况下都不符合 HIPAA 资格。开发人员在医疗代码库上使用个人 ChatGPT 账户,是在任何业务伙伴协议(BAA)或 ZDR 保护之外操作的,没有任何合同保障。研究表明,38% 的员工曾将机密公司数据分享给未经批准的 AI 工具,通常是通过个人或未经批准的账户。
Vertex AI:结构性隐私,而非合同性隐私
Google Vertex AI 采取了根本不同的方法。Google 并非将 ZDR 作为合同附加条款,而是将 AI/ML 隐私承诺内置于平台中:未经事先许可,Google 不会使用你的数据来训练或微调模型。这适用于 Vertex 上的所有托管模型,包括通过 Model Garden 访问的 Claude。Vertex 支持 HIPAA 工作负载,Google 的 BAA 涵盖 Vertex。HIPAA 支持不像其他提供商那样是特殊的附加层级。
一个值得注意的细节:默认情况下,已发布的 Gemini 模型会将客户数据缓存在内存中以减少延迟,并设有 24 小时生存时间(TTL),这意味着数据会自动删除或过期。这种缓存可以在项目级别禁用,但你需要知道如何操作。
ZDR 在代理工作流中失灵的地方
医疗保健组织已经在积极进入生产部署。McKinsey 研究显示,大约 50% 的美国医疗保健组织已经在使用生成式 AI,超过 80% 已向最终用户部署了至少一个用例。这种规模的采用意味着以下失败模式不是边缘情况;它们正在生产中发生。
对于构建处理护理协调、资格工作流或接收管道的生产代理的团队,在 Claude API 上构建代理的核心是符合 ZDR 的。Messages API 实时处理数据,响应后不存储。但几种常见模式会悄然破坏 ZDR 状态。
代码执行沙箱会将容器数据保留最多 30 天,并且不符合 ZDR 资格。Batch API 通常用于夜间资格重新计算或批量索赔处理,明确不符合 ZDR 资格,标准保留政策为 29 天。Beta 功能被明确排除在 ZDR 安排之外,除非另有明确说明。
架构含义:将所有涉及 PHI 的推理路由通过 Messages API,避免对受监管数据使用 Batch API,并将任何 Beta 功能默认视为非 ZDR。
医疗技术团队现在应该做什么
上述复杂性不是避免使用这些工具的理由,而是有意识地实施它们的理由。在实践中如下:
审计你的开发团队正在使用的每个 AI 工具。
假设如果它没有被你的 BAA 明确覆盖,那么对于涉及 PHI 或 PHI 相关代码的工作来说,它就不是 HIPAA 安全的。●理解 ZDR 是一种合同关系,而不是产品功能。
你需要签署协议、合适的组织层级以及明确的自主选择。
了解每个路由路径的合规状态。
通过 Bedrock 或 Vertex 进行云托管推理给你带来与直接连接到模型提供商不同的合规状态,不一定更好或更差。了解你拥有什么,并记录在案。
实施不依赖记忆的技术控制。
拒绝规则、代码审查门禁、网络隔离;这些是在截止日期压力下仍然有效的控制措施。●保持最新。
Anthropic 在 2025 年末大幅更新了其消费者数据保留政策。OpenAI 一直在迭代 ZDR 文档。Google Vertex 扩展了 HIPAA 覆盖范围。六个月前的合规假设可能已经过时。
医疗保健行业继续面临所有行业中最昂贵的数据泄露,根据 IBM 的数据,平均每次事件损失 742 万美元。ZDR 是真实的,对医疗保健组织来说非常重要。但它不是自动的,不是普遍的,也不等同于 HIPAA 合规。将隐私架构放在首位,强大的 AI 工具自然会随之而来。
Anand Chandrasekaran, AI Chief/Principal Engineer at Arya Health
A developer on your team is debugging a scheduling algorithm. They paste a function into an AI coding tool that references a patient’s Medicaid eligibility window. Did that data just get retained? Logged? Used for training? For most engineering leaders, the honest answer is: they don’t know.
That knowledge gap has a cost. IBM’s Cost of a Data Breach Report found that 63% of organizations lack formal AI governance policies, and as AI tooling becomes embedded in everyday development workflows, the exposure only grows.
The term you’ll encounter most is “Zero Data Retention” (ZDR), and while it’s genuinely important, it’s widely misunderstood. After a deep review of how Claude Code, OpenAI Codex, and Google Vertex AI actually handle data, here’s what ZDR means in practice, where each tool falls short, and what healthcare technology teams and engineers need to do now.
What ZDR Actually Means (And What It Doesn’t)
Zero Data Retention sounds self-explanatory: send a prompt, get a response, nothing is stored. The reality is more nuanced. True ZDR means the provider processes your data in real time and immediately discards it: no prompt logging, no retained outputs, no training use. What major providers actually offer is contractual ZDR, available only to enterprise customers who specifically negotiate for it, with important carve-outs.
Every major provider retains data for at least some period under safety monitoring obligations. Even under ZDR agreements, if a session is flagged for a Terms of Service violation, inputs and outputs can be held for up to two years. ZDR is not an absolute guarantee of ephemerality for every request. More critically, ZDR and HIPAA compliance are related but distinct obligations. You can have one without the other, and neither is automatic.
Claude Code: The Nuances Healthcare Teams Need
Claude Code is among the most powerful agentic coding tools currently available, but its HIPAA story comes with complexity that teams need to understand before deployment. Anthropic’s ZDR offering is real, but it is explicitly tied to the Anthropic API via direct commercial contract.
Claude Code bundled seats are not currently covered as part of Anthropic’s HIPAA-ready offering. If you want Claude Code usage covered for HIPAA-related services, you must contact Anthropic’s account team directly. It’s not a standard, self-serve path.
There are additional exceptions that matter in healthcare contexts. Files uploaded via the Files API are retained until explicitly deleted, regardless of any ZDR agreement, which is a meaningful risk when uploading lab reports or care plans. If metrics logging is enabled for cost tracking, that data is explicitly exempted from ZDR and may be retained. And critically, ZDR does not apply to Claude accessed through AWS Bedrock or Google Vertex AI. Those platforms offer their own data protections through architectural isolation and cloud BAAs, which is a legitimate HIPAA compliance path, but a different one.
OpenAI Codex: Enterprise ZDR Exists, But Read the Fine Print
OpenAI has a solid ZDR story for enterprise API customers, and Codex supports organizations with ZDR enabled at the ChatGPT Enterprise tier. But standard API endpoints retain inputs and outputs for up to 30 days for abuse monitoring, and ZDR is not self-serve. Enterprise customers must specifically request and receive approval.
The cloud versus local distinction is critical: Codex cloud, where tasks run in OpenAI-hosted containers, is incompatible with ZDR. ZDR effectively only applies to the local Codex CLI and IDE extension within ZDR-approved organizations. If your team delegates work to Codex cloud agents, that traffic is not ZDR-protected even in a ZDR-enabled org.
The biggest risk for healthcare organizations: consumer-facing ChatGPT products, including Free, Plus, Pro, and Team tiers, are not HIPAA-eligible under any circumstances. Developers using personal ChatGPT accounts on healthcare codebases are operating outside any Business Associate Agreement (BAA) or ZDR protection, with no contractual safeguard of any kind. Research shows that 38% of employees have shared confidential company data with unapproved AI tools, often through personal or unsanctioned accounts.
Vertex AI: Structural Privacy, Not Contractual
Google Vertex AI takes a fundamentally different approach. Rather than leading with ZDR as a contractual add-on, Google’s AI/ML Privacy Commitment is built into the platform: Google won’t use your data to train or fine-tune models without prior permission. This applies to all managed models on Vertex, including Claude accessed through Model Garden. Vertex supports HIPAA workloads, and Google’s BAA covers Vertex. HIPAA support is not a special add-on tier in the same way it is with other providers.
One nuance worth noting: by default, published Gemini models cache customer data in-memory to reduce latency, with a 24-hour Time to Live, meaning before the data automatically deletes or expires. This caching can be disabled at the project level, but you have to know how to do it.
Where ZDR Breaks Down in Agent Workflows
Healthcare organizations are already moving aggressively into production deployment. McKinsey research shows that roughly 50% of U.S. healthcare organizations are already using generative AI, and more than 80% have deployed at least one use case to end users. That scale of adoption means the following failure modes aren’t edge cases; they’re happening in production.
For teams building production agents that handle care coordination, eligibility workflows, or intake pipelines, the core of agent-building on Claude’s API is ZDR-eligible. The Messages API processes data in real time with no storage after response. But several common patterns silently break ZDR posture.
Code execution sandboxes retain container data for up to 30 days and are not ZDR-eligible. The Batch API, commonly used for nightly eligibility recalculations or bulk claim processing, is explicitly not ZDR-eligible, with a standard 29-day retention policy. Beta features are categorically excluded from ZDR arrangements until explicitly documented otherwise.
The architectural implication: route all PHI-adjacent inference through the Messages API, avoid the Batch API for regulated data, and treat any beta feature as non-ZDR by default.
What Healthcare Technology Teams Should Do Now
The complexity above isn’t a reason to avoid these tools. It’s a reason to implement them deliberately. Here’s what that looks like in practice:
Audit every AI tool your development team is using.
Assume that if it’s not explicitly covered by your BAA, it’s not HIPAA-safe for work that touches PHI or PHI-adjacent code. ● Understand that ZDR is a contractual relationship, not a product feature.
You need a signed agreement, the right organizational tier, and explicit opt-in.
Know your compliance posture for each routing path.
Cloud-managed inference through Bedrock or Vertex gives you a different compliance posture than going direct to model providers, not necessarily better or worse. Understand what you have, and document it.
Implement technical controls that don’t depend on memory.
Deny rules, code review gates, network isolation; these are the controls that hold under deadline pressure. ● Stay current.
Anthropic updated its consumer data retention policies significantly in late 2025. OpenAI has been iterating on ZDR documentation. Google Vertex has expanded HIPAA coverage. The compliance assumptions from six months ago may already be outdated.
Healthcare continues to face the costliest data breaches of any industry, averaging $7.42 million per incident according to IBM. ZDR is real, and for healthcare organizations, it matters enormously. But it is not automatic, not universal, and not the same as HIPAA compliance. Put privacy architecture first, and the powerful AI tooling follows naturally.
Anand Chandrasekaran
is the AI Chief/Principal Engineer at Arya Health, a healthcare staffing platform serving home health agencies across the United States. Arya Health builds AI-powered systems for clinician recruitment, scheduling, and EMR integration.
Reader Interactions