Picture a practice manager at a Brisbane allied health group asking the obvious question: if we put an AI agent in Slack, what stops it reading a patient's file? Three healthcare-adjacent companies running Claude Tag in production have given a concrete answer, and it is not a policy document. It is an access-control design.
Claude Tag is Claude working as a teammate inside Slack. Claude published a write-up of these three deployments in September 2026. The detail that frames all three is blunt: Claude Tag is not yet covered by Anthropic's Business Associate Agreement, the US instrument for handling protected health information. So none of these organisations let it near patient data. They designed around that limit rather than waiting for it to change.
Can Claude Tag be used in healthcare without accessing patient data?
Yes, if the deployment is scoped so patient data never enters the channels or connectors Claude Tag can reach. Admins switch it on only in approved channels, disable direct messages, and attach connectors per channel. It sees only what a workspace member sees, cannot read private channels it has not been invited into, and clinical systems are simply never connected to it.
That last point carries most of the weight. The safety comes from what is absent, not from asking the model to be careful. If an electronic health record is never in the access bundle, no prompt can pull a record out of it.
The controls that do the work
Channel allow-listing: Claude Tag runs only where an admin has switched it on, so a clinical team channel can stay off-limits by default
No direct messages: removes the private side door where someone might paste a patient detail to ask a quick question
Workspace-member visibility: it can keyword-search public channels but has no access to private channels unless invited
Access bundles per channel: a codebase and issue tracker can be connected in an engineering channel while EHR, clinical systems and patient communications stay out entirely
Channel scope matters more now that Claude Tag can take in a whole channel's context, a change we covered in our note on Claude Tag reading full channels. The wider the context window, the more important it is that the channel itself is clean. The underlying identity model is set out in our Claude Tag access model explainer.
Three deployments, three different jobs
Insight Health builds referral coordination software used by more than 1,100 specialty practices. It runs Claude Tag in engineering and support channels that carry no patient data, triaging production alerts against the codebase and ticket history. A second, separate agent built on the Claude Agent SDK runs under a BAA-covered API organisation, sees production data, and masks patient details before anything reaches Slack. Since going live, 97% of alerts in their critical channel have closed without an engineer stepping in.
Tennr, a patient orchestration platform, made Claude Tag the primary maintainer of an internal tool built in Claude Code. Recruiting and People-team staff request changes in plain language and see them shipped the same day: more than 15 tickets in a month, including a same-day fix when a security issue was flagged. None of that work involves clinical data.
Medallion handles provider credentialing and payer enrolment. It uses Claude Tag to answer payer-rules questions from historical expert responses in Slack, which broke a knowledge bottleneck that sat with one person. When Claude is not confident, it tags in the right human expert, and that answer becomes the basis for future responses.
The design choice worth noticing in Insight Health's setup is the split. The agent in Slack and the agent that touches production data are two different systems with two different access levels, and only one of them sits under a patient-data agreement.
A scoping matrix for an Australian practice
Here is how we would sort a typical clinic group's Slack or Teams channels before any pilot. The test for each row is simple: could a patient's health information plausibly appear here?
| Channel or system | Patient data likely? | Claude Tag | Human sign-off |
|---|---|---|---|
| IT alerts and engineering | No, if logs are masked | Yes | Engineer merges any fix |
| Internal tools and HR requests | No | Yes | Owner approves changes |
| Billing rules and payer or Medicare item questions | Rarely, keep it rule-level | Yes, rules only | Expert corrects low-confidence answers |
| Rostering and facilities | No | Yes | Manager approves |
| Clinical handover and case discussion | Yes | No | Not applicable |
| Practice management system or EHR | Yes | Never connected | Not applicable |
Every row marked yes also keeps a person in the loop for the part that matters. That mirrors all three case studies: an engineer merges the pull request, an expert corrects the payer-rules answer, and downstream systems check Medallion's outputs.
What the Australian context changes
A BAA is a US arrangement with no direct Australian equivalent. Here, health information is sensitive information under the Privacy Act, and practices also answer to state health records laws and their professional bodies. None of the three case studies establishes that Claude Tag is suitable for identified patient data in Australia, and we would not describe it that way.
What they do establish is a pattern a Sydney or Melbourne practice can adopt today for work that is genuinely patient-free. Most healthcare organisations have far more of that work than they think: IT, rostering, internal tooling, billing rules, onboarding. If a practice pays a loaded $120K a year for a staff member who spends a third of their week answering the same internal questions, a well-scoped channel agent is worth modelling on that work alone. We compared how general assistants handle healthcare admin under the Privacy Act in our Claude vs Gemini healthcare admin guide, and Anthropic's own internal Claude Tag patterns are a useful template for the low-risk channels.
Before you switch it on
Audit which channels already contain patient details, because staff paste things where they should not
Write down the channel allow-list and the access bundle for each channel, and have the privacy officer sign it
Keep direct messages off and review the allow-list quarterly
Decide in advance who answers when the agent hands a question back to a human
If your practice or aged care group wants a governed AI pilot that never touches clinical records, our services page sets out how we scope that work. When you are ready to map your own channels, book a time with us.



