What problem does it solve?
This Skill identifies missing HIPAA Privacy and Security Rule safeguards before a clinical data pipeline processes protected health information, helping teams document risks, remediation steps, and deployment readiness without treating the assessment as legal advice.
Core Features & Use Cases
- Administrative, Physical, and Technical Review: Evaluate risk analysis, workforce controls, facility safeguards, access management, encryption, audit controls, integrity, and transmission security against 45 CFR Part 164.
- De-identification Assessment: Compare Safe Harbor and Expert Determination approaches, verify minimum-necessary handling, and identify residual risks from identifiers, logs, caches, and temporary files.
- Evidence and Gap Reporting: Connect OpenMed on-device de-identification and signed audit reports to relevant controls, record unmet requirements, and assign remediation ownership.
- Use Case: Before deploying an OpenMed pipeline on clinical notes, use this Skill to map PHI flows, check BAA obligations, assess Safe Harbor coverage, and produce a go/no-go report for the Privacy or Security Officer.
Quick Start
Use the HIPAA compliance skill to review my clinical text pipeline, identify unmet safeguards, assess its de-identification method, and produce a cited remediation gap report.