checking-hipaa-compliance

Evaluate clinical data pipelines for HIPAA safeguards and de-identification readiness.

5.0k|615|Updated Oct 4, 2025
One-click install
npx skills add https://github.com/maziyarpanahi/openmed --skill checking-hipaa-compliance
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: checking-hipaa-compliance
Source: https://github.com/maziyarpanahi/openmed/tree/main/skills/checking-hipaa-compliance
Command: npx skills add https://github.com/maziyarpanahi/openmed --skill checking-hipaa-compliance

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill identifies missing HIPAA Privacy and Security Rule safeguards before a clinical data pipeline processes protected health information, helping teams document risks, remediation steps, and deployment readiness without treating the assessment as legal advice.

Core Features & Use Cases

  • Administrative, Physical, and Technical Review: Evaluate risk analysis, workforce controls, facility safeguards, access management, encryption, audit controls, integrity, and transmission security against 45 CFR Part 164.
  • De-identification Assessment: Compare Safe Harbor and Expert Determination approaches, verify minimum-necessary handling, and identify residual risks from identifiers, logs, caches, and temporary files.
  • Evidence and Gap Reporting: Connect OpenMed on-device de-identification and signed audit reports to relevant controls, record unmet requirements, and assign remediation ownership.
  • Use Case: Before deploying an OpenMed pipeline on clinical notes, use this Skill to map PHI flows, check BAA obligations, assess Safe Harbor coverage, and produce a go/no-go report for the Privacy or Security Officer.

Quick Start

Use the HIPAA compliance skill to review my clinical text pipeline, identify unmet safeguards, assess its de-identification method, and produce a cited remediation gap report.

Frequently Asked Questions about checking-hipaa-compliance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I assess a clinical data pipeline for HIPAA compliance before processing PHI?

Assess clinical data pipelines for HIPAA compliance by conducting a control-by-control review of administrative, physical, technical, and Privacy Rule safeguards with 45 CFR citations, producing a documented remediation gap report.

What is the difference between Safe Harbor and Expert Determination de-identification under HIPAA?

Safe Harbor de-identification removes 18 specific identifiers, while Expert Determination uses statistical analysis to verify re-identification risk is minimal. This skill compares both approaches to verify minimum-necessary handling and identify residual risks.

How do I check if my BAA scoping meets HIPAA Security Rule requirements?

Check BAA scoping against HIPAA Security Rule requirements by evaluating access management, encryption, audit controls, integrity, and transmission security safeguards against 45 CFR Part 164 to document unmet requirements and assign remediation ownership.

Can I use this HIPAA compliance audit for OpenMed on-device de-identification workflows?

Yes, you can use this assessment for OpenMed on-device de-identification workflows. It connects signed audit reports to relevant controls and produces a go/no-go report for the Privacy or Security Officer before PHI deployment.

What are the limitations of treating an automated HIPAA compliance gap assessment as legal advice?

An automated HIPAA compliance gap assessment is explicitly not legal advice. It functions as a risk analysis tool to document missing safeguards, remediation steps, and deployment readiness, but requires legal review for official compliance validation.