compliance-architect

Design compliance frameworks for regulated applications across HIPAA, GDPR, and SOC 2.

Updated Mar 20, 2026
One-click install
npx skills add https://github.com/Cure-Consulting-Group/iep-and-thrive --skill compliance-architect
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: compliance-architect
Source: https://github.com/Cure-Consulting-Group/iep-and-thrive/tree/main/.agents/skills/compliance-architect
Command: npx skills add https://github.com/Cure-Consulting-Group/iep-and-thrive --skill compliance-architect

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill automates the design and implementation of compliance frameworks for regulated applications, streamlining the process of ensuring compliance with various regulations.

Core Features & Use Cases

  • Compliance Framework Design: Architect compliance architectures for HIPAA, COPPA, GDPR, CCPA, PCI DSS, and SOC 2.
  • Data Classification: Classify data fields into public, internal, confidential, and restricted categories.
  • Consent Management: Implement consent management systems with granular, revocable, and provably recorded consent flows.
  • Audit Trail: Create immutable audit logs for tracking access and changes to confidential and restricted data.
  • Vendor Assessment: Assess and manage vendor compliance with BAA/DPA requirements.
  • Use Case: For a healthcare application, this Skill can design a compliance framework that ensures all patient data is handled in accordance with HIPAA and GDPR regulations.

Quick Start

Use the compliance-architect skill to design a compliance framework for a new healthcare application.

Frequently Asked Questions about compliance-architect

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I design a compliance framework for a regulated healthcare application?

To architect a compliance framework you must classify data fields, implement granular consent management, and create immutable audit trails for access tracking. This ensures patient data handling aligns with HIPAA and GDPR regulatory requirements.

What is the best way to classify application data fields for GDPR and CCPA compliance?

Data classification for GDPR and CCPA compliance categorizes data fields into public, internal, confidential, and restricted tiers. This classification dictates how consent management and audit logging mechanisms apply to sensitive information.

How does consent management work for COPPA and PCI DSS regulated applications?

Consent management for COPPA and PCI DSS implements granular, revocable, and provably recorded consent flows. This ensures user agreements are tracked and managed throughout the data lifecycle within the compliance architecture.

Can I use automated audit trails for tracking access to restricted data?

Automated audit trails create immutable logs for tracking access and changes to confidential and restricted data. These logs are essential for proving compliance during assessments for frameworks like SOC 2 and HIPAA.

Do I need project context and regulatory documentation to architect SOC 2 compliance?

Architecting SOC 2 compliance requires access to project context and relevant regulatory documentation. This input allows the automated design of accurate data classification, audit trails, and vendor assessment workflows.

How do I assess vendor compliance with BAA and DPA requirements?

Assessing vendor compliance with BAA and DPA requirements involves evaluating third-party handling of confidential and restricted data. This ensures external vendors meet HIPAA, GDPR, and CCPA regulatory standards during framework implementation.