comply-breach

Automate HIPAA breach response with incident intake, four-factor risk assessment, and notification planning.

10|5|Updated Mar 22, 2026
One-click install
npx skills add https://github.com/aanishs/em-dash --skill comply-breach
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: comply-breach
Source: https://github.com/aanishs/em-dash/tree/main/skills/comply-breach
Command: npx skills add https://github.com/aanishs/em-dash --skill comply-breach

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Guided HIPAA breach response workflow helps healthcare teams document incidents, perform formal four-factor risk assessments, determine notification requirements, and produce a compliant notification plan with timelines and templates.

Core Features & Use Cases

  • Structured incident intake prompts to collect essential facts while preserving evidence and timelines.
  • Four-factor risk assessment aligned with 45 CFR 164.402 to determine whether breach notification is required.
  • Generated notification plan with timelines, required content, and state/HHS considerations.

Quick Start

Initiate the breach workflow and answer prompts in sequence to complete the assessment and notification plan.

Frequently Asked Questions about comply-breach

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct a HIPAA breach risk assessment to determine notification requirements?

A HIPAA breach risk assessment evaluates incidents through a four-factor analysis aligned with 45 CFR 164.402 to determine whether breach notification is legally required. This workflow guides teams through structured incident intake prompts to collect essential facts while preserving evidence and timelines.

What is a HIPAA breach notification plan and how is it generated?

A HIPAA breach notification plan outlines required timelines, content, and state and HHS considerations for disclosing incidents. It is generated automatically after completing a guided risk assessment, ensuring the 60-day notification clock is properly tracked.

How do I document a HIPAA incident response to maintain an auditable compliance process?

Documenting a HIPAA incident response involves using structured intake prompts, templates, and logging to capture essential facts and timelines. This workflow enforces an auditable process across varied healthcare settings while avoiding storage of actual protected health information.

Can I use this breach response workflow for incidents across different healthcare settings?

This breach response workflow applies to incidents across varied healthcare settings, adapting to different operational contexts. It structures the incident intake, risk assessment, and notification planning to ensure federal and state requirements are consistently considered.

Does this HIPAA breach notification tool store protected health information during incident intake?

This HIPAA breach notification tool avoids storage of actual protected health information during incident intake. It focuses on structuring the response workflow, risk assessment, and notification planning while adhering to legal disclaimers and maintaining data privacy.

What is the four-factor risk assessment for HIPAA breach determination?

The four-factor risk assessment for HIPAA breach determination evaluates the nature of protected health information, the unauthorized recipient, whether information was acquired or viewed, and mitigation efforts. This structured analysis determines if breach notification is required.