data-access-governance

Implement HIPAA role-based access controls, minimum necessary standards, and audit logging for PHI.

1|1|Updated Feb 19, 2026
One-click install
npx skills add https://github.com/GoldenZero/skills --skill data-access-governance-goldenzero
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: data-access-governance
Source: https://github.com/GoldenZero/skills/tree/main/skills/data-access-governance
Command: npx skills add https://github.com/GoldenZero/skills --skill data-access-governance-goldenzero

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) and assets (resource) components.

What problem does it solve?

This Skill helps organizations establish and enforce robust data access governance for protected health information (PHI), ensuring compliance with HIPAA regulations and preventing unauthorized access.

Core Features & Use Cases

  • Role-Based Access Control (RBAC): Defines granular access permissions based on job roles.
  • Minimum Necessary Standards: Enforces access only to the minimum PHI required for a specific task.
  • Audit Logging & Monitoring: Tracks all access to PHI and detects suspicious activity.
  • Use Case: A hospital needs to review its access control policies for its Electronic Health Record (EHR) system to ensure compliance with HIPAA. This Skill can analyze the existing framework, identify gaps, and recommend improvements for RBAC, minimum necessary implementation, and audit logging.

Quick Start

Analyze my current data access governance framework for HIPAA compliance gaps and suggest remediation steps.

Frequently Asked Questions about data-access-governance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I implement role-based access control for PHI to meet HIPAA compliance?

Role-based access control for PHI is implemented by defining granular access permissions based on job roles, enforcing minimum necessary standards, and tracking all access through audit logging to ensure HIPAA compliance.

What is the minimum necessary standard for protected health information access?

The minimum necessary standard for PHI access requires enforcing access controls so workforce members only access the specific protected health information required to complete a specific task.

How do I audit my existing EHR system for HIPAA data access governance gaps?

Auditing HIPAA data access governance involves analyzing your existing access control framework, role definitions, and access logs to identify RBAC and minimum necessary implementation gaps and recommend remediation steps.

What data do I need to investigate unauthorized access to protected health information?

Investigating unauthorized access to protected health information requires structured inventory, workforce rosters, access logs, role definitions, incident data, and regulatory requirements for comprehensive analysis.

Can this analyze my current data access governance framework for OCR compliance?

Yes, it operationalizes HIPAA data access governance by analyzing your current framework, identifying compliance gaps, and recommending improvements for RBAC, minimum necessary standards, and audit logging to ensure OCR compliance.