domain-healthcare:hipaa-compliance

Implement HIPAA compliance safeguards and breach notification procedures for healthcare systems.

14|3|Updated Feb 22, 2026
One-click install
npx skills add https://github.com/rnavarych/alpha-engineer --skill domain-healthcare-hipaa-compliance
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: domain-healthcare:hipaa-compliance
Source: https://github.com/rnavarych/alpha-engineer/tree/main/plugins/domains/domain-healthcare/skills/hipaa-compliance
Command: npx skills add https://github.com/rnavarych/alpha-engineer --skill domain-healthcare-hipaa-compliance

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill provides comprehensive guidance and implementation details for meeting HIPAA compliance requirements, ensuring the secure and lawful handling of Protected Health Information (PHI).

Core Features & Use Cases

  • Technical Safeguards: Details encryption standards (AES-256-GCM, TLS 1.3), access controls, and audit logging for PHI.
  • Administrative & Physical Safeguards: Outlines security officer roles, workforce training, incident response, and physical security measures.
  • BAA, Risk Assessment & Breach Notification: Provides checklists for vendor agreements, a methodology for risk analysis, and procedures for breach reporting.
  • Use Case: When designing a new patient portal or auditing an existing healthcare system, use this Skill to ensure all technical, administrative, and physical safeguards align with HIPAA regulations.

Quick Start

Use the domain-healthcare:hipaa-compliance skill to review the technical safeguards for encrypting PHI at rest and in transit.

Frequently Asked Questions about domain-healthcare:hipaa-compliance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What technical safeguards are required for encrypting PHI at rest and in transit?

HIPAA compliance for PHI requires AES-256-GCM encryption at rest and TLS 1.3 for data in transit. Additional technical safeguards include strict access controls and comprehensive audit logging to track all access to protected health information.

How do I conduct a HIPAA risk assessment for a healthcare application?

To conduct a HIPAA risk assessment, use a structured methodology to identify vulnerabilities in your healthcare system's technical, administrative, and physical safeguards. This process evaluates risks to PHI and satisfies regulatory compliance requirements for data security.

Do I need a Business Associate Agreement when my healthcare system uses third-party vendors?

Yes, you need a Business Associate Agreement (BAA) for third-party vendors handling PHI. This Skill provides BAA checklists to ensure vendor agreements meet HIPAA compliance requirements, covering security obligations and breach notification procedures.

What are the HIPAA breach notification procedures for compromised protected health information?

HIPAA breach notification procedures require specific reporting protocols when PHI is compromised. This Skill outlines the necessary administrative steps and incident response workflows to report breaches, ensuring regulatory compliance and proper risk mitigation.

Can I use this guidance to audit an existing patient portal for administrative and physical safeguards?

Yes, you can use this HIPAA compliance guidance to audit existing healthcare systems like patient portals. It outlines required administrative safeguards, such as security officer roles and workforce training, alongside physical security measures for PHI.

What is the best way to implement access controls and audit logging for PHI?

Implementing access controls and audit logging for PHI involves deploying technical safeguards that restrict unauthorized access and record all system interactions. This ensures HIPAA compliance by maintaining detailed audit trails and securing healthcare data.