What problem does it solve?
It helps you assess whether applications and infrastructure that create, receive, maintain, or transmit ePHI follow HIPAA requirements, with engineering-focused evidence for administrative, technical, and privacy controls.
Core Features & Use Cases
- HIPAA Security Rule safeguards coverage: Administrative, Physical, and Technical safeguard review with a strong focus on access control, audit controls, integrity, authentication, and transmission security.
- Privacy Rule minimum-necessary and permitted use checks: Validates scope reduction patterns like avoiding over-broad PHI queries and ensuring API/analytics only return necessary fields.
- Breach Notification readiness: Uses audit logging and scoping to support breach timing expectations and encryption “safe harbor” evaluation.
- HIPAA identifiers and PHI scoping guidance: Uses the 18 HIPAA identifiers to determine what data is in scope and flags common minimization and de-identification misunderstandings.
Quick Start
Use the hipaa-audit skill to review how your system accesses, logs, stores, and transmits PHI, then generate a structured HIPAA audit findings checklist with prioritized engineering remediation.