hipaa-audit

Identify HIPAA compliance gaps in code, data flows, and third-party integrations.

13|3|Updated Mar 27, 2026
One-click install
npx skills add https://github.com/heaptracetechnology/heaptrace-skills --skill hipaa-audit-heaptracetechnology
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: hipaa-audit
Source: https://github.com/heaptracetechnology/heaptrace-skills/tree/main/compliance/hipaa-audit
Command: npx skills add https://github.com/heaptracetechnology/heaptrace-skills --skill hipaa-audit-heaptracetechnology

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

HIPAA compliance requirements are enforced across code, data flows, logs, and third-party integrations. This Skill helps teams identify, document, and remediate PHI exposure risks and ensure alignment with HIPAA Security Rule mappings.

Core Features & Use Cases

  • Audit code, data handling, logs, and third-party integrations for HIPAA compliance, mapping findings to §164.xxx sections.
  • Provide structured templates for risk analysis, BAAs, encryption, access controls, audit trails, breach notification workflows, and incident response plans.
  • Use before handling PHI, during OCR audits, and when evaluating new third-party vendors to ensure ongoing compliance.

Quick Start

Review your codebase and configurations with HIPAA mappings to identify gaps before handling PHI.

Frequently Asked Questions about hipaa-audit

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit my codebase for HIPAA compliance and PHI exposure risks?

To audit code for HIPAA compliance, review data handling, logs, and third-party integrations to identify PHI exposure risks. This process maps findings directly to HIPAA Security Rule sections to ensure encryption, access controls, and audit trails meet regulatory standards.

What is a HIPAA Security Rule code audit and when do I need one?

A HIPAA Security Rule code audit identifies compliance gaps in data flows and system architectures. You need this audit before handling PHI, during OCR audits, or when integrating new third-party vendors to ensure ongoing regulatory alignment.

How do I prepare for an OCR audit regarding my application's PHI handling?

Prepare for an OCR audit by evaluating your codebase and configurations against HIPAA Security Rule mappings. This structured review identifies gaps in encryption, access controls, breach notification workflows, and administrative safeguards before official assessment.

Does my code need Business Associate Agreements and encryption checks for HIPAA compliance?

Yes, HIPAA compliance requires checking code and third-party integrations for valid Business Associate Agreements and encryption standards. Auditing these components ensures PHI protection and aligns with structured administrative, physical, and technical safeguards.

What's the best way to map HIPAA compliance findings to specific regulatory sections?

The best way to map HIPAA findings is through a code-aware workflow that evaluates data flows and integration points, categorizing risks by specific §164.xxx Security Rule sections. This structured approach ensures all administrative and technical safeguards are addressed.

Can I assess third-party vendor integrations for HIPAA compliance gaps?

You can assess third-party vendor integrations for HIPAA compliance by analyzing data flows and API connections for PHI exposure. This audit verifies that vendor systems maintain required encryption, access controls, and audit trails under the Security Rule.