hipaa-compliance

Explain HIPAA Privacy, Security, and Breach Notification Rules for PHI handling.

1|1|Updated May 16, 2026
One-click install
npx skills add https://github.com/aks-builds/healthcareskills --skill hipaa-compliance-aks-builds
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: hipaa-compliance
Source: https://github.com/aks-builds/healthcareskills/tree/main/skills/hipaa-compliance
Command: npx skills add https://github.com/aks-builds/healthcareskills --skill hipaa-compliance-aks-builds

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides accurate and detailed guidance on applying the U.S. Health Insurance Portability and Accountability Act (HIPAA) Privacy, Security, and Breach Notification Rules, supporting engineering, product, security, and compliance teams in making defensible decisions about Protected Health Information (PHI).

Core Features & Use Cases

  • HIPAA Rule Explanation: Detailed explanations of HIPAA's Privacy Rule, Security Rule, and Breach Notification Rule.
  • Initial Assessment: Provides an initial assessment based on the user's HIPAA role and jurisdiction.
  • Common Scenarios: Offers guidance on common scenarios like new SaaS for PHI processing, marketing to patients, handling vendor incidents, and research requests.

Quick Start

Use the hipaa-compliance skill to assess a potential breach of PHI involving a patient's email to an external address.

Frequently Asked Questions about hipaa-compliance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is HIPAA compliance and how do the Privacy and Security Rules affect engineering decisions?

HIPAA compliance requires adhering to the Privacy Rule, Security Rule, and Breach Notification Rule when handling Protected Health Information (PHI). Engineering teams must implement these regulations to make defensible decisions about healthcare technology design and data processing.

How do I assess a potential PHI breach involving an external email address?

To assess a potential PHI breach, use initial assessment tools based on your HIPAA role and jurisdiction. Evaluate the incident against the Breach Notification Rule to determine if Protected Health Information was compromised and what notification steps are legally required.

Do I need a Business Associate Agreement (BAA) when building a new SaaS app that processes PHI?

Yes, you need a Business Associate Agreement (BAA) when building a new SaaS app that processes PHI. HIPAA requires BAAs between covered entities and their vendors to ensure all parties apply adequate Privacy Rule and Security Rule protections to health data.

Can I use this HIPAA guidance for marketing to patients and handling vendor incidents?

Yes, this HIPAA guidance covers common scenarios like marketing to patients and handling vendor incidents. It provides actionable direction for engineering, product, and security teams to ensure patient outreach and third-party incident responses comply with PHI regulations.

What are the limitations of using HIPAA compliance guidance for healthcare research requests?

HIPAA compliance guidance for healthcare research requests is limited to U.S. regulations like the Privacy Rule and Security Rule. It does not replace formal legal counsel and may not cover international health data privacy laws or specialized institutional review board requirements.

What's the best way to ensure my healthcare engineering project meets HIPAA Security Rule requirements?

The best way to ensure your healthcare engineering project meets HIPAA Security Rule requirements is to evaluate your system design against established regulations for PHI protection. Engineering teams should reference detailed compliance guidance to implement defensible security safeguards for health data.