hipaa-compliance-guard

Audits HIPAA technical safeguards in healthcare infrastructure configurations across AWS, GCP, or Azure.

1|Updated Jan 28, 2026
One-click install
npx skills add https://github.com/Benmore-Studio/Benmore-Meridian --skill hipaa-compliance-guard-benmore-studio
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: hipaa-compliance-guard
Source: https://github.com/Benmore-Studio/Benmore-Meridian/tree/main/skills/hipaa-compliance-guard
Command: npx skills add https://github.com/Benmore-Studio/Benmore-Meridian --skill hipaa-compliance-guard-benmore-studio

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

HealthTech teams need a structured audit of HIPAA safeguards across configurations to ensure encryption and logging meet security standards.

Core Features & Use Cases

  • Terraform/CloudFormation configuration scanning for HIPAA controls.
  • PHI handling checks that do not inspect PHI data, ensuring privacy.
  • Audit logging presence verification and actionable findings for infrastructure reviews.
  • Use Case: During architecture reviews, run the guard to confirm encryption in transit at load balancers and S3 bucket encryption, plus logging.

Quick Start

Provide the project_root and cloud_provider to start the HIPAA compliance audit and receive a structured score and findings.

Frequently Asked Questions about hipaa-compliance-guard

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit my cloud infrastructure for HIPAA technical safeguards?

Auditing HIPAA safeguards involves scanning infrastructure configurations to identify gaps in encryption, logging, and access controls. This Skill assesses Terraform and CloudFormation templates across AWS, GCP, or Azure to verify encryption and audit logging presence.

Does this HIPAA compliance audit inspect actual patient health data?

No, this HIPAA compliance audit does not inspect PHI data. It evaluates infrastructure configuration patterns for encryption and logging presence to ensure privacy while reviewing cloud environments like AWS, GCP, or Azure.

Can I use this to check Terraform configurations for HIPAA encryption requirements?

Yes, you can use this to check Terraform configurations for HIPAA encryption requirements. It scans infrastructure as code to verify encryption in transit at load balancers and S3 bucket encryption at rest.

What is needed to start a pre-audit self-assessment for healthcare infrastructure?

To start a pre-audit self-assessment for healthcare infrastructure, you need to provide your project root directory and cloud provider. The audit then returns a structured compliance score and actionable findings.

What limitations exist when scanning cloud infrastructure for ePHI safeguards?

A key limitation is that it assesses configuration patterns without inspecting actual ePHI data. It focuses strictly on verifying encryption and audit logging presence within AWS, GCP, or Azure infrastructure configurations.