hipaa-compliance

Assess HIPAA applicability and PHI handling gaps in healthcare products.

22|2|Updated Mar 24, 2026
One-click install
npx skills add https://github.com/jshsakura/awesome-opencode-skills --skill hipaa-compliance-jshsakura
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: hipaa-compliance
Source: https://github.com/jshsakura/awesome-opencode-skills/tree/main/skills/hipaa-compliance
Command: npx skills add https://github.com/jshsakura/awesome-opencode-skills --skill hipaa-compliance-jshsakura

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

HIPAA compliance reviews for healthcare products are complex and error-prone; this Skill helps teams identify when HIPAA applies, what PHI flows exist, and what BAA requirements and safeguards are needed to reduce risk and accelerate customer onboarding.

Core Features & Use Cases

  • HIPAA applicability assessment: determine whether data flows involve Covered Entity, Business Associate, or neither.
  • PHI path mapping: identify where PHI is collected, transmitted, stored, processed, retained, and de-identified.
  • Safeguards and breach readiness: evaluate administrative, physical, and technical safeguards and breach notification preparation.
  • BAA lifecycle and vendor inventory: verify BAA obligations and track processors touching PHI.

Quick Start

Provide your data-flow description and PHI handling details to generate a HIPAA risk assessment outline.

Frequently Asked Questions about hipaa-compliance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I assess HIPAA applicability for a healthcare SaaS product?

To assess HIPAA applicability, determine whether your data flows involve a Covered Entity, Business Associate, or neither. This evaluation identifies specific PHI handling gaps and BAA requirements to reduce compliance risk.

What is PHI path mapping and when do I need it for cloud platforms?

PHI path mapping identifies where Protected Health Information is collected, transmitted, stored, processed, retained, and de-identified. You need it when cloud platforms process healthcare data to ensure proper safeguards are implemented.

Do I need a BAA for vendors processing PHI in my healthcare product?

You need a BAA for vendors acting as Business Associates that process PHI. BAA lifecycle management verifies vendor obligations and tracks all processors touching PHI to maintain breach readiness and compliance.

How do I evaluate administrative, physical, and technical safeguards for HIPAA compliance?

Evaluating HIPAA safeguards involves analyzing administrative, physical, and technical controls across your healthcare product. This assessment identifies gaps in breach notification preparation and specifies requirements for HITRUST considerations when relevant.

What are the breach notification timeline requirements for healthcare products handling PHI?

Breach notification timeline requirements dictate specific deadlines for reporting PHI breaches in healthcare products. Assessing breach readiness verifies your product meets these timelines and implements necessary administrative, physical, and technical safeguards.

Can I use this HIPAA risk analysis for customer onboarding acceleration?

You can use HIPAA risk analysis to accelerate customer onboarding by proactively identifying compliance gaps, verifying BAA obligations, and mapping PHI data flows to reduce risk and streamline healthcare product readiness.