hipaa-compliance

Enforce HIPAA privacy and security requirements for US healthcare systems handling PHI.

Updated Mar 26, 2026
One-click install
npx skills add https://github.com/luongldptit/move-ticket --skill hipaa-compliance-luongldptit
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: hipaa-compliance
Source: https://github.com/luongldptit/move-ticket/tree/main/.agent/skills/hipaa-compliance
Command: npx skills add https://github.com/luongldptit/move-ticket --skill hipaa-compliance-luongldptit

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill eliminates the risk of costly HIPAA violations and data breaches for teams building, reviewing, or operating US healthcare systems that handle protected health information (PHI), by providing clear, actionable compliance guardrails and workflow guidance.

Core Features & Use Cases

  • HIPAA Decision Gating: Built-in checks to confirm if data qualifies as PHI, if actors are covered entities or business associates, and if BAAs are required for third-party vendors before they touch PHI.
  • Compliance Workflow Coordination: Directs users to the correct supporting skills for PHI handling, clinical workflow review, and security hardening to cover all compliance requirements.
  • Use Case: A team building a clinician dashboard that stores patient visit notes can use this skill to verify all PHI access is audited, third-party AI summarization tools have active BAAs in place, and minimum necessary access rules are enforced for all users.

Quick Start

Use the hipaa-compliance skill to review our new patient messaging feature for HIPAA alignment before it launches to US clinics.

Frequently Asked Questions about hipaa-compliance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I check if my healthcare data qualifies as PHI under HIPAA?

To check if healthcare data qualifies as PHI, use HIPAA decision gating to verify if the data contains identifiable patient health information handled by covered entities or business associates. This confirms whether HIPAA privacy and security requirements apply to your workflow.

When do I need a BAA for third-party vendors handling PHI?

You need a BAA for third-party vendors when business associates touch PHI in your healthcare system. HIPAA compliance validation requires confirming active BAAs are in place before third-party tools process protected health information.

How do I enforce minimum necessary access rules for clinician-facing tools?

To enforce minimum necessary access rules for clinician-facing tools, apply HIPAA compliance checks to verify PHI access is audited and restricted. This ensures users only access protected health information essential for their role.

Can I use this for patient-facing healthcare tools operating in the US?

Yes, you can use HIPAA compliance checks for patient-facing healthcare tools operating in the US. It validates PHI exposure prevention and compliance requirements for regulated healthcare products handling protected health information.

What is the best way to design audit trails for regulated healthcare products?

The best way to design audit trails for regulated healthcare products is to apply HIPAA security requirements that verify all PHI access is logged. This ensures compliance validation and supports PHI exposure prevention.

Why does my third-party AI summarization tool need a BAA before processing patient visit notes?

Your third-party AI summarization tool needs a BAA because it functions as a business associate touching PHI. HIPAA requires active BAAs for third-party vendors to ensure PHI handling compliance before processing patient visit notes.