hipaa-compliance

Enforces HIPAA privacy and security controls for PHI handling in healthcare software.

Updated Apr 13, 2026
One-click install
npx skills add https://github.com/sakamoto-family-smile/agent_monorepo --skill hipaa-compliance-sakamoto-family-smile
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: hipaa-compliance
Source: https://github.com/sakamoto-family-smile/agent_monorepo/tree/main/.claude/skills/ecc/hipaa-compliance
Command: npx skills add https://github.com/sakamoto-family-smile/agent_monorepo --skill hipaa-compliance-sakamoto-family-smile

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

HIPAA privacy and security controls are enforced for PHI handling in healthcare software.

Core Features & Use Cases

  • Overlay HIPAA decision gates on healthcare privacy workflows to ensure PHI remains protected.
  • Provide structured guidance for PHI handling, data minimization, access controls, auditing, and BAAs when vendors are involved.
  • Use Case: When designing a patient portal, use this skill to verify PHI access boundaries and logging requirements before deployment.

Quick Start

Describe a healthcare task involving PHI and ask for HIPAA-aware guidance.

Frequently Asked Questions about hipaa-compliance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I enforce HIPAA privacy controls for PHI handling in healthcare software?

HIPAA privacy controls for PHI handling are enforced by applying decision gates to healthcare workflows, ensuring protected health information remains secure during storage, processing, and transmission. This verifies access boundaries before deployment.

What HIPAA security requirements apply when designing a patient portal?

HIPAA security requirements for a patient portal include enforcing authentication, data minimization, audit logging, and secure data handling. This approach verifies PHI access boundaries and logging requirements before the portal goes live.

How do I set up audit logging and access control for PHI data processing?

Audit logging and access control for PHI data processing are established by applying HIPAA guardrails to healthcare software. This enforces authentication and structured logging to track all protected health information access.

Do I need a BAA when sharing PHI with external vendors?

A BAA is required when sharing PHI with external vendors. HIPAA guardrails provide structured guidance for vendor data sharing, ensuring protected health information remains protected through proper agreements and data minimization.

What is data minimization in HIPAA compliance workflows?

Data minimization in HIPAA compliance limits protected health information collection to what is strictly necessary. It acts as a decision gate overlay on healthcare privacy workflows to ensure PHI remains protected during processing.

Can I use this to verify PHI access boundaries before deployment?

You can verify PHI access boundaries before deployment by applying HIPAA-aware guidance to healthcare tasks. This enforces access control and logging requirements to ensure protected health information stays secure.