What problem does it solve? Security teams struggle to determine whether their firewall estate actually supports HIPAA Security Rule requirements, and often overclaim that a device is "HIPAA compliant" when compliance is assessed at the covered entity or business associate level. This Skill provides a structured method to map NGFW controls, configurations, and evidence to specific 45 CFR Part 164 safeguards without overpromising. ## Core Features & Use Cases - Control Mapping: Maps firewall capabilities (segmentation, access control, audit logging, transmission security) to HIPAA safeguards including 164.312(a)-(e), 164.308, and 164.314 via a full control-by-control matrix. - Assessment Workflow: Guides a nine-step assessment from ePHI scoping through vendor/BAA path validation, with evidence markers, red flags, and an evidence request checklist. - Runtime Intake: Asks targeted clarifying questions about organizational role, ePHI scope, evidence period, and report emphasis before producing conclusions. - Use Case: Given a Palo Alto or Fortinet firewall configuration export, assess whether rules protecting an EHR system align with HIPAA access control and audit safeguard expectations, then produce a safeguard matrix with gaps and remediation steps. ## Quick Start Use the hipaa-ngfw-compliance skill to assess this firewall configuration against HIPAA Security Rule safeguards and identify gaps.