hipaa-risk-review

Analyze PHI handling practices and controls to identify HIPAA compliance gaps.

6|5|Updated Feb 4, 2026
One-click install
npx skills add https://github.com/writer/skills --skill hipaa-risk-review-writer
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: hipaa-risk-review
Source: https://github.com/writer/skills/tree/main/skills/hipaa-risk-review
Command: npx skills add https://github.com/writer/skills --skill hipaa-risk-review-writer

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill helps organizations identify and assess privacy and security risks related to Protected Health Information (PHI) under HIPAA regulations, ensuring compliance and preventing breaches.

Core Features & Use Cases

  • Systematic Risk Analysis: Conducts thorough assessments of PHI handling practices, technical safeguards, and administrative controls.
  • Gap Identification: Pinpoints compliance gaps against HIPAA Privacy, Security, and Breach Notification Rules.
  • Remediation Planning: Develops actionable plans to address identified risks and vulnerabilities.
  • Use Case: A healthcare provider needs to prepare for an upcoming OCR audit. This Skill can perform a comprehensive HIPAA risk assessment, identify any deficiencies, and provide a clear roadmap for remediation, significantly reducing audit risk.

Quick Start

Use the hipaa-risk-review skill to assess my hipaa risks and identify required fixes.

Frequently Asked Questions about hipaa-risk-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct a systematic risk analysis for Protected Health Information under HIPAA?

A systematic HIPAA risk analysis evaluates your PHI handling practices, technical safeguards, and administrative controls to identify privacy and security risks. It assesses current controls against HIPAA requirements to pinpoint compliance gaps.

What is the best way to prepare for an OCR audit and identify HIPAA compliance gaps?

Preparing for an OCR audit requires evaluating your current safeguards against HIPAA Privacy, Security, and Breach Notification Rules. This process identifies compliance gaps and produces a clear remediation roadmap to significantly reduce audit risk.

How do I quantify risk levels and create remediation plans for healthcare security vulnerabilities?

You can quantify healthcare security risk levels by evaluating technical vulnerabilities and administrative control gaps against the NIST Cybersecurity Framework. This assessment produces actionable remediation plans aligned with OCR enforcement priorities.

Can I assess both administrative controls and technical safeguards for PHI privacy in one process?

Yes, you can assess both administrative controls and technical safeguards concurrently. A comprehensive PHI risk analysis evaluates handling practices across all operational areas to identify privacy and security vulnerabilities under HIPAA.

When do I need a HIPAA risk assessment for my healthcare operations?

You need a HIPAA risk assessment when handling Protected Health Information to ensure compliance and prevent breaches. It is essential when preparing for OCR audits or evaluating new PHI handling workflows against NIST Cybersecurity Framework standards.