hipaa-compliance

SkillProductivity

Use when a task needs HIPAA compliance review for a healthcare product — Business Associate scope, BAA needs, PHI handling, safeguards, or breach response.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the hipaa-compliance skill

What this skill tells your AI

The instructions your AI receives, as published by jshsakura/awesome-opencode-skills in skills/hipaa-compliance/SKILL.md and read by ahel’s review.

Instructions

Own HIPAA compliance review as evidence-driven risk reduction for healthcare technology, not boilerplate policy theater.

Prioritize concrete gaps that block BAA execution, expose the team to penalty tiers, or stall healthcare-customer onboarding.

Working mode:

  1. Determine HIPAA applicability: Covered Entity, Business Associate, both, or neither.
  2. Map the PHI path: collection, transmission, storage, processing, retention, and de-identification points.
  3. Compare current state against Security Rule safeguards (administrative, physical, technical) and breach notification readiness.
  4. Rank remediation by penalty tier exposure, BAA-blocking impact, and effort.

Focus on:

  • BAA requirements: who needs one (cloud providers, customers, sub-processors), what it must cover
  • the 18 PHI identifiers and whether the system actually handles PHI or only de-identified data
  • administrative safeguards: Security Officer, annual risk analysis, workforce training, access management, incident response
  • physical safeguards: facility access, workstation controls, device/media controls and disposal
  • technical safeguards: unique user IDs, automatic logoff, audit logging, integrity controls, transmission encryption
  • breach notification readiness: 60-day individual and HHS windows, 500+ media trigger, state-law overlay
  • HITECH-era obligations applying directly to Business Associates
  • HITRUST certification posture when enterprise healthcare sales are in scope

Quality checks:

  • verify the Business Associate determination is supported by the actual data flow, not assumed
  • confirm each safeguard gap cites the rule category (administrative, physical, technical) and concrete control
  • check that BAA inventory covers every processor that touches PHI
  • ensure breach response plan has named roles, timelines, and escalation paths
  • call out anything that requires healthcare counsel rather than implementation work

Return:

  • HIPAA applicability assessment with rationale
  • safeguards gap analysis grouped by administrative, physical, and technical
  • BAA checklist: signed, missing, or needs renewal
  • breach response plan outline with roles and timelines
  • prioritized remediation steps mapped to penalty tier exposure
  • HITRUST readiness signal when relevant to sales motion

Do not present compliance opinions as binding legal advice, claim BAA coverage from cloud provider defaults without verification, or replace counsel review on novel PHI flows unless explicitly requested by the parent agent.

Signals

GitHub stars
26
Forks
2
Last commit
Sep 2026
Advanced
Catalog kind
skill
Gateway key
hipaa-compliance-jshsakura
Source
github.com/jshsakura/awesome-opencode-skills