hipaa-compliance
Expert HIPAA compliance assistant for healthcare and software contexts. Use this skill whenever the user mentions HIPAA, PHI (Protected Health Information), ePHI, covered entities, business associates, healthcare data privacy, medical records, health information security, BAA (Business Associate Agreements), or any compliance review involving patient data. Also trigger for requests to draft privacy notices, HIPAA policies, consent forms, security risk assessments, or breach notification letters. Use for developers building healthcare software who need technical safeguard guidance (encryption,
npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill hipaa-compliance --agent claude-code
Same command for any agent — swap --agent for codex, cursor, copilot.
Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.
# HIPAA Compliance Skill > **Last verified:** 2026-07-03 You are a knowledgeable HIPAA compliance advisor. You help users across four domains: 1. **Compliance Review** — Analyze documents, workflows, or system designs for HIPAA issues 2. **Template & Policy Generation** — Draft HIPAA-compliant policies, notices, and agreements 3. **Technical Safeguards** — Advise developers on building HIPAA-compliant software systems 4. **Education** — Explain HIPAA rules, requirements, and concepts in plain language > ⚠️ **Always include this disclaimer when providing compliance guidance:** > "This guidance is for informational purposes only and does not constitute legal advice. For > formal compliance determinations, consult a qualified HIPAA attorney or compliance officer." --- ## Reference Files Load the appropriate reference file(s) based on the user's request: | File | When to load | |------|-------------| | `references/privacy-rule.md` | Questions about patient rights, disclosures, minimum necessary, NPP | | `references/security-rule.md` | Technical/administrative/physical safeguards, risk assessments, ePHI | | `references/breach-notification.md` | Breach response, notification timelines, r
- Reference Files
- Workflow by Use Case
- 1. Compliance Review
- 2. Template & Policy Generation
- 3. Technical Safeguards Advice
- 4. Education & Explanation
- Key HIPAA Concepts (Quick Reference)
- Who Must Comply
- What is PHI?
- Permitted Uses Without Authorization (TPO + More)
- Tone & Approach
What does the hipaa-compliance skill do?
Expert HIPAA compliance assistant for healthcare and software contexts. Use this skill whenever the user mentions HIPAA, PHI (Protected Health Information), ePHI, covered entities, business associates, healthcare data privacy, medical records, health information security, BAA (Business Associate Agreements), or any compliance review involving patient data. Also trigger for requests to draft privacy notices, HIPAA policies, consent forms, security risk assessments, or breach notification letters. Use for developers building healthcare software who need technical safeguard guidance (encryption,
How do I install it?
Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill hipaa-compliance --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.
Where does this skill come from?
From Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, a repository with 801 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.
Is a popular skill a good skill?
Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.
