Installs into .claude/skills of the current project.
Are you the author of Hipaa Compliance?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/nmor-hipaa-compliance-the-council)
---
name: hipaa-compliance
description: Principal-level guidance for HIPAA Privacy + Security + Breach Notification + HITECH + 42 CFR Part 2 compliance — BAAs, minimum-necessary, ePHI encryption, audit controls, breach 60-day clock, OCR enforcement. Sister to gdpr-ccpa-compliance, audit-logging, data-retention, security.
disable-model-invocation: true
---
# HIPAA Compliance
> **Size budget: 8 KB** — `token-budget.mjs --check`.
Principal-level guidance for HIPAA Privacy + Security + Breach Notification + HITECH + 42 CFR Part 2 compliance — BAAs, minimum-necessary, ePHI encryption, audit controls, breach 60-day clock, OCR enforcement. Sister to gdpr-ccpa-compliance, audit-logging, data-retention, security.
## Working procedure
1. Establish the relevant mode and existing evidence; do not repeat completed intake.
2. Determine covered entity/business associate and actual record applicability first. Protect PHI, document evidence and legal holds; security telemetry is not automatically a HIPAA medical record. Never claim compliance from a checklist alone.
3. Read only the corresponding sections below before applying their examples.
4. Verify the result with meaningful positive, negative and failure controls. Record actual outcomes, limitations and next action.
## Selected references
- [Purpose](references/procedure.md#purpose) — read when this part of the task applies.
- [Standards Cited](references/procedure.md#standards-cited) — read when this part of the task applies.
- [When to Fire](references/procedure.md#when-to-fire) — read when this part of the task applies.
- [Core Patterns](references/procedure.md#core-patterns) — read when this part of the task applies.
- [Anti-Patterns](references/procedure.md#anti-patterns) — read when this part of the task applies.
- [Verification Checklist](references/procedure.md#verification-checklist) — read when this part of the task applies.
- [Cross-References](references/procedure.md#cross-references) — read when this part of the task applies.
- [Why This Skill Exists](references/procedure.md#why-this-skill-exists) — read when this part of the task applies.
- [Learning hooks](references/procedure.md#learning-hooks) — read when this part of the task applies.
The [full procedure](references/procedure.md) preserves detailed examples and standards.
Load relevant excerpts rather than the entire reference. Runtime capabilities and higher-priority instructions govern imported templates.