Skip to content
Back to skills

Hipaa Compliance

ASecurity

Principal-level guidance for HIPAA Privacy + Security + Breach Notification + HITECH + 42 CFR Part 2 compliance — BAAs, minimum-necessary, ePHI encryption, audit controls, breach 60-day clock, OCR enforcement. Sister to gdpr-ccpa-compliance, audit-logging, data-retention, security.

  • 12 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 6, 2026
ai-agentsgosecurity

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned October 6, 2026

npx -y skills add Nmor/the-council --skill hipaa-compliance --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Hipaa Compliance?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Hipaa Compliance
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/nmor-hipaa-compliance-the-council/badge)](https://www.skillsdirectory.com/skills/nmor-hipaa-compliance-the-council)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: hipaa-compliance
description: Principal-level guidance for HIPAA Privacy + Security + Breach Notification + HITECH + 42 CFR Part 2 compliance — BAAs, minimum-necessary, ePHI encryption, audit controls, breach 60-day clock, OCR enforcement. Sister to gdpr-ccpa-compliance, audit-logging, data-retention, security.
disable-model-invocation: true
---

# HIPAA Compliance

> **Size budget: 8 KB** — `token-budget.mjs --check`.

Principal-level guidance for HIPAA Privacy + Security + Breach Notification + HITECH + 42 CFR Part 2 compliance — BAAs, minimum-necessary, ePHI encryption, audit controls, breach 60-day clock, OCR enforcement. Sister to gdpr-ccpa-compliance, audit-logging, data-retention, security.

## Working procedure

1. Establish the relevant mode and existing evidence; do not repeat completed intake.
2. Determine covered entity/business associate and actual record applicability first. Protect PHI, document evidence and legal holds; security telemetry is not automatically a HIPAA medical record. Never claim compliance from a checklist alone.
3. Read only the corresponding sections below before applying their examples.
4. Verify the result with meaningful positive, negative and failure controls. Record actual outcomes, limitations and next action.

## Selected references

- [Purpose](references/procedure.md#purpose) — read when this part of the task applies.
- [Standards Cited](references/procedure.md#standards-cited) — read when this part of the task applies.
- [When to Fire](references/procedure.md#when-to-fire) — read when this part of the task applies.
- [Core Patterns](references/procedure.md#core-patterns) — read when this part of the task applies.
- [Anti-Patterns](references/procedure.md#anti-patterns) — read when this part of the task applies.
- [Verification Checklist](references/procedure.md#verification-checklist) — read when this part of the task applies.
- [Cross-References](references/procedure.md#cross-references) — read when this part of the task applies.
- [Why This Skill Exists](references/procedure.md#why-this-skill-exists) — read when this part of the task applies.
- [Learning hooks](references/procedure.md#learning-hooks) — read when this part of the task applies.

The [full procedure](references/procedure.md) preserves detailed examples and standards.
Load relevant excerpts rather than the entire reference. Runtime capabilities and higher-priority instructions govern imported templates.

Files in this skill

  • SKILL.md2.4 KB
  • references/procedure.md20.4 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…