Agent skill

Healthcare Phi Compliance

by affaan-m in affaan-m/ECC

医疗应用中受保护健康信息(PHI)和个人身份信息(PII)的合规模式。涵盖数据分类、访问控制、审计追踪、加密及常见泄露途径。

MITAuto-check passed

Install Healthcare Phi Compliance

skills CLI
$ npx skills add affaan-m/ECC --skill healthcare-phi-compliance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install affaan-m/ECC healthcare-phi-compliance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/affaan-m/ECC.git skills-src && mkdir -p .claude/skills && cp -r skills-src/docs/zh-CN/skills/healthcare-phi-compliance .claude/skills/healthcare-phi-compliance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
healthcare-phi-compliance
GitHub stars
276k
Token cost
~901 tokens
SKILL.md length
94 words
Files
1
Skills in repo
683
Repo updated
First seen
Licence
MIT

At a glance

医疗应用中受保护健康信息(PHI)和个人身份信息(PII)的合规模式。涵盖数据分类、访问控制、审计追踪、加密及常见泄露途径。

  • SKILL.md covers 何时使用, 工作原理 and 示例
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Healthcare Phi Compliance is an agent skill from affaan-m/ECC. 医疗应用中受保护健康信息(PHI)和个人身份信息(PII)的合规模式。涵盖数据分类、访问控制、审计追踪、加密及常见泄露途径。

Its SKILL.md is about 900 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond. The licence is MIT.

Example prompts

  • “/healthcare-phi-compliance”

What it can do on your machine

Read from SKILL.md and the folder at commit 4eb71d9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are sql and typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Healthcare Phi Compliance loads about 901 tokens when it runs. Until then it costs about 22 tokens; SKILL.md has 94 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~22
When it runs · the whole SKILL.md, loaded when a task matches
~901

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from affaan-m/ECC at commit 4eb71d9, republished under its MIT licence (© affaan-m). 94 words, ~901 tokens.

Download SKILL.mdSave it as .claude/skills/healthcare-phi-compliance/SKILL.md (or your agent's skills folder).
name
healthcare-phi-compliance
description
医疗应用中受保护健康信息(PHI)和个人身份信息(PII)的合规模式。涵盖数据分类、访问控制、审计追踪、加密及常见泄露途径。
origin
Health1 Super Speciality Hospitals — contributed by Dr. Keyur Patel
version
1.0.0

医疗 PHI/PII 合规模式

用于保护医疗应用中患者数据、临床医生数据和财务数据的模式。适用于 HIPAA(美国)、DISHA(印度)、GDPR(欧盟)以及通用医疗数据保护。

何时使用

  • 构建任何涉及患者记录的功能
  • 为临床系统实施访问控制或身份验证
  • 设计医疗数据的数据库模式
  • 构建返回患者或临床医生数据的 API
  • 实施审计追踪或日志记录
  • 审查代码中的数据泄露漏洞
  • 为多租户医疗系统设置行级安全(RLS)

工作原理

医疗数据保护在三个层面运作:分类(什么是敏感数据)、访问控制(谁能查看)和审计(谁查看了数据)。

数据分类

PHI(受保护健康信息) — 任何能够识别患者身份且与其健康相关的数据:患者姓名、出生日期、地址、电话、电子邮件、国家身份证号码(SSN、Aadhaar、NHS 号码)、病历号、诊断、药物、化验结果、影像资料、保险单和理赔详情、预约和入院记录,或上述任意组合。

医疗系统中的 PII(非患者敏感数据):临床医生/员工个人详细信息、医生收费结构和支付金额、员工薪资和银行信息、供应商付款信息。

访问控制:行级安全
sql
ALTER TABLE patients ENABLE ROW LEVEL SECURITY;

-- Scope access by facility
CREATE POLICY "staff_read_own_facility"
  ON patients FOR SELECT TO authenticated
  USING (facility_id IN (
    SELECT facility_id FROM staff_assignments
    WHERE user_id = auth.uid() AND role IN ('doctor','nurse','lab_tech','admin')
  ));

-- Audit log: insert-only (tamper-proof)
CREATE POLICY "audit_insert_only" ON audit_log FOR INSERT
  TO authenticated WITH CHECK (user_id = auth.uid());
CREATE POLICY "audit_no_modify" ON audit_log FOR UPDATE USING (false);
CREATE POLICY "audit_no_delete" ON audit_log FOR DELETE USING (false);
审计追踪

每次 PHI 访问或修改都必须记录:

typescript
interface AuditEntry {
  timestamp: string;
  user_id: string;
  patient_id: string;
  action: 'create' | 'read' | 'update' | 'delete' | 'print' | 'export';
  resource_type: string;
  resource_id: string;
  changes?: { before: object; after: object };
  ip_address: string;
  session_id: string;
}
常见泄露途径

错误消息: 切勿在发送给客户端的错误消息中包含患者身份识别数据。仅在服务器端记录详细信息。

控制台输出: 切勿记录完整的患者对象。使用不透明的内部记录 ID(UUID)——而不是病历号、国家身份证号或姓名。

URL 参数: 切勿在可能出现在日志或浏览器历史记录中的查询字符串或路径段中包含患者身份识别数据。仅使用不透明的 UUID。

浏览器存储: 切勿在 localStorage 或 sessionStorage 中存储 PHI。仅在内存中保留 PHI,按需获取。

服务角色密钥: 切勿在客户端代码中使用 service_role 密钥。始终使用匿名/可发布密钥,并让 RLS 强制执行访问控制。

日志和监控: 切勿记录完整的患者记录。仅使用不透明的记录 ID(而不是病历号)。在发送到错误跟踪服务之前,清理堆栈跟踪。

数据库模式标记

在模式级别标记 PHI/PII 列:

sql
COMMENT ON COLUMN patients.name IS 'PHI: patient_name';
COMMENT ON COLUMN patients.dob IS 'PHI: date_of_birth';
COMMENT ON COLUMN patients.aadhaar IS 'PHI: national_id';
COMMENT ON COLUMN doctor_payouts.amount IS 'PII: financial';
部署检查清单

每次部署前:

  • 错误消息或堆栈跟踪中无 PHI
  • console.log/console.error 中无 PHI
  • URL 参数中无 PHI
  • 浏览器存储中无 PHI
  • 客户端代码中无 service_role 密钥
  • 所有 PHI/PII 表已启用 RLS
  • 所有数据修改均有审计追踪
  • 已配置会话超时
  • 所有 PHI 端点均需 API 身份验证
  • 已验证跨机构数据隔离

示例

示例 1:安全与不安全的错误处理
typescript
// BAD — leaks PHI in error
throw new Error(`Patient ${patient.name} not found in ${patient.facility}`);

// GOOD — generic error, details logged server-side with opaque IDs only
logger.error('Patient lookup failed', { recordId: patient.id, facilityId });
throw new Error('Record not found');
示例 2:多机构隔离的 RLS 策略
sql
-- Doctor at Facility A cannot see Facility B patients
CREATE POLICY "facility_isolation"
  ON patients FOR SELECT TO authenticated
  USING (facility_id IN (
    SELECT facility_id FROM staff_assignments WHERE user_id = auth.uid()
  ));

-- Test: login as doctor-facility-a, query facility-b patients
-- Expected: 0 rows returned
示例 3:安全日志记录
typescript
// BAD — logs identifiable patient data
console.log('Processing patient:', patient);

// GOOD — logs only opaque internal record ID
console.log('Processing record:', patient.id);
// Note: even patient.id should be an opaque UUID, not a medical record number

© affaan-m, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in docs/zh-CN/skills/healthcare-phi-compliance of affaan-m/ECC.

Open the folder on GitHubat commit 4eb71d9

Compare with similar skills

Healthcare Phi Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Healthcare Phi Compliance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Healthcare Phi Compliance this skillaffaan-m/ECC276k—~901Automated safety check: PassMIT
Pii Detectruvnet/ruflo74k—~350Automated safety check: NotesMIT
Paddle Phi KernelPaddlePaddle/Paddle24k—~656Automated safety check: PassApache-2.0
Extracting Pii Entitiesmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Pick A Pii Modelmaziyarpanahi/openmed5.5k—~798Automated safety check: PassApache-2.0
Deepread PiiLeoYeAI/openclaw-master-skills2.2k—~5kAutomated safety check: PassMIT

Similar skills

  • Pii Detect

    ruvnet/ruflo

    Detect and flag personally identifiable information (PII) in text, code, and configurations.

    74k GitHub stars~350 tokensUpdated yesterday
    Auto-check: notes
  • Paddle Phi Kernel

    PaddlePaddle/Paddle

    A skill your agent uses when working with Paddle's PHI kernel system: registering new kernels, debugging kernel selection/dispatch, understanding code auto-generation from YAML, or implementing…

    24k GitHub stars~656 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Extracting Pii Entities

    maziyarpanahi/openmed

    Detect PHI/PII spans in clinical text with OpenMed's extractpii without altering the text.

    5.5k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Pick A Pii Model

    maziyarpanahi/openmed

    Select an on-device OpenMed PII model from the committed registry by language, runtime format, and size budget, then require recall validation before deployment.

    5.5k GitHub stars~798 tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Deepread Pii

    LeoYeAI/openclaw-master-skills

    Redact PII from documents before sharing or sending to LLMs.

    2.2k GitHub stars~5k tokensUpdated 2 mo ago
    Documents & OfficeAuto-check passed
  • Benchmark Pii Recall

    maziyarpanahi/openmed

    Benchmark an OpenMed PII model with synthetic gold spans and report label-aware exact-span and grapheme recall without emitting identifier surfaces.

    5.5k GitHub stars~1k tokensUpdated today
    AI & LLM EngineeringAuto-check passed

More from affaan-m/ECC

All 682 skills in this repo
  • Skill Stocktake

    affaan-m/ECC

    Audits your installed Claude skills and commands for quality, with a quick mode for recently changed skills and a full mode that evaluates all of them through subagents.

    277k GitHub starsUsed in 5 repos~3.1k tokens
    Auto-check passed
  • Ingests, indexes, searches, edits and monitors video, audio and live streams through the VideoDB Python SDK, returning stream links, clips and timestamps.

    277k GitHub starsUsed in 3 repos~3.5k tokens
    Auto-check: notes
  • Docs Governance

    affaan-m/ECC

    Route broad documentation-governance requests to existing ECC skills and run an opt-in, read-only audit of mapped documentation roles, links, ADR indexes, and evidence references.

    277k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Rules Distillation

    affaan-m/ECC

    Scans installed skills for principles that recur across them and proposes rule-file changes: append, revise, add a section, create a file or leave as covered.

    277k GitHub starsUsed in 2 repos~2.3k tokens
    Auto-check passed
  • Builds DRAFT counterparty agreements from one markdown template and a small JSON spec per party, with clauses picked by the party's role.

    277k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Set an ECC-specific frontend design direction for production UI work.

    277k GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed

Questions about Healthcare Phi Compliance

What does Healthcare Phi Compliance do?

医疗应用中受保护健康信息(PHI)和个人身份信息(PII)的合规模式。涵盖数据分类、访问控制、审计追踪、加密及常见泄露途径。. Healthcare Phi Compliance is an agent skill from affaan-m/ECC.

How do I install Healthcare Phi Compliance in Claude Code?

Run `npx skills add affaan-m/ECC --skill healthcare-phi-compliance -a claude-code`. Or copy the skill folder (docs/zh-CN/skills/healthcare-phi-compliance in affaan-m/ECC) into .claude/skills/healthcare-phi-compliance in your project. Claude Code loads it when a task matches its description.

How do I install Healthcare Phi Compliance in Codex?

Run `npx skills add affaan-m/ECC --skill healthcare-phi-compliance -a codex`. Or copy the skill folder (docs/zh-CN/skills/healthcare-phi-compliance in affaan-m/ECC) into .agents/skills/healthcare-phi-compliance in your project. Codex loads it when a task matches its description.

Can I use Healthcare Phi Compliance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add affaan-m/ECC --skill healthcare-phi-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/healthcare-phi-compliance, .gemini/skills/healthcare-phi-compliance, .github/skills/healthcare-phi-compliance and .opencode/skills/healthcare-phi-compliance in your project.

What does Healthcare Phi Compliance need to run?

SKILL.md names no scripts, command-line tools or credentials: Healthcare Phi Compliance is instructions for the agent only.

Does Healthcare Phi Compliance access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Healthcare Phi Compliance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Healthcare Phi Compliance use?

Healthcare Phi Compliance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Healthcare Phi Compliance use?

About 901 tokens (SKILL.md is roughly 3.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Healthcare Phi Compliance?

Skills that share tags, products or a category with Healthcare Phi Compliance: Pii Detect (ruvnet/ruflo, 74k stars), Paddle Phi Kernel (PaddlePaddle/Paddle, 24k stars), Extracting Pii Entities (maziyarpanahi/openmed, 5.5k stars) and Pick A Pii Model (maziyarpanahi/openmed, 5.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Healthcare Phi Compliance?

affaan-m (a GitHub user) maintains it in affaan-m/ECC, which has 276,111 GitHub stars. The repository holds 683 skills in this directory. The repository was last updated on October 10, 2026.

Source: affaan-m/ECC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.