HIPAA Safe Harbor Coverage Audit
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
Clinical-grade PII/PHI detection and de-identification for healthcare text data.
$ npx skills add aipoch/medical-research-skills --skill hipaa-compliance-auditor -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aipoch/medical-research-skills hipaa-compliance-auditor --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aipoch/medical-research-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/'scientific-skills/Academic Writing/hipaa-compliance-auditor' .claude/skills/hipaa-compliance-auditor && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "hipaa-compliance-auditor" agent skill from https://github.com/aipoch/medical-research-skills/tree/main/scientific-skills/Academic%20Writing/hipaa-compliance-auditor into .claude/skills/hipaa-compliance-auditor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hipaa-compliance-auditor", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aipoch/medical-research-skills/tree/main/scientific-skills/Academic%20Writing/hipaa-compliance-auditorType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aipoch/medical-research-skills --skill hipaa-compliance-auditor -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aipoch/medical-research-skills hipaa-compliance-auditor --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aipoch/medical-research-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/'scientific-skills/Academic Writing/hipaa-compliance-auditor' .agents/skills/hipaa-compliance-auditor && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "hipaa-compliance-auditor" agent skill from https://github.com/aipoch/medical-research-skills/tree/main/scientific-skills/Academic%20Writing/hipaa-compliance-auditor into .agents/skills/hipaa-compliance-auditor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hipaa-compliance-auditor", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aipoch/medical-research-skills --skill hipaa-compliance-auditor -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aipoch/medical-research-skills hipaa-compliance-auditor --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aipoch/medical-research-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/'scientific-skills/Academic Writing/hipaa-compliance-auditor' .cursor/skills/hipaa-compliance-auditor && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "hipaa-compliance-auditor" agent skill from https://github.com/aipoch/medical-research-skills/tree/main/scientific-skills/Academic%20Writing/hipaa-compliance-auditor into .cursor/skills/hipaa-compliance-auditor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hipaa-compliance-auditor", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aipoch/medical-research-skills.git --path 'scientific-skills/Academic Writing/hipaa-compliance-auditor'--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aipoch/medical-research-skills --skill hipaa-compliance-auditor -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aipoch/medical-research-skills hipaa-compliance-auditor --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aipoch/medical-research-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/'scientific-skills/Academic Writing/hipaa-compliance-auditor' .gemini/skills/hipaa-compliance-auditor && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "hipaa-compliance-auditor" agent skill from https://github.com/aipoch/medical-research-skills/tree/main/scientific-skills/Academic%20Writing/hipaa-compliance-auditor into .gemini/skills/hipaa-compliance-auditor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hipaa-compliance-auditor", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aipoch/medical-research-skills hipaa-compliance-auditorInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aipoch/medical-research-skills --skill hipaa-compliance-auditor -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aipoch/medical-research-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/'scientific-skills/Academic Writing/hipaa-compliance-auditor' .github/skills/hipaa-compliance-auditor && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "hipaa-compliance-auditor" agent skill from https://github.com/aipoch/medical-research-skills/tree/main/scientific-skills/Academic%20Writing/hipaa-compliance-auditor into .github/skills/hipaa-compliance-auditor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hipaa-compliance-auditor", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aipoch/medical-research-skills --skill hipaa-compliance-auditor -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aipoch/medical-research-skills hipaa-compliance-auditor --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aipoch/medical-research-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/'scientific-skills/Academic Writing/hipaa-compliance-auditor' .opencode/skills/hipaa-compliance-auditor && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "hipaa-compliance-auditor" agent skill from https://github.com/aipoch/medical-research-skills/tree/main/scientific-skills/Academic%20Writing/hipaa-compliance-auditor into .opencode/skills/hipaa-compliance-auditor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hipaa-compliance-auditor", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
hipaa-compliance-auditorClinical-grade PII/PHI detection and de-identification for healthcare text data.
Hipaa Compliance Auditor is an agent skill from aipoch/medical-research-skills. Clinical-grade PII/PHI detection and de-identification for healthcare text data. Scans all 18 HIPAA identifier categories with confidence scoring, generates audit logs, supports custom regex patterns, and produces de-identified output while preserving document structure.
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `POLISH_CHANGELOG.md`, `eval_report_hipaa-compliance-auditor_result.json` and `references/hipaa_safe_harbor_guide.md`).
It sits in Legal & Compliance, covering Healthcare and finance regulation and Clinical and healthcare research. It works with Python. The repository describes itself as: Hundreds of agent skills for medical research, including protocol design, data analysis, evidence insights, and academic writing. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 686e09d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
pythonFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Hipaa Compliance Auditor loads about 2.9k tokens when it runs, and up to ~4.7k if it reads all its reference files. Until then it costs about 74 tokens; SKILL.md has 1,177 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from aipoch/medical-research-skills at commit 686e09d, republished under its MIT licence (© aipoch). 1,177 words, ~2,884 tokens.
.claude/skills/hipaa-compliance-auditor/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.A clinical-grade PII/PHI detection and de-identification tool for healthcare text data.
Use this command to verify that the packaged script entry point can be parsed before deeper execution.
python -m py_compile scripts/main.pyUse these concrete commands for validation. They are intentionally self-contained and avoid placeholder paths.
python -m py_compile scripts/main.py
python scripts/main.py --help
python scripts/main.py --text "Audit validation sample with explicit methods, findings, and conclusion."Provide clinical text in one of two ways:
python scripts/main.py --input patient_text.txt --output deidentified.txtpython scripts/main.py --text "Patient John Doe, SSN 123-45-6789..." --audit-log audit.jsonIf neither input provided: Request the text or file path from the user. Do not proceed without input.
--confidence 0.7 (default): Minimum confidence threshold (0.0-1.0). Lower = more detections but more false positives.--preserve-structure true (default): Maintain document formatting after redaction--custom-patterns <path>: Optional custom regex patterns JSON for institution-specific identifiers🔍 Checkpoint 1: If confidence threshold is changed from default, inform the user about the trade-off (lower threshold catches more PII but may produce more false positives).
from scripts.main import HIPAAAuditor
auditor = HIPAAAuditor()
result = auditor.deidentify("Patient John Doe was admitted on 2024-01-15...")
# result.cleaned_text → De-identified output
# result.detected_pii → List of found PII entities with types and confidence scoresIf de-identification fails (missing spaCy model): Install with python -m spacy download en_core_web_trf, then retry.
Check the audit log for:
If unexpected PII remains: Increase custom patterns or lower confidence threshold.
This skill analyzes text for HIPAA-protected identifiers and automatically redacts or anonymizes them. It uses a combination of regex patterns, NLP entity recognition, and contextual analysis to identify 18 HIPAA identifier categories.
[PATIENT_NAME], [DATE_1])python scripts/main.py --input "patient_text.txt" --output "deidentified.txt"
python scripts/main.py --text "Patient John Doe, SSN 123-45-6789..." --audit-log audit.jsonfrom scripts.main import HIPAAAuditor
auditor = HIPAAAuditor()
result = auditor.deidentify("Patient John Doe was admitted on 2024-01-15...")
print(result.cleaned_text) # De-identified output
print(result.detected_pii) # List of found PII entities| Parameter | Type | Default | Required | Description |
|---|---|---|---|---|
--input, -i | string | - | No | Path to input text file |
--text | string | - | No | Direct text input (alternative to file) |
--output, -o | string | - | No | Path for de-identified output file |
--audit-log | string | - | No | Path for JSON audit log |
--confidence | float | 0.7 | No | Minimum confidence threshold (0.0-1.0) |
--preserve-structure | bool | true | No | Maintain document structure |
--custom-patterns | string | - | No | Path to custom regex patterns JSON |
Original identifiers replaced with semantic tags:
[PATIENT_NAME_1], [PATIENT_NAME_2] ...[DATE_1], [DATE_2] ...[SSN_1][PHONE_1], [PHONE_2] ...[EMAIL_1][MRN_1] (Medical Record Number)[ADDRESS_1]{
"timestamp": "2024-01-15T10:30:00Z",
"input_hash": "sha256:abc123...",
"detections": [
{
"type": "PATIENT_NAME",
"position": [10, 18],
"confidence": 0.95,
"replacement": "[PATIENT_NAME_1]",
"original_length": 8
}
],
"statistics": {
"total_pii_found": 5,
"categories_detected": ["NAME", "DATE", "PHONE", "SSN"]
}
}See references/requirements.txt for full dependency list.
⚠️ CRITICAL: This tool is designed as a helper, not a replacement for human review.
references/hipaa_safe_harbor_guide.pdf - HIPAA Safe Harbor de-identification standardsreferences/pii_patterns.json - Complete regex pattern definitionsreferences/test_cases/ - Sample clinical texts with expected outputsreferences/requirements.txt - Python dependenciesComplex NLP pipelines, contextual disambiguation, regulatory compliance requirements.
| Risk Indicator | Assessment | Level |
|---|---|---|
| Code Execution | Python/R scripts executed locally | Medium |
| Network Access | No external API calls | Low |
| File System Access | Read input files, write output files | Medium |
| Instruction Tampering | Standard prompt guidelines | Low |
| Data Exposure | Output files saved to workspace | Low |
# Python dependencies
pip install -r requirements.txtEvery final response should make these items explicit when they are relevant:
scripts/main.py fails, report the failure point, summarize what still can be completed safely, and provide a manual fallback.This skill accepts requests that match the documented purpose of hipaa-compliance-auditor and include enough context to complete the workflow safely.
Do not continue the workflow when the request is out of scope, missing a critical input, or would require unsupported assumptions. Instead respond:
hipaa-compliance-auditoronly handles its documented workflow. Please provide the missing required inputs or switch to a more suitable skill.
Use the following fixed structure for non-trivial requests:
If the request is simple, you may compress the structure, but still keep assumptions and limits explicit when they affect correctness.
© aipoch, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files (scripts, references) in scientific-skills/Academic Writing/hipaa-compliance-auditor of aipoch/medical-research-skills.
Open the folder on GitHubat commit 686e09d
Hipaa Compliance Auditor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Hipaa Compliance Auditor this skillaipoch/medical-research-skills | 1.9k | — | ~2.9k | Automated safety check: Pass | MIT | |
| HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Clinical Reportsdavila7/claude-code-templates | 33k | 11 repos | ~9.9k | Automated safety check: Notes | MIT | |
| Shifting Clinical Datesmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Healthtech Advisorborghei/Claude-Skills | 891 | — | ~1.7k | Automated safety check: Pass | MIT | |
| Health Data Dpiamukul975/Privacy-Data-Protection-Skills | 301 | — | ~2.4k | Automated safety check: Pass | Apache-2.0 |
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
davila7/claude-code-templates
Write comprehensive clinical reports including case reports (CARE guidelines), diagnostic reports (radiology/pathology/lab), clinical trial reports (ICH-E3, SAE, CSR), and patient documentation…
maziyarpanahi/openmed
Apply consistent per-patient date shifting in OpenMed that preserves intervals between events while satisfying HIPAA Safe Harbor's date rule.
borghei/Claude-Skills
Strategic advisory for digital health founders on HIPAA scope, FDA SaMD classification, EHR integration, and payor/provider GTM.
mukul975/Privacy-Data-Protection-Skills
Guides DPIA for health and medical data processing covering Art.
mukul975/Privacy-Data-Protection-Skills
Addresses healthcare AI privacy at the intersection of HIPAA and the EU AI Act for clinical decision support systems.
aipoch/medical-research-skills
Complete workflow for generating academic research posters from PDF literature; use when you need to extract paper content from PDFs and produce a LaTeX-based poster…
aipoch/medical-research-skills
Analyzes clinical diagnostic accuracy studies for bias using the QUADAS-2 tool.
aipoch/medical-research-skills
Perform comprehensive exploratory data analysis on scientific data files across 200+ file formats.
aipoch/medical-research-skills
A toolkit for preparing ISO 13485:2016 certification documentation for medical device QMS.
aipoch/medical-research-skills
Recommends target journals for manuscript submission by analyzing the paper topic/abstract and the journal distribution of similar PubMed literature; use when users ask for journal…
aipoch/medical-research-skills
Creates academic-poster writing packages for LaTeX using beamerposter, tikzposter, or baposter.
Works with
Categories
Clinical-grade PII/PHI detection and de-identification for healthcare text data. Hipaa Compliance Auditor is an agent skill from aipoch/medical-research-skills. Clinical-grade PII/PHI detection and de-identification for healthcare text data.
Hipaa Compliance Auditor fits situations like: tasks that involve Healthcare and finance regulation; tasks that involve Clinical and healthcare research.
Run `npx skills add aipoch/medical-research-skills --skill hipaa-compliance-auditor -a claude-code`. Or copy the skill folder (scientific-skills/Academic Writing/hipaa-compliance-auditor in aipoch/medical-research-skills) into .claude/skills/hipaa-compliance-auditor in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aipoch/medical-research-skills --skill hipaa-compliance-auditor -a codex`. Or copy the skill folder (scientific-skills/Academic Writing/hipaa-compliance-auditor in aipoch/medical-research-skills) into .agents/skills/hipaa-compliance-auditor in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aipoch/medical-research-skills --skill hipaa-compliance-auditor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hipaa-compliance-auditor, .gemini/skills/hipaa-compliance-auditor, .github/skills/hipaa-compliance-auditor and .opencode/skills/hipaa-compliance-auditor in your project.
Going by SKILL.md and its folder, Hipaa Compliance Auditor needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Hipaa Compliance Auditor is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.8k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Hipaa Compliance Auditor: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Clinical Reports (davila7/claude-code-templates, 33k stars), Shifting Clinical Dates (maziyarpanahi/openmed, 5.5k stars) and Healthtech Advisor (borghei/Claude-Skills, 891 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aipoch (a GitHub organization) maintains it in aipoch/medical-research-skills, which has 1,937 GitHub stars. The repository holds 578 skills in this directory. The repository was last updated on September 17, 2026.
Source: aipoch/medical-research-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.