Agent skill

Hipaa Compliance Auditor

by aipoch in aipoch/medical-research-skills

Clinical-grade PII/PHI detection and de-identification for healthcare text data.

MITAuto-check passedLegal & Compliance

Install Hipaa Compliance Auditor

skills CLI
$ npx skills add aipoch/medical-research-skills --skill hipaa-compliance-auditor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aipoch/medical-research-skills hipaa-compliance-auditor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aipoch/medical-research-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/'scientific-skills/Academic Writing/hipaa-compliance-auditor' .claude/skills/hipaa-compliance-auditor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hipaa-compliance-auditor
GitHub stars
1.9k
Token cost
~2.9k tokens
SKILL.md length
1,177 words
Files
7 (incl. scripts, references)
Skills in repo
578
Repo updated
First seen
Licence
MIT

At a glance

Clinical-grade PII/PHI detection and de-identification for healthcare text data.

  • Works in 5 steps: Provide Input Text → Configure Detection Parameters → Run De-identification → …
  • Tasks that involve Healthcare and finance regulation
  • SKILL.md covers Quick Check, Audit-Ready Commands, When to Use and When NOT to Use, plus 16 more sections
  • Runs Python scripts from its folder; calls python

What it does

Hipaa Compliance Auditor is an agent skill from aipoch/medical-research-skills. Clinical-grade PII/PHI detection and de-identification for healthcare text data. Scans all 18 HIPAA identifier categories with confidence scoring, generates audit logs, supports custom regex patterns, and produces de-identified output while preserving document structure.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `POLISH_CHANGELOG.md`, `eval_report_hipaa-compliance-auditor_result.json` and `references/hipaa_safe_harbor_guide.md`).

It sits in Legal & Compliance, covering Healthcare and finance regulation and Clinical and healthcare research. It works with Python. The repository describes itself as: Hundreds of agent skills for medical research, including protocol design, data analysis, evidence insights, and academic writing. The licence is MIT.

When your agent uses it

  • Tasks that involve Healthcare and finance regulation
  • Tasks that involve Clinical and healthcare research

Example prompts

  • “/hipaa-compliance-auditor”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Provide Input Text
  2. Configure Detection Parameters
  3. Run De-identification
  4. Review Detection Results
  5. Output and QA Reminder

What it can do on your machine

Read from SKILL.md and the folder at commit 686e09d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hipaa Compliance Auditor loads about 2.9k tokens when it runs, and up to ~4.7k if it reads all its reference files. Until then it costs about 74 tokens; SKILL.md has 1,177 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~74
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from aipoch/medical-research-skills at commit 686e09d, republished under its MIT licence (© aipoch). 1,177 words, ~2,884 tokens.

Download SKILL.mdSave it as .claude/skills/hipaa-compliance-auditor/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
hipaa-compliance-auditor
description
Clinical-grade PII/PHI detection and de-identification for healthcare text data. Scans all 18 HIPAA identifier categories with confidence scoring, generates audit logs, supports custom regex patterns, and produces de-identified output while preserving document structure.
license
MIT
author
AIPOCH

Source: https://github.com/aipoch/medical-research-skills

HIPAA Compliance Auditor

A clinical-grade PII/PHI detection and de-identification tool for healthcare text data.

Quick Check

Use this command to verify that the packaged script entry point can be parsed before deeper execution.

bash
python -m py_compile scripts/main.py

Audit-Ready Commands

Use these concrete commands for validation. They are intentionally self-contained and avoid placeholder paths.

bash
python -m py_compile scripts/main.py
python scripts/main.py --help
python scripts/main.py --text "Audit validation sample with explicit methods, findings, and conclusion."

When to Use

  • Use this skill when the task needs A clinical-grade PII/PHI detection and de-identification tool for healthcare text data.
  • Use this skill for academic writing tasks that require explicit assumptions, bounded scope, and a reproducible output format.
  • Use this skill when you need a documented fallback path for missing inputs, execution errors, or partial evidence.

When NOT to Use

  • Do NOT use for DICOM image de-identification (use dicom-anonymizer skill)
  • Do NOT use for general data anonymization of structured databases (use dedicated tools)
  • Do NOT use as a legal compliance certification — this tool assists but does NOT replace human HIPAA review

Workflow

Step 1: Provide Input Text

Provide clinical text in one of two ways:

  • File input: python scripts/main.py --input patient_text.txt --output deidentified.txt
  • Direct text: python scripts/main.py --text "Patient John Doe, SSN 123-45-6789..." --audit-log audit.json

If neither input provided: Request the text or file path from the user. Do not proceed without input.

Step 2: Configure Detection Parameters
  • --confidence 0.7 (default): Minimum confidence threshold (0.0-1.0). Lower = more detections but more false positives.
  • --preserve-structure true (default): Maintain document formatting after redaction
  • --custom-patterns <path>: Optional custom regex patterns JSON for institution-specific identifiers

🔍 Checkpoint 1: If confidence threshold is changed from default, inform the user about the trade-off (lower threshold catches more PII but may produce more false positives).

Step 3: Run De-identification
python
from scripts.main import HIPAAAuditor

auditor = HIPAAAuditor()
result = auditor.deidentify("Patient John Doe was admitted on 2024-01-15...")
# result.cleaned_text → De-identified output
# result.detected_pii → List of found PII entities with types and confidence scores

If de-identification fails (missing spaCy model): Install with python -m spacy download en_core_web_trf, then retry.

Step 4: Review Detection Results

Check the audit log for:

  • High-confidence detections (≥0.9): Verify replacements are correct
  • Medium-confidence detections (0.7-0.9): Manual review recommended
  • Categories detected: Confirm all 18 HIPAA identifier categories were scanned

If unexpected PII remains: Increase custom patterns or lower confidence threshold.

Step 5: Output and QA Reminder
  • Output de-identified text to file or stdout
  • Generate audit log JSON with all detection details
  • ⚠️ CRITICAL REMINDER: This tool is a helper, NOT a replacement for human review. Always perform manual QA before HIPAA-compliant release.

Overview

This skill analyzes text for HIPAA-protected identifiers and automatically redacts or anonymizes them. It uses a combination of regex patterns, NLP entity recognition, and contextual analysis to identify 18 HIPAA identifier categories.

Features

  • 18 HIPAA Identifiers Detection: Names, dates, SSN, MRN, phone/fax, email, geographic data, etc.
  • Automatic De-identification: Replace PII with semantic tokens (e.g., [PATIENT_NAME], [DATE_1])
  • Context-Aware Detection: Distinguishes between similar patterns (dates vs. lab values)
  • Audit Logging: Track all redaction actions for compliance documentation
  • Confidence Scoring: Flag uncertain detections for manual review

Usage

Command Line
text
python scripts/main.py --input "patient_text.txt" --output "deidentified.txt"
python scripts/main.py --text "Patient John Doe, SSN 123-45-6789..." --audit-log audit.json
Python API
python
from scripts.main import HIPAAAuditor

auditor = HIPAAAuditor()
result = auditor.deidentify("Patient John Doe was admitted on 2024-01-15...")
print(result.cleaned_text)  # De-identified output
print(result.detected_pii)  # List of found PII entities

Parameters

ParameterTypeDefaultRequiredDescription
--input, -istring-NoPath to input text file
--textstring-NoDirect text input (alternative to file)
--output, -ostring-NoPath for de-identified output file
--audit-logstring-NoPath for JSON audit log
--confidencefloat0.7NoMinimum confidence threshold (0.0-1.0)
--preserve-structurebooltrueNoMaintain document structure
--custom-patternsstring-NoPath to custom regex patterns JSON

HIPAA Identifier Categories Detected

  1. Names (patient, relatives, employers)
  2. Geographic subdivisions smaller than state
  3. Dates (except year) related to individual
  4. Phone numbers
  5. Fax numbers
  6. Email addresses
  7. SSN
  8. Medical record numbers
  9. Health plan beneficiary numbers
  10. Account numbers
  11. Certificate/license numbers
  12. Vehicle identifiers
  13. Device identifiers
  14. URLs
  15. IP addresses
  16. Biometric identifiers
  17. Full-face photos
  18. Any other unique identifying numbers

Output Format

De-identified Text

Original identifiers replaced with semantic tags:

  • [PATIENT_NAME_1], [PATIENT_NAME_2] ...
  • [DATE_1], [DATE_2] ...
  • [SSN_1]
  • [PHONE_1], [PHONE_2] ...
  • [EMAIL_1]
  • [MRN_1] (Medical Record Number)
  • [ADDRESS_1]
Audit Log JSON
json
{
  "timestamp": "2024-01-15T10:30:00Z",
  "input_hash": "sha256:abc123...",
  "detections": [
    {
      "type": "PATIENT_NAME",
      "position": [10, 18],
      "confidence": 0.95,
      "replacement": "[PATIENT_NAME_1]",
      "original_length": 8
    }
  ],
  "statistics": {
    "total_pii_found": 5,
    "categories_detected": ["NAME", "DATE", "PHONE", "SSN"]
  }
}

Technical Architecture

  1. Preprocessing: Normalize text encoding, handle line breaks
  2. Regex Engine: Pattern matching for structured identifiers (SSN, phone, email, MRN)
  3. NLP Pipeline: spaCy NER for names, organizations, locations
  4. Context Filter: Remove false positives (e.g., "Dr. Smith" vs. "smith fracture")
  5. Replacement Engine: Sequential replacement with semantic tokens
  6. Validation: Ensure no original PII remains in output

Dependencies

  • Python 3.9+
  • spaCy (en_core_web_trf or en_core_web_lg)
  • regex (for advanced pattern matching)
  • Presidio (optional, for enhanced PII detection)

See references/requirements.txt for full dependency list.

Show full SKILL.md (470 more words)Show less

Limitations & Warnings

⚠️ CRITICAL: This tool is designed as a helper, not a replacement for human review.

  • Context-dependent PII (e.g., rare disease names + location) may not be fully detected
  • Unstructured narrative text may contain identifying information not caught by patterns
  • Always perform manual QA on output before HIPAA-compliant release
  • AI Autonomous Acceptance Status: Requires Manual Review (Requires Manual Review)

References

  • references/hipaa_safe_harbor_guide.pdf - HIPAA Safe Harbor de-identification standards
  • references/pii_patterns.json - Complete regex pattern definitions
  • references/test_cases/ - Sample clinical texts with expected outputs
  • references/requirements.txt - Python dependencies

Technical Difficulty: High

Complex NLP pipelines, contextual disambiguation, regulatory compliance requirements.

Risk Assessment

Risk IndicatorAssessmentLevel
Code ExecutionPython/R scripts executed locallyMedium
Network AccessNo external API callsLow
File System AccessRead input files, write output filesMedium
Instruction TamperingStandard prompt guidelinesLow
Data ExposureOutput files saved to workspaceLow

Security Checklist

  • No hardcoded credentials or API keys
  • No unauthorized file system access (../)
  • Output does not expose sensitive information
  • Prompt injection protections in place
  • Input file paths validated (no ../ traversal)
  • Output directory restricted to workspace
  • Script execution in sandboxed environment
  • Error messages sanitized (no stack traces exposed)
  • Dependencies audited

Prerequisites

text
# Python dependencies
pip install -r requirements.txt

Evaluation Criteria

Success Metrics
  • Successfully executes main functionality
  • Output meets quality standards
  • Handles edge cases gracefully
  • Performance is acceptable
Test Cases
  1. Basic Functionality: Standard input → Expected output
  2. Edge Case: Invalid input → Graceful error handling
  3. Performance: Large dataset → Acceptable processing time

Lifecycle Status

  • Current Stage: Draft
  • Next Review Date: 2026-03-06
  • Known Issues: None
  • Planned Improvements:
    • Performance optimization
    • Additional feature support

Output Requirements

Every final response should make these items explicit when they are relevant:

  • Objective or requested deliverable
  • Inputs used and assumptions introduced
  • Workflow or decision path
  • Core result, recommendation, or artifact
  • Constraints, risks, caveats, or validation needs
  • Unresolved items and next-step checks

Error Handling

  • If required inputs are missing, state exactly which fields are missing and request only the minimum additional information.
  • If the task goes outside the documented scope, stop instead of guessing or silently widening the assignment.
  • If scripts/main.py fails, report the failure point, summarize what still can be completed safely, and provide a manual fallback.
  • Do not fabricate files, citations, data, search results, or execution outcomes.

Input Validation

This skill accepts requests that match the documented purpose of hipaa-compliance-auditor and include enough context to complete the workflow safely.

Do not continue the workflow when the request is out of scope, missing a critical input, or would require unsupported assumptions. Instead respond:

hipaa-compliance-auditor only handles its documented workflow. Please provide the missing required inputs or switch to a more suitable skill.

Response Template

Use the following fixed structure for non-trivial requests:

  1. Objective
  2. Inputs Received
  3. Assumptions
  4. Workflow
  5. Deliverable
  6. Risks and Limits
  7. Next Checks

If the request is simple, you may compress the structure, but still keep assumptions and limits explicit when they affect correctness.

© aipoch, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references) in scientific-skills/Academic Writing/hipaa-compliance-auditor of aipoch/medical-research-skills.

  • SKILL.md
  • POLISH_CHANGELOG.md
  • eval_report_hipaa-compliance-auditor_result.json
  • references/hipaa_safe_harbor_guide.md
  • references/pii_patterns.json
  • references/requirements.txt
  • scripts/main.py

Open the folder on GitHubat commit 686e09d

Compare with similar skills

Hipaa Compliance Auditor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hipaa Compliance Auditor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hipaa Compliance Auditor this skillaipoch/medical-research-skills1.9k—~2.9kAutomated safety check: PassMIT
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Clinical Reportsdavila7/claude-code-templates33k11 repos~9.9kAutomated safety check: NotesMIT
Shifting Clinical Datesmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Healthtech Advisorborghei/Claude-Skills891—~1.7kAutomated safety check: PassMIT
Health Data Dpiamukul975/Privacy-Data-Protection-Skills301—~2.4kAutomated safety check: PassApache-2.0

Similar skills

  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Clinical Reports

    davila7/claude-code-templates

    Write comprehensive clinical reports including case reports (CARE guidelines), diagnostic reports (radiology/pathology/lab), clinical trial reports (ICH-E3, SAE, CSR), and patient documentation…

    33k GitHub starsUsed in 11 repos~9.9k tokens
    Legal & ComplianceAuto-check: notes
  • Shifting Clinical Dates

    maziyarpanahi/openmed

    Apply consistent per-patient date shifting in OpenMed that preserves intervals between events while satisfying HIPAA Safe Harbor's date rule.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Healthtech Advisor

    borghei/Claude-Skills

    Strategic advisory for digital health founders on HIPAA scope, FDA SaMD classification, EHR integration, and payor/provider GTM.

    891 GitHub stars~1.7k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed
  • Health Data Dpia

    mukul975/Privacy-Data-Protection-Skills

    Guides DPIA for health and medical data processing covering Art.

    301 GitHub stars~2.4k tokensUpdated 6 mo ago
    Legal & ComplianceAuto-check passed
  • Healthcare AI Privacy

    mukul975/Privacy-Data-Protection-Skills

    Addresses healthcare AI privacy at the intersection of HIPAA and the EU AI Act for clinical decision support systems.

    301 GitHub stars~4.4k tokensUpdated 6 mo ago
    Legal & ComplianceAuto-check passed

More from aipoch/medical-research-skills

All 578 skills in this repo
  • Academic Poster Generator

    aipoch/medical-research-skills

    Complete workflow for generating academic research posters from PDF literature; use when you need to extract paper content from PDFs and produce a LaTeX-based poster…

    1.9k GitHub stars~2.2k tokensUpdated 24 days ago
    Auto-check passed
  • Diagnostic Study Quality Assessment Quadas

    aipoch/medical-research-skills

    Analyzes clinical diagnostic accuracy studies for bias using the QUADAS-2 tool.

    1.9k GitHub stars~1.4k tokensUpdated 24 days ago
    Auto-check passed
  • Exploratory Data Analysis

    aipoch/medical-research-skills

    Perform comprehensive exploratory data analysis on scientific data files across 200+ file formats.

    1.9k GitHub stars~3.7k tokensUpdated 24 days ago
    Auto-check passed
  • Iso Certification

    aipoch/medical-research-skills

    A toolkit for preparing ISO 13485:2016 certification documentation for medical device QMS.

    1.9k GitHub stars~1.8k tokensUpdated 24 days ago
    Auto-check passed
  • Journal Skills

    aipoch/medical-research-skills

    Recommends target journals for manuscript submission by analyzing the paper topic/abstract and the journal distribution of similar PubMed literature; use when users ask for journal…

    1.9k GitHub stars~1.7k tokensUpdated 24 days ago
    Auto-check passed
  • Latex Posters

    aipoch/medical-research-skills

    Creates academic-poster writing packages for LaTeX using beamerposter, tikzposter, or baposter.

    1.9k GitHub stars~1.3k tokensUpdated 24 days ago
    Auto-check passed

Works with

Questions about Hipaa Compliance Auditor

What does Hipaa Compliance Auditor do?

Clinical-grade PII/PHI detection and de-identification for healthcare text data. Hipaa Compliance Auditor is an agent skill from aipoch/medical-research-skills. Clinical-grade PII/PHI detection and de-identification for healthcare text data.

When should I use Hipaa Compliance Auditor?

Hipaa Compliance Auditor fits situations like: tasks that involve Healthcare and finance regulation; tasks that involve Clinical and healthcare research.

How do I install Hipaa Compliance Auditor in Claude Code?

Run `npx skills add aipoch/medical-research-skills --skill hipaa-compliance-auditor -a claude-code`. Or copy the skill folder (scientific-skills/Academic Writing/hipaa-compliance-auditor in aipoch/medical-research-skills) into .claude/skills/hipaa-compliance-auditor in your project. Claude Code loads it when a task matches its description.

How do I install Hipaa Compliance Auditor in Codex?

Run `npx skills add aipoch/medical-research-skills --skill hipaa-compliance-auditor -a codex`. Or copy the skill folder (scientific-skills/Academic Writing/hipaa-compliance-auditor in aipoch/medical-research-skills) into .agents/skills/hipaa-compliance-auditor in your project. Codex loads it when a task matches its description.

Can I use Hipaa Compliance Auditor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aipoch/medical-research-skills --skill hipaa-compliance-auditor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hipaa-compliance-auditor, .gemini/skills/hipaa-compliance-auditor, .github/skills/hipaa-compliance-auditor and .opencode/skills/hipaa-compliance-auditor in your project.

What does Hipaa Compliance Auditor need to run?

Going by SKILL.md and its folder, Hipaa Compliance Auditor needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Hipaa Compliance Auditor access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hipaa Compliance Auditor safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Hipaa Compliance Auditor use?

Hipaa Compliance Auditor is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hipaa Compliance Auditor use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.8k tokens, read only when the agent opens those files.

What are the alternatives to Hipaa Compliance Auditor?

Skills that share tags, products or a category with Hipaa Compliance Auditor: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Clinical Reports (davila7/claude-code-templates, 33k stars), Shifting Clinical Dates (maziyarpanahi/openmed, 5.5k stars) and Healthtech Advisor (borghei/Claude-Skills, 891 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hipaa Compliance Auditor?

aipoch (a GitHub organization) maintains it in aipoch/medical-research-skills, which has 1,937 GitHub stars. The repository holds 578 skills in this directory. The repository was last updated on September 17, 2026.

Source: aipoch/medical-research-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.