Agent skill

HIPAA Safe Harbor Coverage Audit

by maziyarpanahi in maziyarpanahi/openmed

Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

Apache-2.0Auto-check passedLegal & Compliance

Install HIPAA Safe Harbor Coverage Audit

skills CLI
$ npx skills add maziyarpanahi/openmed --skill auditing-safe-harbor-checklist -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install maziyarpanahi/openmed auditing-safe-harbor-checklist --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/auditing-safe-harbor-checklist .claude/skills/auditing-safe-harbor-checklist && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
auditing-safe-harbor-checklist
GitHub stars
5.5k
Token cost
~1.7k tokens
SKILL.md length
574 words
Files
2 (incl. references)
Skills in repo
74
Repo updated
First seen
Licence
Apache-2.0

At a glance

Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

  • Works in 5 steps: De-identify with a Safe Harbor profile → Map detected spans to the 18 classes via… → Walk the checklist in → …
  • Confirming a de-identified note meets HIPAA Safe Harbor before release
  • SKILL.md covers When to use this skill, Quick start: coverage check, Workflow and Hand-off to / from OpenMed, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Safe Harbor (45 CFR 164.514(b)(2)) requires removing 18 identifier categories and having no actual knowledge that what remains could identify anyone. The skill turns that checklist into a coverage check: de-identify the note with the `hipaa_safe_harbor` policy of `openmed.deidentify`, map detected spans to the 18 classes using `LABEL_TO_HIPAA`, and build a table of category, detected or not, and action taken.

The agent then walks the cross-walk in `references/safe-harbor-identifiers.md` and flags known gaps: ages over 89 must be aggregated to 90+ and are flagged but not capped, dates keep only the year, ZIP codes beyond the first three digits and small areas are masked, rare geography or characteristics can still re-identify, fax shares the phone label, and biometrics and full-face photos fall outside text processing. A category that was not observed is not proof it is absent, which is why a human review step follows.

When your agent uses it

  • Confirming a de-identified note meets HIPAA Safe Harbor before release
  • Mapping detected entities to the 18 identifier categories
  • Flagging gaps such as ages over 89, rare locations or fax numbers
  • Deciding whether Safe Harbor is achievable for a given text

Example prompts

  • “Run a Safe Harbor coverage check on the de-identified discharge note in ./notes/discharge.txt.”
  • “List which of the 18 HIPAA identifier categories our masking missed in this report.”
  • “Check this note for ages over 89 and rare geography that could still identify the patient.”

Requirements

  • Python with the `openmed` package

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. De-identify with a Safe Harbor profile
  2. Map detected spans to the 18 classes via LABEL_TO_HIPAA (as above).
  3. Walk the checklist in
  4. Assess residual risk. Run audit=True and read residual_risk
  5. Record the "no actual knowledge" judgment. A human must sign off that the

What it can do on your machine

Read from SKILL.md and the folder at commit 34d7b8c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • ecfr.gov
    • hhs.gov

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

HIPAA Safe Harbor Coverage Audit loads about 1.7k tokens when it runs, and up to ~3k if it reads all its reference files. Until then it costs about 159 tokens; SKILL.md has 574 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~159
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from maziyarpanahi/openmed at commit 34d7b8c, republished under its Apache-2.0 licence (© maziyarpanahi). 574 words, ~1,658 tokens.

Download SKILL.mdSave it as .claude/skills/auditing-safe-harbor-checklist/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
auditing-safe-harbor-checklist
description
Verify OpenMed de-identified output against all 18 HIPAA Safe Harbor identifier categories and report residual re-identification risk. Use when the user must confirm a note meets HIPAA Safe Harbor (45 CFR 164.514(b)(2)), needs a coverage checklist mapping detected entities to the 18 categories, wants to flag gaps like ages over 89, rare geography, fax vs phone, or biometrics, or asks whether masking was complete. Maps OpenMed CANONICAL_LABELS to the 18 HIPAA classes and uses extract_pii / deidentify to check coverage. Pairs with OpenMed deidentifying-clinical-text and auditing-deidentification-runs.
license
Apache-2.0
metadata.project
OpenMed
metadata.category
de-identification
metadata.pairs
after
metadata.version
1.0

Auditing against the HIPAA Safe Harbor checklist

The Safe Harbor method (45 CFR 164.514(b)(2)) de-identifies PHI by removing 18 specific identifier categories for the individual and their relatives, employers, and household members — and requires the covered entity to have no actual knowledge that the remainder could re-identify anyone. This skill turns that legal checklist into a concrete coverage check over OpenMed output: which of the 18 categories were detected and handled, and where the gaps are.

The full mapping table lives in references/safe-harbor-identifiers.md — all 18 categories, their OpenMed HIPAA class, the matching CANONICAL_LABELS, and per-category cautions. Read it when you need the authoritative cross-walk.

When to use this skill

Use it after a de-identification run to prove coverage, or before release to decide whether Safe Harbor is even achievable for this text. If the user needs a signed, retained record of the run, hand off to auditing-deidentification-runs.

Quick start: coverage check

python
import openmed
from openmed.core.labels import LABEL_TO_HIPAA, HIPAA_SAFE_HARBOR_CLASSES

note = (
    "Patient John Doe (MRN 1234567), age 92, of Smalltown, seen 2024-03-02. "
    "SSN 123-45-6789, phone 617-555-0142."
)

# 1) Detect identifiers (spans only; no rewrite).
detected = openmed.extract_pii(note)

# 2) Roll each detected span up to its HIPAA Safe Harbor class.
covered = set()
for ent in detected.entities:
    canonical = openmed.normalize_label(ent.label)        # -> CANONICAL_LABELS form
    hipaa_class = LABEL_TO_HIPAA.get(canonical)            # -> one of 18 classes
    if hipaa_class:
        covered.add(hipaa_class)

# 3) Report which of the 18 classes were touched and which weren't observed.
missing = sorted(HIPAA_SAFE_HARBOR_CLASSES - covered)
print("covered:", sorted(covered))
print("not observed in this note:", missing)

"Not observed" is not the same as "absent" — a category may simply not occur in this note, or may have been missed. That is exactly what the human review step (below) is for.

Workflow

  1. De-identify with a Safe Harbor profile: openmed.deidentify(note, policy="hipaa_safe_harbor"). This masks every identifier class by default and runs the mandatory structured-ID safety sweep.
  2. Map detected spans to the 18 classes via LABEL_TO_HIPAA (as above). Build a table of category → detected? → action taken.
  3. Walk the checklist in references/safe-harbor-identifiers.md and flag the known gaps explicitly:
    • Ages > 89 (AGE) must be aggregated to "90+"; OpenMed flags but does not auto-cap — see shifting-clinical-dates.
    • Dates keep only the year; everything else (admit/discharge/DOB) goes.
    • ZIP beyond the first 3 digits, and small-population areas → mask whole.
    • Rare geography (small towns) and rare characteristics (unusual occupation) can re-identify even when masked field-by-field.
    • Fax shares the PHONE label; biometrics and full-face photos are out of scope for text — handle in the imaging/intake pipeline.
  4. Assess residual risk. Run audit=True and read residual_risk (auditing-deidentification-runs). Non-zero projected leakage → review.
  5. Record the "no actual knowledge" judgment. A human must sign off that the remaining text cannot re-identify the individual. Automated coverage is necessary, not sufficient.
Show full SKILL.md (223 more words)Show less

Hand-off to / from OpenMed

  • Detect / de-id: openmed.extract_pii (spans) and openmed.deidentify (rewrite) — see deidentifying-clinical-text.
  • Label mapping: openmed.CANONICAL_LABELS, openmed.normalize_label, and LABEL_TO_HIPAA / HIPAA_SAFE_HARBOR_CLASSES in openmed/core/labels.py.
  • Signed record + residual risk: auditing-deidentification-runs (audit=True → AuditReport.residual_risk).
  • Profile choice: configuring-privacy-policies — if you must keep dates or geography, Safe Harbor fails; use Expert Determination (hipaa_expert_review_assist) or a Limited Data Set (research_limited_dataset).

Edge cases & gotchas

  • Coverage ≠ compliance. Detecting all 18 categories does not satisfy Safe Harbor on its own — the "no actual knowledge" residual-risk judgment is required and is a human decision.
  • Ages over 89 are a transformation, not a detection. Masking the digits is fine; if you keep age, aggregate to "90+". OpenMed will not cap automatically.
  • ZIP / date rules are transformations. Safe Harbor permits keeping 3-digit ZIP (population-gated) and the year — implement the truncation; do not assume detection handles it.
  • Some categories have no text label (biometrics, full-face photos). Mark them N/A for text and ensure another pipeline stage covers them.
  • Combination re-identification. Several non-identifying quasi-identifiers together (rare diagnosis + small town + outlier age) can identify someone; this is precisely why strict_no_leak exists for high-stakes data.
  • No raw PHI in the checklist output — report categories, counts, offsets, and hashes, never the underlying identifiers.

Standards & references

© maziyarpanahi, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/auditing-safe-harbor-checklist of maziyarpanahi/openmed.

  • SKILL.md
  • references/safe-harbor-identifiers.md

Open the folder on GitHubat commit 34d7b8c

Compare with similar skills

HIPAA Safe Harbor Coverage Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

HIPAA Safe Harbor Coverage Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
HIPAA Safe Harbor Coverage Audit this skillmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Compliance Osalirezarezvani/claude-skills28k—~3.3kAutomated safety check: PassMIT
Implementing Complianceancoleman/ai-design-components525—~4kAutomated safety check: PassMIT
Compliance Checklistmohitagw15856/pm-claude-skills1.4k—~1.2kAutomated safety check: PassMIT
Compliance Checklist Generationseb1n/awesome-ai-agent-skills206—~2.5kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • Compliance Os

    alirezarezvani/claude-skills

    Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across…

    28k GitHub stars~3.3k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Implementing Compliance

    ancoleman/ai-design-components

    Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.

    525 GitHub stars~4k tokensUpdated 10 mo ago
    Legal & ComplianceAuto-check passed
  • Compliance Checklist

    mohitagw15856/pm-claude-skills

    Generate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis.

    1.4k GitHub stars~1.2k tokensUpdated 2 days ago
    Legal & ComplianceAuto-check passed
  • Compliance Checklist Generation

    seb1n/awesome-ai-agent-skills

    Build evidence-oriented readiness checklists for frameworks such as SOC 2, HIPAA, PCI DSS, and GDPR, with gaps and remediation priorities.

    206 GitHub stars~2.5k tokensUpdated 2 mo ago
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • ISO Standards Readiness Evidence

    K-Dense-AI/scientific-agent-skills

    Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.

    48k GitHub starsUsed in 1 repo~4.6k tokens
    Legal & ComplianceAuto-check: notes

More from maziyarpanahi/openmed

All 74 skills in this repo
  • OpenMed Model Card Writer

    maziyarpanahi/openmed

    Fills in a model card for an OpenMed clinical NER or de-identification model from its evaluation reports: intended use, metrics, subgroups and limitations.

    5.5k GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Walks a data pipeline against the HIPAA Privacy and Security Rule checklist and produces a gap report before it processes patient data.

    5.5k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • ICD-10 Coding Assistant

    maziyarpanahi/openmed

    Suggests candidate ICD-10-CM diagnosis and ICD-10-PCS procedure codes for clinical text extracted by OpenMed, with rationale for a certified coder to review.

    5.5k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • OpenMed ETL to OMOP CDM

    maziyarpanahi/openmed

    Maps OpenMed-extracted, terminology-coded conditions, drugs and measurements into OMOP CDM v5.4 tables for OHDSI and ATLAS analytics.

    5.5k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Extracting SDOH and Z-Codes

    maziyarpanahi/openmed

    Finds social risks such as housing instability or food insecurity in clinical notes and proposes matching ICD-10-CM Z-codes for a coder to confirm.

    5.5k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Clinical Document Ingestion

    maziyarpanahi/openmed

    Converts scanned faxes, images, CSV/TSV exports and C-CDA XML into clean text on-device, ready for OpenMed de-identification and named-entity recognition.

    5.5k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Questions about HIPAA Safe Harbor Coverage Audit

What does HIPAA Safe Harbor Coverage Audit do?

Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk. 514(b)(2)) requires removing 18 identifier categories and having no actual knowledge that what remains could identify anyone.deidentify`, map detected spans to the 18 classes using `LABEL_TO_HIPAA`, and build a table of category, detected or not, and action taken.

When should I use HIPAA Safe Harbor Coverage Audit?

HIPAA Safe Harbor Coverage Audit fits situations like: confirming a de-identified note meets HIPAA Safe Harbor before release; mapping detected entities to the 18 identifier categories; flagging gaps such as ages over 89, rare locations or fax numbers; deciding whether Safe Harbor is achievable for a given text.

How do I install HIPAA Safe Harbor Coverage Audit in Claude Code?

Run `npx skills add maziyarpanahi/openmed --skill auditing-safe-harbor-checklist -a claude-code`. Or copy the skill folder (skills/auditing-safe-harbor-checklist in maziyarpanahi/openmed) into .claude/skills/auditing-safe-harbor-checklist in your project. Claude Code loads it when a task matches its description.

How do I install HIPAA Safe Harbor Coverage Audit in Codex?

Run `npx skills add maziyarpanahi/openmed --skill auditing-safe-harbor-checklist -a codex`. Or copy the skill folder (skills/auditing-safe-harbor-checklist in maziyarpanahi/openmed) into .agents/skills/auditing-safe-harbor-checklist in your project. Codex loads it when a task matches its description.

Can I use HIPAA Safe Harbor Coverage Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add maziyarpanahi/openmed --skill auditing-safe-harbor-checklist -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/auditing-safe-harbor-checklist, .gemini/skills/auditing-safe-harbor-checklist, .github/skills/auditing-safe-harbor-checklist and .opencode/skills/auditing-safe-harbor-checklist in your project.

What does HIPAA Safe Harbor Coverage Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: HIPAA Safe Harbor Coverage Audit is instructions for the agent only. Our summary lists: Python with the `openmed` package.

Does HIPAA Safe Harbor Coverage Audit access the network?

SKILL.md names 2 domains. As links in the text: ecfr.gov and hhs.gov. This is read from the text; nothing was executed.

Is HIPAA Safe Harbor Coverage Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does HIPAA Safe Harbor Coverage Audit use?

HIPAA Safe Harbor Coverage Audit is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does HIPAA Safe Harbor Coverage Audit use?

About 1.7k tokens (SKILL.md is roughly 6.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.3k tokens, read only when the agent opens those files.

What are the alternatives to HIPAA Safe Harbor Coverage Audit?

Skills that share tags, products or a category with HIPAA Safe Harbor Coverage Audit: Compliance Os (alirezarezvani/claude-skills, 28k stars), Implementing Compliance (ancoleman/ai-design-components, 525 stars), Compliance Checklist (mohitagw15856/pm-claude-skills, 1.4k stars) and Compliance Checklist Generation (seb1n/awesome-ai-agent-skills, 206 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains HIPAA Safe Harbor Coverage Audit?

maziyarpanahi (a GitHub user) maintains it in maziyarpanahi/openmed, which has 5,506 GitHub stars. The repository holds 74 skills in this directory. The repository was last updated on October 11, 2026.

Source: maziyarpanahi/openmed on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.