Hipaa Compliance
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
Run expert-determination-style quasi-identifier risk scoring (k-anonymity, l-diversity) plus OpenMed's empirical re-identification attack on a de-identified dataset, then document residual risk in a…
$ npx skills add maziyarpanahi/openmed --skill reviewing-reidentification-risk -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install maziyarpanahi/openmed reviewing-reidentification-risk --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/reviewing-reidentification-risk .claude/skills/reviewing-reidentification-risk && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "reviewing-reidentification-risk" agent skill from https://github.com/maziyarpanahi/openmed/tree/master/skills/reviewing-reidentification-risk into .claude/skills/reviewing-reidentification-risk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reviewing-reidentification-risk", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/maziyarpanahi/openmed/tree/master/skills/reviewing-reidentification-riskType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add maziyarpanahi/openmed --skill reviewing-reidentification-risk -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install maziyarpanahi/openmed reviewing-reidentification-risk --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/reviewing-reidentification-risk .agents/skills/reviewing-reidentification-risk && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "reviewing-reidentification-risk" agent skill from https://github.com/maziyarpanahi/openmed/tree/master/skills/reviewing-reidentification-risk into .agents/skills/reviewing-reidentification-risk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reviewing-reidentification-risk", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add maziyarpanahi/openmed --skill reviewing-reidentification-risk -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install maziyarpanahi/openmed reviewing-reidentification-risk --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/reviewing-reidentification-risk .cursor/skills/reviewing-reidentification-risk && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "reviewing-reidentification-risk" agent skill from https://github.com/maziyarpanahi/openmed/tree/master/skills/reviewing-reidentification-risk into .cursor/skills/reviewing-reidentification-risk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reviewing-reidentification-risk", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/maziyarpanahi/openmed.git --path skills/reviewing-reidentification-risk--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add maziyarpanahi/openmed --skill reviewing-reidentification-risk -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install maziyarpanahi/openmed reviewing-reidentification-risk --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/reviewing-reidentification-risk .gemini/skills/reviewing-reidentification-risk && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "reviewing-reidentification-risk" agent skill from https://github.com/maziyarpanahi/openmed/tree/master/skills/reviewing-reidentification-risk into .gemini/skills/reviewing-reidentification-risk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reviewing-reidentification-risk", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install maziyarpanahi/openmed reviewing-reidentification-riskInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add maziyarpanahi/openmed --skill reviewing-reidentification-risk -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/reviewing-reidentification-risk .github/skills/reviewing-reidentification-risk && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "reviewing-reidentification-risk" agent skill from https://github.com/maziyarpanahi/openmed/tree/master/skills/reviewing-reidentification-risk into .github/skills/reviewing-reidentification-risk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reviewing-reidentification-risk", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add maziyarpanahi/openmed --skill reviewing-reidentification-risk -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install maziyarpanahi/openmed reviewing-reidentification-risk --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/maziyarpanahi/openmed.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/reviewing-reidentification-risk .opencode/skills/reviewing-reidentification-risk && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "reviewing-reidentification-risk" agent skill from https://github.com/maziyarpanahi/openmed/tree/master/skills/reviewing-reidentification-risk into .opencode/skills/reviewing-reidentification-risk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reviewing-reidentification-risk", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
reviewing-reidentification-riskRun expert-determination-style quasi-identifier risk scoring (k-anonymity, l-diversity) plus OpenMed's empirical re-identification attack on a de-identified dataset, then document residual risk in a…
Reviewing Reidentification Risk is an agent skill from maziyarpanahi/openmed. Run expert-determination-style quasi-identifier risk scoring (k-anonymity, l-diversity) plus OpenMed's empirical re-identification attack on a de-identified dataset, then document residual risk in a defensible memo. Use when the user needs HIPAA Expert Determination (45 CFR 164.514(b)(1)) support, asks whether a dataset is safe to release, worries about singling-out via age/ZIP/dates, or wants a statistical "very small risk" determination. Covers identifying quasi-identifiers, computing k-anonymity / l-diversity…
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Legal & Compliance, covering Healthcare and finance regulation. The repository describes itself as: Local-first healthcare AI: clinical NER and HIPAA PII de-identification on hardware you control. 2,200+ medical models, 35 model-backed PII languages, and Python, MLX, Android… The licence is Apache-2.0.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 34d7b8c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are python).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
hhs.govdataprivacylab.orgdl.acm.orgcsrc.nist.govFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Reviewing Reidentification Risk loads about 1.9k tokens when it runs. Until then it costs about 186 tokens; SKILL.md has 683 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from maziyarpanahi/openmed at commit 34d7b8c, republished under its Apache-2.0 licence (© maziyarpanahi). 683 words, ~1,910 tokens.
.claude/skills/reviewing-reidentification-risk/SKILL.md (or your agent's skills folder).Removing direct identifiers is not enough. A record stripped of name, SSN, and MRN can still be singled out by a combination of quasi-identifiers — age, ZIP/region, admission date, sex, rare diagnosis. The HIPAA Expert Determination pathway (45 CFR 164.514(b)(1)) requires a qualified person to apply statistical methods and document that the risk of re-identification is "very small." This skill produces that evidence: quasi-identifier risk metrics (k-anonymity, l-diversity) plus OpenMed's empirical re-identification attack, written up as a residual-risk memo.
auditing-deid-leakage (no leaks) and
you must decide whether the dataset is releasable.from openmed.eval.attacks.reid import run_reid_attack, run_reid_benchmark
# Synthetic de-identified records; each row is the released, de-id'd data.
deidentified = [
{"record_id": "r1", "text": "[NAME], 47F, ZIP 021xx, admitted 2024-03."},
{"record_id": "r2", "text": "[NAME], 47F, ZIP 021xx, admitted 2024-03."},
{"record_id": "r3", "text": "[NAME], 88M, ZIP 597xx, admitted 2024-03."}, # singleton
]
# Auxiliary = what an attacker might already hold (e.g. a voter list).
auxiliary = [{"record_id": "v9", "text": "88M ZIP 597xx"}]
result = run_reid_attack(
fixtures=[], # bring your own records below
deidentified_records=deidentified,
auxiliary_records=auxiliary,
)
metric = result.to_metric()
print(metric["aux_linkage_rate"], # empirical linkage success
metric["k_min"], # smallest equivalence-class size
metric["singleton_count"], # k=1 records (uniquely identifiable)
metric["quasi_identifier_count"])k_min is the population k-anonymity floor across the dataset; a k_min of 1
means at least one record is unique on its quasi-identifiers and is the highest
re-identification risk. aux_linkage_rate is the empirical attack: how often the
adversary's auxiliary data successfully links back to a released record.
To run against the bundled golden suite and emit a leaderboard-style report:
report = run_reid_benchmark(
suite="golden",
deidentified_records=deidentified,
auxiliary_records=auxiliary,
output_markdown="reid_risk.md",
)auditing-deid-leakage); QIs are what's left to worry about.run_reid_attack returns k_min and
the list of singleton_records (k=1). A common Expert Determination target is
k ≥ a documented threshold (e.g. k ≥ 5 or k ≥ 11) for every record.run_reid_attack / run_reid_benchmark model an
adversary with auxiliary_records and measure actual linkage success
(aux_linkage_rate), residual leakage (leakage_rate), surrogate-consistency
leaks, and date-shift-inversion leaks. Structural metrics bound risk;
the attack demonstrates it.k_min and linkage rate meet your
documented threshold.k_min, l-diversity, the attack's aux_linkage_rate, the assumptions about
attacker capability, and the conclusion that residual risk is "very small."
Cite the metrics — never paste raw records into the memo.auditing-deid-leakage: only score QI risk once direct-identifier
leakage is zero. A leak short-circuits the whole determination.from openmed.eval.attacks.reid import run_reid_attack, run_reid_benchmark, generate_reid_leaderboard. The attack delegates to
openmed.risk.risk_report for k-anonymity / linkage internals.evaluating-with-leakage-gates: register reid_leakage_rate as a gate
in the eval harness so re-identification risk regressions fail CI.pseudonymizing-for-gdpr: pseudonymized output is still re-identifiable
via QIs — run this attack before claiming a dataset is low-risk or anonymized.auxiliary_records you model. Document the assumed attacker
(motivated insider vs. public voter list) — different aux sets, different risk.singleton_count and singleton_records first.date_shift_inversion_rate.
Watch it when de-id used method="shift_dates".© maziyarpanahi, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/reviewing-reidentification-risk of maziyarpanahi/openmed.
Open the folder on GitHubat commit 34d7b8c
Reviewing Reidentification Risk next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Reviewing Reidentification Risk this skillmaziyarpanahi/openmed | 5.5k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | |
| Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~2.3k | Automated safety check: Pass | MIT | |
| ISO Standards Readiness EvidenceK-Dense-AI/scientific-agent-skills | 48k | 1 repos | ~4.6k | Automated safety check: Notes | MIT | |
| Fda Consultant Specialistdavila7/claude-code-templates | 33k | 1 repos | ~2.7k | Automated safety check: Pass | MIT | |
| Grc Knowledgemlunato47/claude-grc-plugin | 184 | — | ~6.1k | Automated safety check: Pass | MIT | |
| Clinical Reportsdavila7/claude-code-templates | 33k | 11 repos | ~9.9k | Automated safety check: Notes | MIT |
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
K-Dense-AI/scientific-agent-skills
Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.
davila7/claude-code-templates
Senior FDA consultant and specialist for medical device companies including HIPAA compliance and requirement management.
mlunato47/claude-grc-plugin
Senior GRC analyst expertise across 18 compliance frameworks — NIST 800-53, FedRAMP (Rev5 + 20x/CR26, KSIs, VDR/VER, Certification Classes A–D), DoD/DoW Impact Levels (IL2–IL6, DISA Cloud SRG), ITAR…
davila7/claude-code-templates
Write comprehensive clinical reports including case reports (CARE guidelines), diagnostic reports (radiology/pathology/lab), clinical trial reports (ICH-E3, SAE, CSR), and patient documentation…
cyberful/cyberful
Audit PCI DSS penetration-test methodology, scope, internal and external reports, segmentation results, tester independence, remediation, retesting, retention, and multi-tenant support evidence.
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
maziyarpanahi/openmed
Fills in a model card for an OpenMed clinical NER or de-identification model from its evaluation reports: intended use, metrics, subgroups and limitations.
maziyarpanahi/openmed
Walks a data pipeline against the HIPAA Privacy and Security Rule checklist and produces a gap report before it processes patient data.
maziyarpanahi/openmed
Suggests candidate ICD-10-CM diagnosis and ICD-10-PCS procedure codes for clinical text extracted by OpenMed, with rationale for a certified coder to review.
maziyarpanahi/openmed
Maps OpenMed-extracted, terminology-coded conditions, drugs and measurements into OMOP CDM v5.4 tables for OHDSI and ATLAS analytics.
maziyarpanahi/openmed
Finds social risks such as housing instability or food insecurity in clinical notes and proposes matching ICD-10-CM Z-codes for a coder to confirm.
Categories
Run expert-determination-style quasi-identifier risk scoring (k-anonymity, l-diversity) plus OpenMed's empirical re-identification attack on a de-identified dataset, then document residual risk in a…. Reviewing Reidentification Risk is an agent skill from maziyarpanahi/openmed. Run expert-determination-style quasi-identifier risk scoring (k-anonymity, l-diversity) plus OpenMed's empirical re-identification attack on a de-identified dataset, then document residual risk in a defensible memo.
Reviewing Reidentification Risk fits situations like: the user needs HIPAA Expert Determination (45 CFR 164.514(b); asks whether a dataset is safe to release; worries about singling-out via age/ZIP/dates; wants a statistical very small risk determination.
Run `npx skills add maziyarpanahi/openmed --skill reviewing-reidentification-risk -a claude-code`. Or copy the skill folder (skills/reviewing-reidentification-risk in maziyarpanahi/openmed) into .claude/skills/reviewing-reidentification-risk in your project. Claude Code loads it when a task matches its description.
Run `npx skills add maziyarpanahi/openmed --skill reviewing-reidentification-risk -a codex`. Or copy the skill folder (skills/reviewing-reidentification-risk in maziyarpanahi/openmed) into .agents/skills/reviewing-reidentification-risk in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add maziyarpanahi/openmed --skill reviewing-reidentification-risk -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/reviewing-reidentification-risk, .gemini/skills/reviewing-reidentification-risk, .github/skills/reviewing-reidentification-risk and .opencode/skills/reviewing-reidentification-risk in your project.
SKILL.md names no scripts, command-line tools or credentials: Reviewing Reidentification Risk is instructions for the agent only. Our summary lists: Python 3.
SKILL.md names 4 domains. As links in the text: hhs.gov, dataprivacylab.org, dl.acm.org and csrc.nist.gov. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Reviewing Reidentification Risk is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Reviewing Reidentification Risk: Hipaa Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), ISO Standards Readiness Evidence (K-Dense-AI/scientific-agent-skills, 48k stars), Fda Consultant Specialist (davila7/claude-code-templates, 33k stars) and Grc Knowledge (mlunato47/claude-grc-plugin, 184 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
maziyarpanahi (a GitHub user) maintains it in maziyarpanahi/openmed, which has 5,506 GitHub stars. The repository holds 74 skills in this directory. The repository was last updated on October 11, 2026.
Source: maziyarpanahi/openmed on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.