Agent skill

Hipaa Safeguards

by mohitagw15856 in mohitagw15856/pm-claude-skills

Map HIPAA Security Rule safeguards and run a risk analysis for systems handling PHI.

MITAuto-check passedLegal & Compliance

Install Hipaa Safeguards

skills CLI
$ npx skills add mohitagw15856/pm-claude-skills --skill hipaa-safeguards -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mohitagw15856/pm-claude-skills hipaa-safeguards --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mohitagw15856/pm-claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hipaa-safeguards .claude/skills/hipaa-safeguards && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hipaa-safeguards
GitHub stars
1.4k
Token cost
~1k tokens
SKILL.md length
469 words
Files
2 (incl. scripts)
Skills in repo
1,348
Repo updated
First seen
Licence
MIT

At a glance

Map HIPAA Security Rule safeguards and run a risk analysis for systems handling PHI.

  • Asked to become HIPAA-compliant
  • SKILL.md covers Required Inputs, Output Format, Programmatic Helper and Quality Checks, plus 3 more sections
  • Runs Python scripts from its folder; calls python3
  • Assess HIPAA safeguards

What it does

Hipaa Safeguards is an agent skill from mohitagw15856/pm-claude-skills. Map HIPAA Security Rule safeguards and run a risk analysis for systems handling PHI. Use when asked to become HIPAA-compliant, assess HIPAA safeguards, prepare for handling PHI/ePHI, or scope a BAA. Produces a HIPAA assessment — the administrative/physical/technical safeguards with required-vs-addressable status, a risk analysis, BAA scope, and a prioritised remediation plan.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts (for example `scripts/hipaa_checklist.py`).

It sits in Legal & Compliance, covering Healthcare and finance regulation. The repository describes itself as: 1255 professional Agent Skills for Claude, ChatGPT, Gemini, Cursor & Codex — PRDs, postmortems, leases, medical bills, layoffs, go-bags, new countries. Plain markdown, MIT, in… The licence is MIT.

When your agent uses it

  • Asked to become HIPAA-compliant
  • Assess HIPAA safeguards
  • Prepare for handling PHI/ePHI

Example prompts

  • “/hipaa-safeguards”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 1cbf1f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hipaa Safeguards loads about 1k tokens when it runs. Until then it costs about 99 tokens; SKILL.md has 469 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~99
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mohitagw15856/pm-claude-skills at commit 1cbf1f0, republished under its MIT licence (© mohitagw15856). 469 words, ~1,048 tokens.

Download SKILL.mdSave it as .claude/skills/hipaa-safeguards/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
hipaa-safeguards
description
Map HIPAA Security Rule safeguards and run a risk analysis for systems handling PHI. Use when asked to become HIPAA-compliant, assess HIPAA safeguards, prepare for handling PHI/ePHI, or scope a BAA. Produces a HIPAA assessment — the administrative/physical/technical safeguards with required-vs-addressable status, a risk analysis, BAA scope, and a prioritised remediation plan.

HIPAA Safeguards Skill

HIPAA's Security Rule is a list of safeguards for electronic protected health information (ePHI), split into administrative, physical, and technical — some required, some addressable (you must do them or document why an equivalent is reasonable). This skill maps your controls to that list, runs the risk analysis HIPAA mandates, and flags where you're exposed — so handling PHI is defensible, not hopeful.

Required Inputs

Ask for these only if they aren't already provided:

  • Your role — covered entity, or business associate (a vendor handling PHI for one). Both owe Security Rule safeguards.
  • The ePHI flow — where PHI is created, received, stored, transmitted, and who can access it.
  • Current safeguards — what's in place for access control, encryption, audit logging, backups, training.
  • Business associates — third parties touching PHI (each needs a BAA).

Output Format

HIPAA Assessment: [entity] ([covered entity / business associate])

1. ePHI inventory & flow — where PHI lives and moves; the systems in scope.

2. Safeguards — a table per category; status met / partial / gap, and required vs. addressable:

CategorySafeguardReq/AddrStatusNotes
TechnicalEncryption of ePHI at rest & in transitAddressablepartialTLS yes; disk encryption pending
AdministrativeSecurity risk analysisRequiredgapNot yet performed
PhysicalFacility access controlsRequiredmet

3. Risk analysis — the required (§164.308(a)(1)) assessment: threats to ePHI, likelihood × impact, and the residual risk after controls. This is the control auditors check first and the one most often missing.

4. BAA scope — which business associates need a Business Associate Agreement, and what each must guarantee.

5. Remediation — prioritised gaps (required-and-gap first), owners, dates. For addressable items not implemented, the documented justification + alternative.

Programmatic Helper

scripts/hipaa_checklist.py (stdlib only) scores safeguard coverage and surfaces unmet required safeguards (the ones with no "addressable" escape hatch):

bash
# safeguards.json: [{"category":"Technical","safeguard":"...","required":true,"status":"met|partial|gap"}, ...]
python3 scripts/hipaa_checklist.py safeguards.json
python3 scripts/hipaa_checklist.py safeguards.json --json
Show full SKILL.md (183 more words)Show less

Quality Checks

  • A documented security risk analysis exists (or is the top remediation item) — it's required and foundational
  • Each safeguard is marked required vs. addressable, and addressable-not-done items have a written justification + alternative
  • Encryption of ePHI in transit and at rest is assessed explicitly
  • Every business associate has (or is flagged as needing) a BAA
  • Audit logging / access review for PHI access is covered

Anti-Patterns

  • Do not treat "addressable" as "optional" — you must implement it or document why an equivalent is reasonable; silence is a violation
  • Do not skip the risk analysis — it's explicitly required and the most-cited gap in OCR enforcement
  • Do not handle PHI through a vendor without a BAA — that alone is a breach
  • Do not present this as legal certification — flag that compliance counsel / a security assessor must validate, especially the risk analysis
  • Do not conflate HIPAA with SOC 2 or GDPR — overlapping controls, different legal requirements; map each separately

Based On

HIPAA Security Rule (45 CFR §164.308–312) — administrative, physical, and technical safeguards + required risk analysis.

Example Trigger Phrases

  • "Assess HIPAA safeguards."
  • "Prepare for handling PHI/ePHI."
  • "Scope a BAA."

© mohitagw15856, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in skills/hipaa-safeguards of mohitagw15856/pm-claude-skills.

  • SKILL.md
  • scripts/hipaa_checklist.py

Open the folder on GitHubat commit 1cbf1f0

Compare with similar skills

Hipaa Safeguards next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hipaa Safeguards compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hipaa Safeguards this skillmohitagw15856/pm-claude-skills1.4k—~1kAutomated safety check: PassMIT
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
HIPAA Pre-Deployment Compliance Checkmaziyarpanahi/openmed5.5k—~2kAutomated safety check: PassApache-2.0
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT
ISO Standards Readiness EvidenceK-Dense-AI/scientific-agent-skills48k1 repos~4.6kAutomated safety check: NotesMIT
Fda Consultant Specialistdavila7/claude-code-templates33k1 repos~2.7kAutomated safety check: PassMIT

Similar skills

  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Walks a data pipeline against the HIPAA Privacy and Security Rule checklist and produces a gap report before it processes patient data.

    5.5k GitHub stars~2k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • ISO Standards Readiness Evidence

    K-Dense-AI/scientific-agent-skills

    Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.

    48k GitHub starsUsed in 1 repo~4.6k tokens
    Legal & ComplianceAuto-check: notes
  • Fda Consultant Specialist

    davila7/claude-code-templates

    Senior FDA consultant and specialist for medical device companies including HIPAA compliance and requirement management.

    33k GitHub starsUsed in 1 repo~2.7k tokens
    Legal & ComplianceAuto-check passed
  • Grc Knowledge

    mlunato47/claude-grc-plugin

    Senior GRC analyst expertise across 18 compliance frameworks — NIST 800-53, FedRAMP (Rev5 + 20x/CR26, KSIs, VDR/VER, Certification Classes A–D), DoD/DoW Impact Levels (IL2–IL6, DISA Cloud SRG), ITAR…

    184 GitHub stars~6.1k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed

More from mohitagw15856/pm-claude-skills

All 1,348 skills in this repo
  • Car Tco

    mohitagw15856/pm-claude-skills

    Compare the total cost of car ownership across buy-new, buy-used, lease, and keep-your-current-car — depreciation, insurance, maintenance ramp, and fuel over a real horizon, not just the monthly…

    1.4k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Cs Health Scorecard

    mohitagw15856/pm-claude-skills

    Build a customer health scorecard for a specific account. An agent skill from mohitagw15856/pm-claude-skills.

    1.4k GitHub stars~2.4k tokensUpdated 2 days ago
    Auto-check passed
  • Exit Waterfall

    mohitagw15856/pm-claude-skills

    Compute who gets what at each exit price from a cap table — liquidation preferences, conversion points, and where the founders' share collapses.

    1.4k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Feature Prioritisation

    mohitagw15856/pm-claude-skills

    Apply prioritisation frameworks (RICE, MoSCoW, Kano, ICE, Opportunity Scoring) to rank features and backlog items.

    1.4k GitHub stars~2k tokensUpdated 2 days ago
    Auto-check passed
  • Fire Number

    mohitagw15856/pm-claude-skills

    Compute a financial-independence (FIRE) target and years-to-reach with every assumption labeled as an assumption — plus a sensitivity table instead of a single false-precision answer.

    1.4k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Freelance Rate

    mohitagw15856/pm-claude-skills

    Derive a freelance day/hourly rate backwards from target income, honest billable utilization, overhead, and the self-employment tax premium — the arithmetic that proves a rate is not salary÷2000.

    1.4k GitHub stars~1.2k tokensUpdated 2 days ago
    Auto-check passed

Questions about Hipaa Safeguards

What does Hipaa Safeguards do?

Map HIPAA Security Rule safeguards and run a risk analysis for systems handling PHI. Hipaa Safeguards is an agent skill from mohitagw15856/pm-claude-skills. Map HIPAA Security Rule safeguards and run a risk analysis for systems handling PHI.

When should I use Hipaa Safeguards?

Hipaa Safeguards fits situations like: asked to become HIPAA-compliant; assess HIPAA safeguards; prepare for handling PHI/ePHI.

How do I install Hipaa Safeguards in Claude Code?

Run `npx skills add mohitagw15856/pm-claude-skills --skill hipaa-safeguards -a claude-code`. Or copy the skill folder (skills/hipaa-safeguards in mohitagw15856/pm-claude-skills) into .claude/skills/hipaa-safeguards in your project. Claude Code loads it when a task matches its description.

How do I install Hipaa Safeguards in Codex?

Run `npx skills add mohitagw15856/pm-claude-skills --skill hipaa-safeguards -a codex`. Or copy the skill folder (skills/hipaa-safeguards in mohitagw15856/pm-claude-skills) into .agents/skills/hipaa-safeguards in your project. Codex loads it when a task matches its description.

Can I use Hipaa Safeguards in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mohitagw15856/pm-claude-skills --skill hipaa-safeguards -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hipaa-safeguards, .gemini/skills/hipaa-safeguards, .github/skills/hipaa-safeguards and .opencode/skills/hipaa-safeguards in your project.

What does Hipaa Safeguards need to run?

Going by SKILL.md and its folder, Hipaa Safeguards needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Hipaa Safeguards access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hipaa Safeguards safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Hipaa Safeguards use?

Hipaa Safeguards is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hipaa Safeguards use?

About 1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hipaa Safeguards?

Skills that share tags, products or a category with Hipaa Safeguards: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), HIPAA Pre-Deployment Compliance Check (maziyarpanahi/openmed, 5.5k stars), Hipaa Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars) and ISO Standards Readiness Evidence (K-Dense-AI/scientific-agent-skills, 48k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hipaa Safeguards?

mohitagw15856 (a GitHub user) maintains it in mohitagw15856/pm-claude-skills, which has 1,434 GitHub stars. The repository holds 1,348 skills in this directory. The repository was last updated on October 9, 2026.

Source: mohitagw15856/pm-claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.