HIPAA Safe Harbor Coverage Audit
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
Guides audit findings remediation program management including finding prioritization by severity (critical, high, medium, low), owner assignment, remediation planning, deadline tracking…
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill audit-remediation-program -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills audit-remediation-program --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/audit-remediation-program .claude/skills/audit-remediation-program && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "audit-remediation-program" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/audit-remediation-program into .claude/skills/audit-remediation-program/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-remediation-program", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/audit-remediation-programType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill audit-remediation-program -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills audit-remediation-program --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/audit-remediation-program .agents/skills/audit-remediation-program && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "audit-remediation-program" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/audit-remediation-program into .agents/skills/audit-remediation-program/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-remediation-program", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill audit-remediation-program -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills audit-remediation-program --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/audit-remediation-program .cursor/skills/audit-remediation-program && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "audit-remediation-program" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/audit-remediation-program into .cursor/skills/audit-remediation-program/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-remediation-program", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/audit-remediation-program--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill audit-remediation-program -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills audit-remediation-program --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/audit-remediation-program .gemini/skills/audit-remediation-program && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "audit-remediation-program" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/audit-remediation-program into .gemini/skills/audit-remediation-program/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-remediation-program", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills audit-remediation-programInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill audit-remediation-program -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/audit-remediation-program .github/skills/audit-remediation-program && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "audit-remediation-program" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/audit-remediation-program into .github/skills/audit-remediation-program/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-remediation-program", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill audit-remediation-program -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills audit-remediation-program --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/audit-remediation-program .opencode/skills/audit-remediation-program && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "audit-remediation-program" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/audit-remediation-program into .opencode/skills/audit-remediation-program/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-remediation-program", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
audit-remediation-programGuides audit findings remediation program management including finding prioritization by severity (critical, high, medium, low), owner assignment, remediation planning, deadline tracking…
Audit Remediation Program is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides audit findings remediation program management including finding prioritization by severity (critical, high, medium, low), owner assignment, remediation planning, deadline tracking, verification testing, closure criteria, escalation protocols, and management reporting. Covers remediation lifecycle from finding issuance to verified closure. Keywords: audit remediation, finding management, prioritization, verification testing, closure criteria, remediation tracking.
Its SKILL.md is about 5.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Legal & Compliance, covering Audit readiness, Prioritization frameworks and Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Audit Remediation Program loads about 5.3k tokens when it runs, and up to ~6.6k if it reads all its reference files. Until then it costs about 125 tokens; SKILL.md has 2,012 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 2,012 words, ~5,332 tokens.
.claude/skills/audit-remediation-program/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.An audit findings remediation program ensures that privacy audit findings — whether from internal audits, external audits (SOC 2, ISO 27701), regulatory inspections, or self-assessments — are systematically prioritized, assigned, tracked, remediated, verified, and closed. Without a structured remediation program, findings accumulate as "privacy debt," increasing regulatory risk and undermining the credibility of the privacy program.
The remediation program operates as a closed-loop system: findings enter the pipeline, are triaged and assigned, remediated by control owners, verified by the audit function (or an independent party), and formally closed only when evidence confirms effective remediation. Findings that fail verification are reopened with revised remediation plans and escalated if they become overdue.
Sentinel Compliance Group manages an average of 85 open privacy findings per year across internal audits (47), SOC 2 examinations (12), ISO 27701 audits (8), regulatory inquiries (6), and self-assessment activities (12), with a 91% on-time remediation rate in 2024.
Finding Issued by Audit Source
↓
Finding Registered in Tracking System
↓
Initial Triage (severity classification, regulatory impact)
↓
Owner Assignment (finding owner + remediation owner)
↓
Management Response Due (10 business days)
↓
Remediation Plan Approved
↓
Remediation In Progress
↓
Remediation Owner Reports Completion
↓
Verification Testing by Audit/Independent Party
↓
Pass → Finding Closed with Evidence → Archived
↓
Fail → Finding Reopened → Revised Remediation Plan → Escalation if Overdue| Severity | Criteria | Remediation Deadline | Escalation Timeline |
|---|---|---|---|
| Critical | Systemic regulatory non-compliance; active or imminent data exposure; processing without lawful basis for large-scale activity; complete control failure affecting data subject rights | 30 calendar days | Day 1: CPO + CISO notified; Day 5: CEO notified if no plan; Day 15: Board notified if no progress |
| High | Material non-compliance with specific GDPR article; control design deficiency; widespread operating failure; regulatory inspection finding | 60 calendar days | Day 10: CPO notified if no plan; Day 30: CEO notified if behind schedule; Day 45: Audit Committee notified |
| Medium | Isolated non-compliance; control operating inconsistently; documentation gaps with compliance implications; process improvement needed for compliance | 90 calendar days | Day 30: CPO notified if no plan; Day 60: Escalate to management |
| Low | Minor documentation gaps; best practice deviations; control enhancements; efficiency improvements | 180 calendar days | Day 90: Follow-up notification; Day 150: Escalate to management |
| Advisory | Recommendations for enhancement; emerging risk observations; no current non-compliance identified | No mandatory deadline | Tracked for information; reviewed during next audit cycle |
Beyond severity, findings are prioritized using additional factors:
| Factor | Weight | Scoring (1-5) |
|---|---|---|
| Severity | 40% | 1 = Advisory, 2 = Low, 3 = Medium, 4 = High, 5 = Critical |
| Regulatory Exposure | 20% | 1 = No regulatory linkage, 5 = Direct GDPR article non-compliance with enforcement precedent |
| Data Subject Impact | 15% | 1 = No impact, 5 = Direct harm to data subjects (breach, rights denial) |
| Systemic Risk | 10% | 1 = Isolated occurrence, 5 = Affects multiple processes/systems/locations |
| Recurrence | 10% | 1 = First occurrence, 5 = Finding repeated 3+ times |
| External Visibility | 5% | 1 = Internal only, 5 = Visible to regulators/customers/public |
Priority Score: Weighted sum (maximum 5.0)
| Score Range | Priority Tier | Queue Position |
|---|---|---|
| 4.0 — 5.0 | Tier 1 | Immediate attention; reviewed daily |
| 3.0 — 3.9 | Tier 2 | Active management; reviewed weekly |
| 2.0 — 2.9 | Tier 3 | Standard tracking; reviewed monthly |
| 1.0 — 1.9 | Tier 4 | Periodic tracking; reviewed quarterly |
| Role | Responsibility | Accountability |
|---|---|---|
| Finding Owner | Senior leader accountable for remediation outcomes; typically the department head or VP whose area is affected | Ensures resources, removes blockers, approves remediation plan, accountable for deadline compliance |
| Remediation Owner | Individual responsible for executing the remediation plan; typically a manager or team lead | Develops remediation plan, executes remediation activities, reports progress, provides evidence of completion |
| Verification Owner | Individual responsible for testing that remediation is effective; typically internal audit or an independent party | Designs verification tests, executes testing, determines pass/fail, documents results |
| Escalation Owner | Senior leader responsible for resolving escalated findings; typically CPO or CISO | Intervenes when findings are overdue, allocates additional resources, reports to executive management |
The Finding Owner must provide a formal management response:
Finding ID: RA-2025-017
Finding Title: Incomplete vendor sub-processor notification
Severity: High
Finding Source: Internal Privacy Audit PA-2025-Q1
MANAGEMENT RESPONSE
Response Date: 2025-02-15
Finding Owner: VP, Procurement — Sarah Chen
Remediation Owner: Senior Vendor Manager — James Park
Agree/Disagree: Agree
Root Cause Analysis:
The current vendor management process does not include a mandatory step for
vendors to provide updated sub-processor lists when changes occur. The DPA
template includes a sub-processor notification clause (Section 8.3), but
there is no operational workflow to receive, review, and action these
notifications. 14 of 47 active processor DPAs were found to have outdated
sub-processor lists during the audit period.
Remediation Plan:
1. Implement sub-processor change notification workflow in vendor management
platform (ServiceNow) — target: March 15, 2025
2. Send outreach to all 47 processors requesting current sub-processor lists
— target: March 1, 2025
3. Update DPA template to include specific notification timeframe (30 days
prior notice) and objection mechanism — target: March 15, 2025
4. Establish quarterly sub-processor list verification for high-risk vendors
— target: April 1, 2025
5. Deliver training to procurement team on sub-processor change management
— target: March 31, 2025
Target Completion Date: April 1, 2025
Resources Required: 40 hours procurement team time; ServiceNow configuration
(IT support ticket submitted)
Dependencies: ServiceNow workflow configuration by IT (estimated 2 weeks)
Interim Risk Mitigation:
Immediate outreach to the 14 vendors with outdated lists to obtain current
sub-processor information; manual tracking via spreadsheet until ServiceNow
workflow is operational.A remediation plan is approved only if it meets these criteria:
| Criterion | Requirement |
|---|---|
| Root Cause Addressed | Plan addresses the underlying cause, not just the symptom |
| Specific Actions | Each action is concrete, measurable, and assignable |
| Realistic Timeline | Deadlines are achievable given dependencies and resource constraints |
| Resource Identified | Personnel, budget, and tools required are identified |
| Dependencies Documented | External dependencies (IT, legal, vendor) are identified with contingency |
| Interim Mitigation | If the finding presents immediate risk, interim measures are in place pending full remediation |
| Verifiable Outcome | The expected end-state is described in terms that can be objectively tested |
| Owner Assigned | Each action has a named individual responsible |
Plans that do not meet these criteria are returned for revision within 5 business days.
The finding tracking system must support:
| Capability | Purpose |
|---|---|
| Unique finding ID | Consistent reference across all communications |
| Status tracking | Open, In Progress, Pending Verification, Closed, Reopened |
| Severity classification | Critical, High, Medium, Low, Advisory |
| Date tracking | Registration date, management response date, target date, actual completion date, verification date, closure date |
| Owner assignment | Finding owner, remediation owner, verification owner |
| Evidence attachment | Upload evidence of remediation and verification |
| Automated notifications | Reminders at 50%, 75%, 90% of deadline; overdue alerts |
| Reporting and dashboards | Status summaries by severity, age, owner, source |
| Audit trail | Complete history of all changes, communications, and status transitions |
| Status | Definition | Transition Criteria |
|---|---|---|
| New | Finding registered; not yet triaged | → In Progress: after triage and owner assignment |
| In Progress | Remediation plan approved; work underway | → Pending Verification: remediation owner reports completion with evidence |
| Pending Verification | Remediation reported complete; awaiting verification testing | → Closed: verification passes; → Reopened: verification fails |
| Closed | Verification passed; finding archived | Terminal status (can be reopened if issue recurs) |
| Reopened | Verification failed or issue recurred | → In Progress: revised remediation plan submitted |
| Overdue | Past target date without completion | Triggers escalation per severity level |
| Risk Accepted | Management formally accepts the risk of not remediating | Requires CPO + CISO approval for High; Board approval for Critical |
| Trigger | Notification | Recipients |
|---|---|---|
| Finding registered | Assignment notification | Finding Owner, Remediation Owner |
| Management response due in 3 days | Reminder | Finding Owner |
| Management response overdue | Escalation | Finding Owner, CPO |
| 50% of remediation deadline elapsed | Progress check | Remediation Owner |
| 75% of remediation deadline elapsed | Urgency reminder | Remediation Owner, Finding Owner |
| 90% of remediation deadline elapsed | Final reminder | Remediation Owner, Finding Owner, CPO |
| Deadline passed (overdue) | Overdue alert | Finding Owner, CPO, Escalation Owner |
| Overdue by 30+ days | Executive escalation | CEO, Audit Committee (for High/Critical) |
| Verification complete | Closure notification | All stakeholders |
| Approach | When Used | Description |
|---|---|---|
| Documentation Review | Policy/procedure remediation | Verify that updated documents exist, are approved, published, and accessible |
| Technical Testing | System/configuration remediation | Independently verify that technical controls are configured as claimed |
| Transaction Testing | Process remediation | Test a sample of transactions to verify the process now operates correctly |
| Interview | Training/awareness remediation | Interview personnel to verify knowledge and process adherence |
| Observation | Process remediation | Observe the remediated process in operation |
| Reperformance | Control operation remediation | Independently execute the control to verify it produces the expected result |
For each finding, the verification owner designs specific tests:
Finding ID: RA-2025-017
Finding Title: Incomplete vendor sub-processor notification
Verification Tests:
Test 1: ServiceNow Workflow Verification
Procedure: Submit a test sub-processor change notification through the
ServiceNow workflow; verify that it routes to the correct reviewer,
generates the expected notifications, and creates an audit trail.
Pass Criteria: Notification received by vendor manager within 1 business
day; review completed and documented; audit trail complete.
Test 2: Sub-Processor List Currency
Procedure: Select 10 processors from the vendor register; verify that
sub-processor lists are current (dated within the last 90 days).
Pass Criteria: 10 of 10 processors have current sub-processor lists.
Test 3: DPA Template Update
Procedure: Review updated DPA template Section 8.3; verify inclusion of
30-day prior notification requirement and objection mechanism.
Pass Criteria: Clause present, legally reviewed, and approved.
Test 4: Procurement Team Knowledge
Procedure: Interview 3 procurement team members on sub-processor change
management process.
Pass Criteria: All 3 can describe the process correctly.
Test 5: Quarterly Review Process
Procedure: Verify that the quarterly sub-processor review is scheduled
and that the first review has been completed for high-risk vendors.
Pass Criteria: Review schedule established; first review completed with
documented results.| Outcome | Criteria | Next Step |
|---|---|---|
| Pass | All verification tests pass | Finding closed with evidence archived |
| Partial Pass | Some tests pass, minor gaps remain | Finding remains open; targeted remediation for remaining gaps; re-verification within 30 days |
| Fail | Material tests fail; remediation is ineffective | Finding reopened; revised remediation plan required within 10 business days; escalation triggered |
A finding may be closed only when ALL of the following criteria are met:
| # | Closure Criterion | Verified By |
|---|---|---|
| 1 | Remediation actions completed as documented in the approved plan | Remediation Owner attestation |
| 2 | Verification testing passed with documented results | Verification Owner |
| 3 | Evidence of remediation attached to the finding record | Verification Owner review |
| 4 | Root cause addressed (not just symptom) | Verification Owner assessment |
| 5 | No new issues introduced by the remediation | Verification Owner |
| 6 | Finding Owner confirms remediation meets expectations | Finding Owner sign-off |
| 7 | Closure approved by finding management coordinator | DPO or designee |
In exceptional cases, management may accept the risk rather than remediate:
| Severity | Approval Authority | Requirements |
|---|---|---|
| Low | CPO | Written justification; risk documented in risk register; annual review |
| Medium | CPO + CISO | Written justification with risk quantification; risk register entry; semi-annual review; compensating controls documented |
| High | CPO + CISO + CLO | Board notification; written justification with legal opinion; risk register entry; quarterly review; compensating controls verified |
| Critical | Not eligible for risk acceptance | Must be remediated; Board may approve interim risk acceptance for maximum 90 days while remediation is in progress |
| Metric | Current | Prior Month | Trend |
|---|---|---|---|
| Total Open Findings | 23 | 27 | Improving |
| — Critical | 0 | 0 | Stable |
| — High | 3 | 4 | Improving |
| — Medium | 11 | 13 | Improving |
| — Low | 9 | 10 | Improving |
| New Findings This Month | 4 | 6 | Improving |
| Findings Closed This Month | 8 | 5 | Improving |
| Overdue Findings | 2 | 3 | Improving |
| On-Time Closure Rate (YTD) | 91% | 89% | Improving |
| Average Days to Close | 42 | 47 | Improving |
| Findings Reopened | 1 | 0 | Monitoring |
| Risk Accepted | 1 | 1 | Stable |
Content:
Content:
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/audit-remediation-program of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Audit Remediation Program next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Audit Remediation Program this skillmukul975/Privacy-Data-Protection-Skills | 297 | — | ~5.3k | Automated safety check: Pass | Apache-2.0 | |
| HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Compliance Osalirezarezvani/claude-skills | 28k | — | ~3.3k | Automated safety check: Pass | MIT | |
| Implementing Complianceancoleman/ai-design-components | 526 | — | ~4k | Automated safety check: Pass | MIT | |
| Compliance Checklistmohitagw15856/pm-claude-skills | 1.4k | — | ~1.2k | Automated safety check: Pass | MIT | |
| Compliance Checklist Generationseb1n/awesome-ai-agent-skills | 206 | — | ~2.5k | Automated safety check: Pass | MIT |
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
alirezarezvani/claude-skills
Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across…
ancoleman/ai-design-components
Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.
mohitagw15856/pm-claude-skills
Generate a prioritised compliance checklist for GDPR, SOC 2, ISO 27001, FCA, HIPAA, or other frameworks with a gap analysis.
seb1n/awesome-ai-agent-skills
Build evidence-oriented readiness checklists for frameworks such as SOC 2, HIPAA, PCI DSS, and GDPR, with gaps and remediation priorities.
seb1n/awesome-ai-agent-skills
Build a preliminary, evidence-based EU AI Act readiness assessment across AI-system inventory, territorial scope, operator roles, prohibited-practice screening, risk classification, transparency…
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
Guides audit findings remediation program management including finding prioritization by severity (critical, high, medium, low), owner assignment, remediation planning, deadline tracking…. Audit Remediation Program is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides audit findings remediation program management including finding prioritization by severity (critical, high, medium, low), owner assignment, remediation planning, deadline tracking, verification testing, closure criteria, escalation protocols, and management reporting.
Audit Remediation Program fits situations like: tasks that involve Audit readiness; tasks that involve Prioritization frameworks; tasks that involve Privacy and GDPR.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill audit-remediation-program -a claude-code`. Or copy the skill folder (skills/privacy/audit-remediation-program in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/audit-remediation-program in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill audit-remediation-program -a codex`. Or copy the skill folder (skills/privacy/audit-remediation-program in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/audit-remediation-program in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill audit-remediation-program -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-remediation-program, .gemini/skills/audit-remediation-program, .github/skills/audit-remediation-program and .opencode/skills/audit-remediation-program in your project.
Going by SKILL.md and its folder, Audit Remediation Program needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Audit Remediation Program is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.3k tokens (SKILL.md is roughly 21k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Audit Remediation Program: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Compliance Os (alirezarezvani/claude-skills, 28k stars), Implementing Compliance (ancoleman/ai-design-components, 526 stars) and Compliance Checklist (mohitagw15856/pm-claude-skills, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 297 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.