Agent skill

Healthcare AI Privacy

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Addresses healthcare AI privacy at the intersection of HIPAA and the EU AI Act for clinical decision support systems.

Apache-2.0Auto-check passedLegal & Compliance

Install Healthcare AI Privacy

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill healthcare-ai-privacy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills healthcare-ai-privacy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/healthcare-ai-privacy .claude/skills/healthcare-ai-privacy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
healthcare-ai-privacy
GitHub stars
301
Token cost
~4.4k tokens
SKILL.md length
2,056 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Addresses healthcare AI privacy at the intersection of HIPAA and the EU AI Act for clinical decision support systems.

  • Works in 7 steps: Purpose documentation: AI development… → Minimum necessary review: Privacy Office… → De-identification assessment: For models… → …
  • Tasks that involve AI governance
  • SKILL.md covers Overview, Regulatory Landscape, Training Data PHI Handling and Model Transparency and…, plus 6 more sections
  • Runs Python scripts from its folder

What it does

Healthcare AI Privacy is an agent skill from mukul975/Privacy-Data-Protection-Skills. Addresses healthcare AI privacy at the intersection of HIPAA and the EU AI Act for clinical decision support systems. Covers training data PHI handling, model transparency and explainability, patient rights in algorithmic decisions, FDA/OCR regulatory coordination, and bias monitoring. Keywords: healthcare AI, HIPAA, AI Act, clinical decision support, PHI training data, model transparency.

Its SKILL.md is about 4.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering AI governance, Clinical and healthcare research and Healthcare and finance regulation. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve AI governance
  • Tasks that involve Clinical and healthcare research
  • Tasks that involve Healthcare and finance regulation

Example prompts

  • “Use the healthcare-ai-privacy skill to address healthcare AI privacy at the intersection of HIPAA and the EU AI Act for clinical decision support…”
  • “/healthcare-ai-privacy”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Purpose documentation: AI development team submits purpose statement, model description, data elements needed, and lawful basis…
  2. Minimum necessary review: Privacy Office reviews requested data elements against stated purpose; removes unnecessary fields
  3. De-identification assessment: For models that do not require identifiable data, the de-identification team applies safe harbor or…
  4. Data use agreement: For limited datasets used in AI development, a DUA is executed specifying permitted uses and prohibiting…
  5. Security requirements: AI training environment must meet Security Rule requirements — encrypted storage, access-controlled compute…
  6. Model memorization testing: Before deployment, models are tested for training data memorization using membership inference and data…
  7. Data retention: Training data copies are deleted within 90 days of model finalization; only the trained model weights are retained

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Healthcare AI Privacy loads about 4.4k tokens when it runs, and up to ~6.5k if it reads all its reference files. Until then it costs about 104 tokens; SKILL.md has 2,056 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~104
When it runs · the whole SKILL.md, loaded when a task matches
~4.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 2,056 words, ~4,376 tokens.

Download SKILL.mdSave it as .claude/skills/healthcare-ai-privacy/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
healthcare-ai-privacy
description
Addresses healthcare AI privacy at the intersection of HIPAA and the EU AI Act for clinical decision support systems. Covers training data PHI handling, model transparency and explainability, patient rights in algorithmic decisions, FDA/OCR regulatory coordination, and bias monitoring. Keywords: healthcare AI, HIPAA, AI Act, clinical decision support, PHI training data, model transparency.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
healthcare-privacy
metadata.tags
healthcare-ai, hipaa, ai-act, clinical-decision-support, phi-training-data, model-transparency, bias

Healthcare AI Privacy — HIPAA and AI Act Intersection

Overview

Artificial intelligence in healthcare introduces privacy challenges that sit at the intersection of established health privacy law (HIPAA, HITECH) and emerging AI regulation (EU AI Act, FDA regulatory framework, proposed state AI laws). Clinical decision support (CDS) systems, diagnostic AI, and predictive analytics operate on protected health information, creating obligations under HIPAA while simultaneously falling within the scope of AI-specific regulation when deployed in high-risk clinical contexts. This skill addresses the complete privacy lifecycle of healthcare AI — from training data acquisition through model deployment and patient interaction — ensuring compliance with both health privacy and AI governance frameworks.

Regulatory Landscape

Overlapping Regulatory Frameworks
FrameworkApplicability to Healthcare AIKey Requirements
HIPAA Privacy Rule (45 CFR §164)AI systems processing PHI at covered entities or BAsAuthorization or TPO exception for PHI use; minimum necessary; individual rights
HIPAA Security Rule (45 CFR §164.312)ePHI used in AI training, inference, and storageAccess controls, audit trails, encryption, integrity controls
EU AI Act (Regulation 2024/1689)AI systems deployed in EU healthcare or processing EU patient dataHigh-risk classification for medical devices; conformity assessment; transparency
FDA Regulatory FrameworkAI/ML-based Software as a Medical Device (SaMD)510(k), De Novo, or PMA pathway; GMLP (Good Machine Learning Practice); total product lifecycle approach
FTC Act §5AI making health-related decisions affecting consumersUnfair or deceptive practices; Health Breach Notification Rule for non-HIPAA entities
State AI LawsEmerging state legislation (Colorado AI Act SB24-205, Illinois AI Video Interview Act)Algorithmic impact assessments; notice and opt-out for automated decisions
EU AI Act High-Risk Classification for Healthcare AI

Under Annex III of the EU AI Act, the following healthcare AI systems are classified as high-risk:

CategoryAI Act ReferenceExamples
Medical devices (AI-based)Annex III, §5(a)AI diagnostic imaging (radiology, pathology, dermatology), AI-assisted surgery planning
In vitro diagnostic medical devices (AI-based)Annex III, §5(a)AI-based genetic analysis, AI companion diagnostics
Safety components of medical devicesAnnex III, §5(b)AI monitoring in ICU, AI-driven infusion pump dosing

High-risk AI systems must comply with AI Act requirements including risk management (Art. 9), data governance (Art. 10), transparency (Art. 13), human oversight (Art. 14), accuracy/robustness (Art. 15), and conformity assessment (Art. 43).

Training Data PHI Handling

Lawful Basis for Using PHI in AI Training
Lawful BasisHIPAA ProvisionApplicabilityConditions
Treatment§164.506(c)(1)AI models trained to support individual patient treatment decisionsModel must directly serve treatment function; minimum necessary applies
Healthcare Operations§164.506(c)(4)Quality assessment, population health analytics, clinical decision support developmentMust qualify as healthcare operations under §164.501 definition
Research§164.512(i)Academic or institutional research developing AI modelsIRB/Privacy Board approval; authorization or waiver of authorization; data use agreement for limited datasets
De-identified data§164.514(a)Training on data that meets safe harbor or expert determination de-identificationNo HIPAA restrictions once properly de-identified; re-identification risk from AI model memorization must be assessed
Authorization§164.508Individual authorization for specific AI training useValid authorization meeting §164.508(c) requirements; may be impractical at scale
Asclepius Health Network AI Training Data Governance

Asclepius Health Network has established an AI Data Governance Committee that reviews all AI training data requests:

Training Data Request Workflow:

  1. Purpose documentation: AI development team submits purpose statement, model description, data elements needed, and lawful basis justification
  2. Minimum necessary review: Privacy Office reviews requested data elements against stated purpose; removes unnecessary fields
  3. De-identification assessment: For models that do not require identifiable data, the de-identification team applies safe harbor or coordinates expert determination
  4. Data use agreement: For limited datasets used in AI development, a DUA is executed specifying permitted uses and prohibiting re-identification attempts
  5. Security requirements: AI training environment must meet Security Rule requirements — encrypted storage, access-controlled compute environment, audit logging of all data access
  6. Model memorization testing: Before deployment, models are tested for training data memorization using membership inference and data extraction attacks
  7. Data retention: Training data copies are deleted within 90 days of model finalization; only the trained model weights are retained
AI-Specific PHI Risks
RiskDescriptionMitigation
Training data memorizationLarge models (transformers, LLMs) can memorize and reproduce verbatim training data including PHIDifferential privacy (DP-SGD), training data deduplication, memorization testing pre-deployment
Membership inferenceAdversary determines whether a specific patient's data was in the training setOutput perturbation, model regularization, membership inference attack testing
Model inversionAdversary reconstructs patient features from model outputsLimit output granularity, add noise to confidence scores, restrict API access
Attribute inferenceModel reveals sensitive attributes (HIV status, substance use) not provided as inputFeature correlation analysis, fairness-aware training, output filtering
Training data leakage via model explanationSHAP/LIME explanations may reveal individual patient contributionsAggregate explanations; use synthetic examples for patient-facing explanations

Model Transparency and Explainability

HIPAA Transparency Requirements

While HIPAA does not explicitly address AI transparency, several provisions create de facto transparency obligations:

  • Notice of Privacy Practices (§164.520): Must describe how PHI is used — if PHI is used in AI systems for treatment or operations, the NPP should disclose this
  • Right of Access (§164.524): Patients have the right to access their designated record set, which may include AI-generated assessments, risk scores, and recommendations stored in the medical record
  • Minimum Necessary (§164.502(b)): AI systems accessing PHI must be limited to the minimum necessary data elements
EU AI Act Transparency Requirements for Healthcare AI

For high-risk healthcare AI systems under the AI Act:

RequirementAI Act ArticleImplementation
Technical documentationArt. 11Complete description of AI system including training methodology, data governance, performance metrics, known limitations
Record-keepingArt. 12Automatic logging of AI system operations enabling traceability
Transparency to usersArt. 13Instructions for use enabling healthcare providers to interpret outputs and exercise oversight; disclosure of performance metrics, known biases, and foreseeable misuse
Human oversightArt. 14AI systems designed to be effectively overseen by natural persons; override capability; ability to disregard AI output
Accuracy and robustnessArt. 15Declared accuracy levels; resilience against errors, faults, and adversarial attacks
Asclepius Health Network AI Transparency Framework

For each deployed AI system, Asclepius maintains:

Model Card (following the Mitchell et al. framework, adapted for healthcare):

  • Model name, version, deployment date
  • Intended clinical use and patient population
  • Training data description (source, size, demographics, time period — using aggregate statistics, not individual PHI)
  • Performance metrics disaggregated by demographic subgroups (age, sex, race/ethnicity, insurance type)
  • Known limitations and failure modes
  • Fairness evaluation results
  • Human oversight requirements (which clinical decisions require physician review)
  • Data privacy measures implemented (de-identification method, differential privacy parameters, access controls)

Patient-Facing Disclosure:

  • Asclepius NPP includes disclosure that AI/ML tools may be used in treatment and healthcare operations
  • Individual AI-generated recommendations in the patient portal include a notation identifying them as AI-assisted
  • Patients may request information about AI systems used in their care through the Privacy Office

Patient Rights in Algorithmic Healthcare Decisions

HIPAA-Based Rights
RightApplication to Healthcare AIAsclepius Implementation
Right of Access (§164.524)Patient may access AI-generated risk scores, predictions, and recommendations in their medical recordAI outputs stored in EHR are accessible through the patient portal; explanations provided in plain language
Right to Amend (§164.526)Patient may request amendment of AI-generated entries if believed to be inaccurateAI-generated entries clearly labeled; amendment requests reviewed by treating physician and AI governance committee
Right to Accounting of Disclosures (§164.528)AI system disclosures of PHI (e.g., to a cloud-based AI service) must be trackedAll API calls to AI inference services logged; BA disclosures tracked in disclosure accounting system
Right to Restrict (§164.522)Patient may request restrictions on AI processingAsclepius honors requests to exclude specific data from AI-assisted analytics where clinically feasible
Show full SKILL.md (800 more words)Show less
Automated Decision-Making Considerations

HIPAA does not include a direct analog to GDPR Article 22 (right not to be subject to automated decision-making). However:

  • Clinical standard of care: AI-only decisions without physician oversight may constitute substandard care under state medical practice acts
  • Informed consent: State informed consent laws may require disclosure that AI was used in diagnosis or treatment recommendations
  • Anti-discrimination: AI decisions that disproportionately affect protected groups may violate the ACA §1557 (non-discrimination in healthcare programs), CRA Title VI, or ADA
  • FDA regulation: AI/ML SaMD must meet safety and effectiveness standards that inherently require human oversight in the clinical workflow

FDA Regulatory Coordination

AI/ML Software as a Medical Device

The FDA regulates AI/ML-based clinical decision support as Software as a Medical Device (SaMD) when it meets the device definition and is not excluded under the 21st Century Cures Act §3060(a) exemption for certain CDS:

CDS Not Regulated as Device (Cures Act Exemption):

  1. Not intended to acquire, process, or analyze a medical image, signal, or pattern
  2. Intended for the purpose of displaying, analyzing, or printing medical information
  3. Intended for the purpose of supporting or providing recommendations to an HCP
  4. Intended for the HCP to independently review the basis for the recommendation

All four criteria must be met. AI systems that process imaging (radiology AI, pathology AI) or make autonomous decisions do NOT qualify for the exemption.

Privacy in FDA AI/ML Regulatory Pathway
FDA PathwayPrivacy Considerations
510(k) premarket notificationTraining data representativeness documentation; algorithmic bias assessment; cybersecurity controls for ePHI
De Novo classificationNovel AI technology risk-benefit analysis including privacy risks; post-market surveillance plan
PMA (Premarket Approval)Full clinical evidence including training data provenance; long-term monitoring of AI performance across demographics
Predetermined change control planDocumentation of how model updates will maintain privacy protections; re-validation requirements after model retraining
Good Machine Learning Practice (GMLP)

FDA, Health Canada, and MHRA jointly published 10 GMLP principles (October 2021) with privacy-relevant requirements:

  1. Leverage multi-disciplinary expertise (including privacy professionals) throughout the AI lifecycle
  2. Implement good software engineering and security practices (aligns with HIPAA Security Rule)
  3. Ensure training datasets are representative of intended patient population
  4. Manage training-serving skew through monitoring and version control
  5. Focus on global model performance and per-subgroup performance metrics

Bias Monitoring and Health Equity

Regulatory Requirements
  • ACA §1557: Prohibits discrimination in healthcare programs receiving federal financial assistance — AI systems that produce disparate outcomes may violate §1557
  • OCR AI Guidance: OCR has indicated interest in enforcing non-discrimination requirements against AI systems in healthcare
  • CMS Conditions of Participation: Hospitals must not discriminate; AI-driven care recommendations must not produce discriminatory outcomes
Asclepius Health Network AI Bias Monitoring Program

Pre-Deployment Assessment:

  • Performance metrics disaggregated by: age group, sex, race/ethnicity, primary language, insurance type, geography
  • Disparate impact analysis: if any subgroup performance metric falls below 80% of the best-performing group, remediation required before deployment
  • Clinical validation with diverse patient populations matching Asclepius's demographics

Post-Deployment Monitoring:

  • Monthly automated performance monitoring across demographic subgroups
  • Quarterly clinical outcome correlation analysis
  • Annual comprehensive bias audit by independent third party
  • Real-time alert if model performance on any subgroup degrades below threshold
  • Patient feedback mechanism for concerns about AI-assisted care recommendations

Asclepius Health Network AI Privacy Governance Structure

RoleResponsibilities
Chief Privacy OfficerOverall accountability for PHI use in AI; approves AI training data requests; reports to Board
CISOSecurity controls for AI infrastructure; penetration testing of AI systems; incident response
Chief Medical Informatics OfficerClinical appropriateness of AI systems; human oversight protocols; clinician training
AI Ethics CommitteeReviews AI use cases for ethical implications including privacy; includes patient advocate representation
AI Data Governance CommitteeReviews training data requests; ensures de-identification adequacy; manages data use agreements
Model Risk ManagementValidates AI model performance; tests for memorization and bias; manages model inventory

Enforcement and Regulatory Activity

  • HHS Office of the National Coordinator (ONC): Health Data, Technology, and Interoperability (HTI-1) Final Rule (2023) requires AI-enabled health IT to meet transparency requirements including source attribute disclosure and risk management
  • OCR: Ongoing enforcement interest in AI-related privacy violations; no specific AI enforcement action as of early 2025, but OCR has issued guidance emphasizing HIPAA applicability to AI processing of PHI
  • FTC: Health Breach Notification Rule updated (2023) to cover health data processed by non-HIPAA entities including AI health apps; enforcement against AI health claims (e.g., FTC v. Cerebral, 2023)
  • State Actions: Multiple state AGs investigating healthcare AI for consumer protection and privacy violations

Integration Points

  • hipaa-privacy-rule: All PHI use in AI must comply with Privacy Rule requirements; TPO basis for clinical AI
  • hipaa-security-rule: AI infrastructure processing ePHI must meet all technical safeguards
  • hipaa-deidentification: De-identification enables AI training without PHI constraints; model memorization creates new re-identification vectors
  • hipaa-risk-analysis: AI systems with ePHI access must be included in enterprise-wide risk analysis
  • telehealth-privacy: AI integrated into telehealth platforms creates compound privacy obligations

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/healthcare-ai-privacy of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Healthcare AI Privacy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Healthcare AI Privacy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Healthcare AI Privacy this skillmukul975/Privacy-Data-Protection-Skills301—~4.4kAutomated safety check: PassApache-2.0
Compliance Osalirezarezvani/claude-skills28k—~3.3kAutomated safety check: PassMIT
Complianceericrisco/rsc-harness180—~2.4kAutomated safety check: PassMIT
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT
Clinical Reportsdavila7/claude-code-templates33k11 repos~9.9kAutomated safety check: NotesMIT

Similar skills

  • Compliance Os

    alirezarezvani/claude-skills

    Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across…

    28k GitHub stars~3.3k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Compliance

    ericrisco/rsc-harness

    A skill your agent uses when scoping which regulatory frameworks bind a business — SOC 2, ISO 27001, HIPAA, PCI DSS, EU AI Act, DORA, NIS2 — building a control register with owners and evidence, or…

    180 GitHub stars~2.4k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Clinical Reports

    davila7/claude-code-templates

    Write comprehensive clinical reports including case reports (CARE guidelines), diagnostic reports (radiology/pathology/lab), clinical trial reports (ICH-E3, SAE, CSR), and patient documentation…

    33k GitHub starsUsed in 11 repos~9.9k tokens
    Legal & ComplianceAuto-check: notes
  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Healthcare AI Privacy

What does Healthcare AI Privacy do?

Addresses healthcare AI privacy at the intersection of HIPAA and the EU AI Act for clinical decision support systems. Healthcare AI Privacy is an agent skill from mukul975/Privacy-Data-Protection-Skills. Addresses healthcare AI privacy at the intersection of HIPAA and the EU AI Act for clinical decision support systems.

When should I use Healthcare AI Privacy?

Healthcare AI Privacy fits situations like: tasks that involve AI governance; tasks that involve Clinical and healthcare research; tasks that involve Healthcare and finance regulation.

How do I install Healthcare AI Privacy in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill healthcare-ai-privacy -a claude-code`. Or copy the skill folder (skills/privacy/healthcare-ai-privacy in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/healthcare-ai-privacy in your project. Claude Code loads it when a task matches its description.

How do I install Healthcare AI Privacy in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill healthcare-ai-privacy -a codex`. Or copy the skill folder (skills/privacy/healthcare-ai-privacy in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/healthcare-ai-privacy in your project. Codex loads it when a task matches its description.

Can I use Healthcare AI Privacy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill healthcare-ai-privacy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/healthcare-ai-privacy, .gemini/skills/healthcare-ai-privacy, .github/skills/healthcare-ai-privacy and .opencode/skills/healthcare-ai-privacy in your project.

What does Healthcare AI Privacy need to run?

Going by SKILL.md and its folder, Healthcare AI Privacy needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Healthcare AI Privacy access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Healthcare AI Privacy safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Healthcare AI Privacy use?

Healthcare AI Privacy is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Healthcare AI Privacy use?

About 4.4k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.1k tokens, read only when the agent opens those files.

What are the alternatives to Healthcare AI Privacy?

Skills that share tags, products or a category with Healthcare AI Privacy: Compliance Os (alirezarezvani/claude-skills, 28k stars), Compliance (ericrisco/rsc-harness, 180 stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars) and Hipaa Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Healthcare AI Privacy?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.