HIPAA Safe Harbor Coverage Audit
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
Manages HIPAA Business Associate Agreements under 45 CFR §164.502(e) and §164.504(e).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-baa-management -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills hipaa-baa-management --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/hipaa-baa-management .claude/skills/hipaa-baa-management && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "hipaa-baa-management" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/hipaa-baa-management into .claude/skills/hipaa-baa-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hipaa-baa-management", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/hipaa-baa-managementType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-baa-management -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills hipaa-baa-management --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/hipaa-baa-management .agents/skills/hipaa-baa-management && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "hipaa-baa-management" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/hipaa-baa-management into .agents/skills/hipaa-baa-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hipaa-baa-management", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-baa-management -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills hipaa-baa-management --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/hipaa-baa-management .cursor/skills/hipaa-baa-management && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "hipaa-baa-management" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/hipaa-baa-management into .cursor/skills/hipaa-baa-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hipaa-baa-management", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/hipaa-baa-management--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-baa-management -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills hipaa-baa-management --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/hipaa-baa-management .gemini/skills/hipaa-baa-management && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "hipaa-baa-management" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/hipaa-baa-management into .gemini/skills/hipaa-baa-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hipaa-baa-management", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills hipaa-baa-managementInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-baa-management -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/hipaa-baa-management .github/skills/hipaa-baa-management && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "hipaa-baa-management" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/hipaa-baa-management into .github/skills/hipaa-baa-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hipaa-baa-management", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-baa-management -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills hipaa-baa-management --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/hipaa-baa-management .opencode/skills/hipaa-baa-management && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "hipaa-baa-management" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/hipaa-baa-management into .opencode/skills/hipaa-baa-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hipaa-baa-management", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
hipaa-baa-managementManages HIPAA Business Associate Agreements under 45 CFR §164.502(e) and §164.504(e).
Hipaa Baa Management is an agent skill from mukul975/Privacy-Data-Protection-Skills. Manages HIPAA Business Associate Agreements under 45 CFR §164.502(e) and §164.504(e). Covers required BAA provisions, business associate vs subcontractor obligations, breach notification chain, downstream BA requirements, and termination remedies. Keywords: BAA, business associate, subcontractor, HIPAA compliance, PHI disclosure, termination.
Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Legal & Compliance, covering Healthcare and finance regulation. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
10 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Hipaa Baa Management loads about 3.8k tokens when it runs, and up to ~5.5k if it reads all its reference files. Until then it costs about 91 tokens; SKILL.md has 1,894 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,894 words, ~3,807 tokens.
.claude/skills/hipaa-baa-management/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.The HIPAA Privacy and Security Rules require covered entities to obtain satisfactory assurances from business associates that they will appropriately safeguard PHI. These assurances are documented through Business Associate Agreements (BAAs). The HITECH Act of 2009 and the 2013 Omnibus Rule fundamentally changed the BA landscape by making business associates directly liable for HIPAA Security Rule compliance and certain Privacy Rule provisions, and by extending the BAA chain to subcontractors. A BAA is not merely a contractual formality — it is a regulatory requirement, and failure to execute a BAA when required is itself a HIPAA violation subject to enforcement.
A business associate is a person or entity that:
| Entity | Why Not a BA | Reference |
|---|---|---|
| Member of the covered entity's workforce | Employees, volunteers, trainees under direct control are workforce, not BAs | §160.103 definition of workforce |
| Another covered entity exchanging PHI for treatment | Treatment disclosures between covered entities do not create BA relationship | §164.502(e)(1)(i) |
| Health plan sponsor receiving only summary health information or enrollment/disenrollment information | Exemption for plan sponsor limited functions | §164.504(f) |
| Conduit (entity that merely transports PHI without accessing it beyond what is necessary for transport) | Postal service, Internet service providers, couriers with transient access | OCR guidance on conduit exception |
| Banking institutions processing financial transactions containing only the minimum necessary demographic information | Payment processing exception | OCR FAQ on financial institutions |
| Person or entity whose functions do not involve the use or disclosure of PHI | Janitorial services, plumbing, electrical contractors | §160.103 |
| BA Category | Examples | PHI Access Level |
|---|---|---|
| EHR/IT Vendors | Epic hosting, cloud infrastructure (Azure) | Full ePHI access — storage, maintenance, support |
| Revenue Cycle Management | Third-party billing company, collections agency | Demographics, insurance, diagnosis/procedure codes, dates of service |
| Transcription Services | Medical transcription vendor | Dictated clinical notes, patient identifiers |
| Legal/Accounting | Healthcare law firm, external auditors | PHI involved in litigation, audit samples |
| Data Analytics | Population health analytics vendor | De-identified or limited datasets; full PHI if performing analytics on behalf of CE |
| Health Information Exchange | Regional HIE operator | ADT, CCD documents, lab results |
| Shredding/Destruction | Document destruction vendor | Paper records containing PHI during destruction |
| Accreditation | Joint Commission surveyors | PHI in medical records reviewed during survey |
| Consulting | Privacy/security consultants, compliance firms | PHI accessed during assessments |
| Cloud Services | Email hosting, cloud storage, SaaS platforms | ePHI stored or processed in cloud environment |
A BAA must include the following provisions:
The BAA must establish the permitted and required uses and disclosures of PHI by the business associate. The BA may not use or disclose PHI other than as permitted or required by the BAA or as required by law.
Asclepius Health Network BAA language: "Business Associate shall not use or disclose Protected Health Information other than as permitted or required by this Agreement, as Required by Law, or as otherwise permitted by 45 CFR §164.504(e)."
The BAA must not authorize the BA to use or disclose PHI in a manner that would violate the Privacy Rule if done by the covered entity.
Exception: The BAA may permit the BA to use PHI for:
The BA must use appropriate safeguards and comply with the Security Rule to prevent unauthorized use or disclosure.
Asclepius Health Network BAA language: "Business Associate shall implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI that it creates, receives, maintains, or transmits on behalf of Covered Entity, in accordance with 45 CFR Part 164, Subpart C."
The BA must report to the covered entity any use or disclosure of PHI not provided for by the BAA, including breaches of unsecured PHI as required by §164.410.
Asclepius Health Network BAA language: "Business Associate shall report to Covered Entity any use or disclosure of Protected Health Information not provided for by this Agreement of which Business Associate becomes aware, including any Breach of Unsecured Protected Health Information as required by 45 CFR §164.410, without unreasonable delay and in no case later than five (5) business days after discovery of the Breach."
The BA must ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of the BA agree to the same restrictions and conditions that apply to the BA, including entering into a BAA with the subcontractor.
The BA must make PHI available to the covered entity (or directly to the individual if designated in the BAA) to satisfy the individual's right of access under §164.524.
Asclepius Health Network BAA language: "Business Associate shall make available Protected Health Information in a Designated Record Set to Covered Entity, or at Covered Entity's direction, directly to the Individual, within fifteen (15) business days of a request, to satisfy Covered Entity's obligations under 45 CFR §164.524."
The BA must make PHI available for amendment and incorporate amendments as directed by the covered entity under §164.526.
The BA must make available the information required to provide an accounting of disclosures under §164.528.
The BA must make its internal practices, books, and records relating to the use and disclosure of PHI available to HHS for determining compliance.
At termination of the BAA, the BA must return or destroy all PHI received from or created on behalf of the covered entity. If return or destruction is not feasible, the BA must extend the protections of the BAA for as long as it maintains the PHI.
| Phase | Activities | Responsible Party | Timeline |
|---|---|---|---|
| Identification | Determine if vendor relationship requires BAA through PHI access assessment questionnaire | Privacy Office + Procurement | Before contract execution |
| Risk Assessment | Evaluate vendor security posture through questionnaire, SOC 2 review, security assessment | Information Security | 15-30 business days |
| Negotiation | Execute BAA using Asclepius standard template; negotiate deviations with legal review | Legal + Privacy Office | Concurrent with master services agreement |
| Execution | Final BAA signed by authorized signatories; logged in BAA tracking system | Legal + Compliance | Before PHI access begins |
| Monitoring | Annual security assessment questionnaire; SOC 2 report review; incident tracking | Information Security + Privacy | Annually and upon trigger events |
| Renewal/Amendment | Review BAA at master agreement renewal; update for regulatory changes | Legal + Privacy Office | At MSA renewal or regulatory change |
| Termination | PHI return/destruction verification; certificate of destruction obtained; BAA tracking system updated | Privacy Office + IT | Within 60 days of termination |
Since the 2013 Omnibus Rule, business associates are directly liable for:
| Obligation | BA Directly Liable | Subcontractor Directly Liable |
|---|---|---|
| Security Rule compliance (all standards) | Yes — §164.306, 308, 310, 312, 314, 316 | Yes — through BA-subcontractor BAA |
| Impermissible uses/disclosures under Privacy Rule | Yes — §164.502(a)(3) | Yes — through BA-subcontractor BAA |
| Breach notification to covered entity | Yes — §164.410 | Yes — notify BA, who notifies CE |
| Minimum necessary standard | Yes — §164.502(b) | Yes — through BAA chain |
| Individual rights (access, amendment, accounting) | Yes — as delegated | Yes — as delegated in BAA chain |
| Civil and criminal penalties | Yes — directly enforceable by OCR | Yes — directly enforceable by OCR |
Covered Entity
└── BAA → Business Associate
└── BAA → Subcontractor (Level 1)
└── BAA → Subcontractor (Level 2)
└── ...continues downstreamEach link in the chain must have a BAA in place. Asclepius Health Network requires primary BAs to:
When a breach occurs at a subcontractor:
If the covered entity knows of a pattern of activity or practice of the BA that constitutes a material breach or violation of the BAA:
Asclepius Health Network Termination Process:
Asclepius Health Network requires:
| Deficiency | Risk | Mitigation |
|---|---|---|
| No BAA in place for qualifying vendor relationship | Direct HIPAA violation; CE liable for BA's actions without contractual protections | Pre-procurement PHI assessment; no PHI access before BAA execution |
| BAA does not include breach notification provisions | CE may not learn of breach timely; notification deadlines missed | Use standard template with mandatory breach reporting within 5 days |
| BAA permits BA to use PHI for BA's own purposes (marketing, analytics) | Impermissible use of PHI; potential sale of PHI violation | Restrict BA use to services performed for CE; prohibit independent use |
| No subcontractor flow-down requirements | Downstream entities handle PHI without HIPAA obligations | Require BA to bind subcontractors to equivalent BAA terms |
| No termination provisions for PHI return/destruction | PHI retained indefinitely by former BA without safeguards | Mandatory return/destruction clause with certification requirement |
| Outdated BAA not updated for Omnibus Rule | Missing required provisions (subcontractor, breach notification, direct liability acknowledgment) | Periodic BAA review aligned with MSA renewal |
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/hipaa-baa-management of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Hipaa Baa Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Hipaa Baa Management this skillmukul975/Privacy-Data-Protection-Skills | 301 | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | |
| HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| HIPAA Pre-Deployment Compliance Checkmaziyarpanahi/openmed | 5.5k | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~2.3k | Automated safety check: Pass | MIT | |
| ISO Standards Readiness EvidenceK-Dense-AI/scientific-agent-skills | 48k | 1 repos | ~4.6k | Automated safety check: Notes | MIT | |
| Fda Consultant Specialistdavila7/claude-code-templates | 33k | 1 repos | ~2.7k | Automated safety check: Pass | MIT |
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
maziyarpanahi/openmed
Walks a data pipeline against the HIPAA Privacy and Security Rule checklist and produces a gap report before it processes patient data.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
K-Dense-AI/scientific-agent-skills
Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.
davila7/claude-code-templates
Senior FDA consultant and specialist for medical device companies including HIPAA compliance and requirement management.
mlunato47/claude-grc-plugin
Senior GRC analyst expertise across 18 compliance frameworks — NIST 800-53, FedRAMP (Rev5 + 20x/CR26, KSIs, VDR/VER, Certification Classes A–D), DoD/DoW Impact Levels (IL2–IL6, DISA Cloud SRG), ITAR…
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
Categories
Manages HIPAA Business Associate Agreements under 45 CFR §164.502(e) and §164.504(e). Hipaa Baa Management is an agent skill from mukul975/Privacy-Data-Protection-Skills.504(e).
Hipaa Baa Management fits situations like: tasks that involve Healthcare and finance regulation.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-baa-management -a claude-code`. Or copy the skill folder (skills/privacy/hipaa-baa-management in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/hipaa-baa-management in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-baa-management -a codex`. Or copy the skill folder (skills/privacy/hipaa-baa-management in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/hipaa-baa-management in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-baa-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hipaa-baa-management, .gemini/skills/hipaa-baa-management, .github/skills/hipaa-baa-management and .opencode/skills/hipaa-baa-management in your project.
Going by SKILL.md and its folder, Hipaa Baa Management needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Hipaa Baa Management is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.7k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Hipaa Baa Management: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), HIPAA Pre-Deployment Compliance Check (maziyarpanahi/openmed, 5.5k stars), Hipaa Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars) and ISO Standards Readiness Evidence (K-Dense-AI/scientific-agent-skills, 48k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.