Agent skill

Hipaa Baa Management

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Manages HIPAA Business Associate Agreements under 45 CFR §164.502(e) and §164.504(e).

Apache-2.0Auto-check passedLegal & Compliance

Install Hipaa Baa Management

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-baa-management -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills hipaa-baa-management --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/hipaa-baa-management .claude/skills/hipaa-baa-management && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hipaa-baa-management
GitHub stars
301
Token cost
~3.8k tokens
SKILL.md length
1,894 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Manages HIPAA Business Associate Agreements under 45 CFR §164.502(e) and §164.504(e).

  • Works in 10 steps: Permitted and Required Uses and… → Prohibition on Unauthorized Use or… → Appropriate Safeguards → …
  • Tasks that involve Healthcare and finance regulation
  • SKILL.md covers Overview, Who Is a Business Associate —…, Required BAA Provisions —… and Business Associate vs…, plus 5 more sections
  • Runs Python scripts from its folder

What it does

Hipaa Baa Management is an agent skill from mukul975/Privacy-Data-Protection-Skills. Manages HIPAA Business Associate Agreements under 45 CFR §164.502(e) and §164.504(e). Covers required BAA provisions, business associate vs subcontractor obligations, breach notification chain, downstream BA requirements, and termination remedies. Keywords: BAA, business associate, subcontractor, HIPAA compliance, PHI disclosure, termination.

Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Healthcare and finance regulation. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Healthcare and finance regulation

Example prompts

  • “Use the hipaa-baa-management skill to manage HIPAA Business Associate Agreements under 45 CFR §164.502(e) and §164.504(e)”
  • “/hipaa-baa-management”

Requirements

  • Python 3

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Permitted and Required Uses and Disclosures
  2. Prohibition on Unauthorized Use or Disclosure
  3. Appropriate Safeguards
  4. Breach Reporting
  5. Subcontractor Requirements
  6. Access Rights
  7. Amendment Rights
  8. Accounting of Disclosures
  9. HHS Access
  10. Return or Destruction of PHI

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hipaa Baa Management loads about 3.8k tokens when it runs, and up to ~5.5k if it reads all its reference files. Until then it costs about 91 tokens; SKILL.md has 1,894 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~91
When it runs · the whole SKILL.md, loaded when a task matches
~3.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,894 words, ~3,807 tokens.

Download SKILL.mdSave it as .claude/skills/hipaa-baa-management/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
hipaa-baa-management
description
Manages HIPAA Business Associate Agreements under 45 CFR §164.502(e) and §164.504(e). Covers required BAA provisions, business associate vs subcontractor obligations, breach notification chain, downstream BA requirements, and termination remedies. Keywords: BAA, business associate, subcontractor, HIPAA compliance, PHI disclosure, termination.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
healthcare-privacy
metadata.tags
hipaa, baa, business-associate, subcontractor, phi-disclosure, termination, compliance

HIPAA Business Associate Agreement Management — §164.502(e), §164.504(e)

Overview

The HIPAA Privacy and Security Rules require covered entities to obtain satisfactory assurances from business associates that they will appropriately safeguard PHI. These assurances are documented through Business Associate Agreements (BAAs). The HITECH Act of 2009 and the 2013 Omnibus Rule fundamentally changed the BA landscape by making business associates directly liable for HIPAA Security Rule compliance and certain Privacy Rule provisions, and by extending the BAA chain to subcontractors. A BAA is not merely a contractual formality — it is a regulatory requirement, and failure to execute a BAA when required is itself a HIPAA violation subject to enforcement.

Who Is a Business Associate — §160.103

Definition

A business associate is a person or entity that:

  1. On behalf of a covered entity or another business associate, creates, receives, maintains, or transmits PHI for a function or activity regulated by the HIPAA Administrative Simplification rules, including claims processing, data analysis, utilization review, quality assurance, billing, benefit management, practice management, and repricing; OR
  2. Provides legal, actuarial, accounting, consulting, data aggregation, management, administrative, accreditation, or financial services to or for a covered entity where the provision of the service involves the disclosure of PHI
Who Is NOT a Business Associate
EntityWhy Not a BAReference
Member of the covered entity's workforceEmployees, volunteers, trainees under direct control are workforce, not BAs§160.103 definition of workforce
Another covered entity exchanging PHI for treatmentTreatment disclosures between covered entities do not create BA relationship§164.502(e)(1)(i)
Health plan sponsor receiving only summary health information or enrollment/disenrollment informationExemption for plan sponsor limited functions§164.504(f)
Conduit (entity that merely transports PHI without accessing it beyond what is necessary for transport)Postal service, Internet service providers, couriers with transient accessOCR guidance on conduit exception
Banking institutions processing financial transactions containing only the minimum necessary demographic informationPayment processing exceptionOCR FAQ on financial institutions
Person or entity whose functions do not involve the use or disclosure of PHIJanitorial services, plumbing, electrical contractors§160.103
Common Business Associate Categories at Asclepius Health Network
BA CategoryExamplesPHI Access Level
EHR/IT VendorsEpic hosting, cloud infrastructure (Azure)Full ePHI access — storage, maintenance, support
Revenue Cycle ManagementThird-party billing company, collections agencyDemographics, insurance, diagnosis/procedure codes, dates of service
Transcription ServicesMedical transcription vendorDictated clinical notes, patient identifiers
Legal/AccountingHealthcare law firm, external auditorsPHI involved in litigation, audit samples
Data AnalyticsPopulation health analytics vendorDe-identified or limited datasets; full PHI if performing analytics on behalf of CE
Health Information ExchangeRegional HIE operatorADT, CCD documents, lab results
Shredding/DestructionDocument destruction vendorPaper records containing PHI during destruction
AccreditationJoint Commission surveyorsPHI in medical records reviewed during survey
ConsultingPrivacy/security consultants, compliance firmsPHI accessed during assessments
Cloud ServicesEmail hosting, cloud storage, SaaS platformsePHI stored or processed in cloud environment

Required BAA Provisions — §164.504(e)(2)

Mandatory Contract Terms

A BAA must include the following provisions:

1. Permitted and Required Uses and Disclosures

The BAA must establish the permitted and required uses and disclosures of PHI by the business associate. The BA may not use or disclose PHI other than as permitted or required by the BAA or as required by law.

Asclepius Health Network BAA language: "Business Associate shall not use or disclose Protected Health Information other than as permitted or required by this Agreement, as Required by Law, or as otherwise permitted by 45 CFR §164.504(e)."

2. Prohibition on Unauthorized Use or Disclosure

The BAA must not authorize the BA to use or disclose PHI in a manner that would violate the Privacy Rule if done by the covered entity.

Exception: The BAA may permit the BA to use PHI for:

  • Proper management and administration of the BA
  • Carrying out its legal responsibilities
  • Data aggregation services (if specifically authorized)
3. Appropriate Safeguards

The BA must use appropriate safeguards and comply with the Security Rule to prevent unauthorized use or disclosure.

Asclepius Health Network BAA language: "Business Associate shall implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI that it creates, receives, maintains, or transmits on behalf of Covered Entity, in accordance with 45 CFR Part 164, Subpart C."

4. Breach Reporting

The BA must report to the covered entity any use or disclosure of PHI not provided for by the BAA, including breaches of unsecured PHI as required by §164.410.

Asclepius Health Network BAA language: "Business Associate shall report to Covered Entity any use or disclosure of Protected Health Information not provided for by this Agreement of which Business Associate becomes aware, including any Breach of Unsecured Protected Health Information as required by 45 CFR §164.410, without unreasonable delay and in no case later than five (5) business days after discovery of the Breach."

5. Subcontractor Requirements

The BA must ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of the BA agree to the same restrictions and conditions that apply to the BA, including entering into a BAA with the subcontractor.

6. Access Rights

The BA must make PHI available to the covered entity (or directly to the individual if designated in the BAA) to satisfy the individual's right of access under §164.524.

Asclepius Health Network BAA language: "Business Associate shall make available Protected Health Information in a Designated Record Set to Covered Entity, or at Covered Entity's direction, directly to the Individual, within fifteen (15) business days of a request, to satisfy Covered Entity's obligations under 45 CFR §164.524."

7. Amendment Rights

The BA must make PHI available for amendment and incorporate amendments as directed by the covered entity under §164.526.

8. Accounting of Disclosures

The BA must make available the information required to provide an accounting of disclosures under §164.528.

9. HHS Access

The BA must make its internal practices, books, and records relating to the use and disclosure of PHI available to HHS for determining compliance.

10. Return or Destruction of PHI

At termination of the BAA, the BA must return or destroy all PHI received from or created on behalf of the covered entity. If return or destruction is not feasible, the BA must extend the protections of the BAA for as long as it maintains the PHI.

Asclepius Health Network BAA Lifecycle Management
PhaseActivitiesResponsible PartyTimeline
IdentificationDetermine if vendor relationship requires BAA through PHI access assessment questionnairePrivacy Office + ProcurementBefore contract execution
Risk AssessmentEvaluate vendor security posture through questionnaire, SOC 2 review, security assessmentInformation Security15-30 business days
NegotiationExecute BAA using Asclepius standard template; negotiate deviations with legal reviewLegal + Privacy OfficeConcurrent with master services agreement
ExecutionFinal BAA signed by authorized signatories; logged in BAA tracking systemLegal + ComplianceBefore PHI access begins
MonitoringAnnual security assessment questionnaire; SOC 2 report review; incident trackingInformation Security + PrivacyAnnually and upon trigger events
Renewal/AmendmentReview BAA at master agreement renewal; update for regulatory changesLegal + Privacy OfficeAt MSA renewal or regulatory change
TerminationPHI return/destruction verification; certificate of destruction obtained; BAA tracking system updatedPrivacy Office + ITWithin 60 days of termination
Show full SKILL.md (708 more words)Show less

Business Associate vs Subcontractor Obligations

Direct Liability Under HITECH/Omnibus Rule

Since the 2013 Omnibus Rule, business associates are directly liable for:

ObligationBA Directly LiableSubcontractor Directly Liable
Security Rule compliance (all standards)Yes — §164.306, 308, 310, 312, 314, 316Yes — through BA-subcontractor BAA
Impermissible uses/disclosures under Privacy RuleYes — §164.502(a)(3)Yes — through BA-subcontractor BAA
Breach notification to covered entityYes — §164.410Yes — notify BA, who notifies CE
Minimum necessary standardYes — §164.502(b)Yes — through BAA chain
Individual rights (access, amendment, accounting)Yes — as delegatedYes — as delegated in BAA chain
Civil and criminal penaltiesYes — directly enforceable by OCRYes — directly enforceable by OCR
Subcontractor BAA Chain
Covered Entity
  └── BAA → Business Associate
                └── BAA → Subcontractor (Level 1)
                              └── BAA → Subcontractor (Level 2)
                                            └── ...continues downstream

Each link in the chain must have a BAA in place. Asclepius Health Network requires primary BAs to:

  1. Maintain a registry of subcontractors with PHI access
  2. Provide the registry to Asclepius upon request
  3. Ensure subcontractor BAAs contain provisions no less restrictive than the primary BAA
  4. Report subcontractor breaches through the primary BA

Breach Chain Notification Flow

When a breach occurs at a subcontractor:

  1. Subcontractor discovers breach → notifies BA within timeframe specified in sub-BA (Asclepius standard: 24 hours)
  2. Business Associate validates and documents → notifies Covered Entity within BAA timeframe (Asclepius standard: 5 business days of BA's discovery)
  3. Covered Entity conducts four-factor risk assessment → determines if breach notification to individuals/HHS/media/AG is required
  4. Covered Entity fulfills notification obligations (or delegates to BA per BAA)

Termination Remedies — §164.504(e)(2)(iii)

Material Breach

If the covered entity knows of a pattern of activity or practice of the BA that constitutes a material breach or violation of the BAA:

  1. Cure: Provide the BA an opportunity to cure the breach or end the violation
  2. Terminate: If cure is not successful, terminate the contract if feasible
  3. Report to HHS: If termination is not feasible, report the problem to HHS OCR

Asclepius Health Network Termination Process:

  • Written notice of material breach with 30-day cure period
  • If not cured within 30 days, termination notice with 60-day wind-down period
  • During wind-down: PHI access restricted to minimum necessary for transition
  • At termination: BA must return or certify destruction of all PHI within 30 days post-termination
  • If return/destruction infeasible, BA must provide written certification of ongoing protection
PHI Return/Destruction Verification

Asclepius Health Network requires:

  • Written certification of PHI destruction from BA within 30 days of termination
  • Destruction must comply with NIST SP 800-88 Rev. 1 for electronic media
  • Paper records destroyed via cross-cut shredding or incineration
  • Asclepius reserves the right to audit destruction compliance

Common BAA Deficiencies

DeficiencyRiskMitigation
No BAA in place for qualifying vendor relationshipDirect HIPAA violation; CE liable for BA's actions without contractual protectionsPre-procurement PHI assessment; no PHI access before BAA execution
BAA does not include breach notification provisionsCE may not learn of breach timely; notification deadlines missedUse standard template with mandatory breach reporting within 5 days
BAA permits BA to use PHI for BA's own purposes (marketing, analytics)Impermissible use of PHI; potential sale of PHI violationRestrict BA use to services performed for CE; prohibit independent use
No subcontractor flow-down requirementsDownstream entities handle PHI without HIPAA obligationsRequire BA to bind subcontractors to equivalent BAA terms
No termination provisions for PHI return/destructionPHI retained indefinitely by former BA without safeguardsMandatory return/destruction clause with certification requirement
Outdated BAA not updated for Omnibus RuleMissing required provisions (subcontractor, breach notification, direct liability acknowledgment)Periodic BAA review aligned with MSA renewal

Enforcement Actions

  • North Memorial Health Care (2016): $1.55 million — failed to execute a BAA with a major contractor that had access to ePHI of 289,904 individuals; failed to conduct organization-wide risk analysis
  • Care New England Health System (2019): $400,000 — failed to execute BAA with BA that experienced a breach; BAA was under negotiation but not signed when PHI was disclosed
  • UMMC (University of Mississippi Medical Center) (2016): $2.75 million — multiple Security Rule violations including failure to manage BA relationships properly

Integration Points

  • hipaa-privacy-rule: BAA requirement stems from Privacy Rule §164.502(e); BA permitted uses mirror Privacy Rule provisions
  • hipaa-security-rule: BA must independently comply with Security Rule; BAA must require appropriate safeguards
  • hipaa-breach-notify: BAA breach notification chain is critical path for timely CE notification and individual notice
  • hipaa-minimum-necessary: BA disclosures must comply with minimum necessary standard

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/hipaa-baa-management of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Hipaa Baa Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hipaa Baa Management compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hipaa Baa Management this skillmukul975/Privacy-Data-Protection-Skills301—~3.8kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
HIPAA Pre-Deployment Compliance Checkmaziyarpanahi/openmed5.5k—~2kAutomated safety check: PassApache-2.0
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT
ISO Standards Readiness EvidenceK-Dense-AI/scientific-agent-skills48k1 repos~4.6kAutomated safety check: NotesMIT
Fda Consultant Specialistdavila7/claude-code-templates33k1 repos~2.7kAutomated safety check: PassMIT

Similar skills

  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Walks a data pipeline against the HIPAA Privacy and Security Rule checklist and produces a gap report before it processes patient data.

    5.5k GitHub stars~2k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • ISO Standards Readiness Evidence

    K-Dense-AI/scientific-agent-skills

    Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.

    48k GitHub starsUsed in 1 repo~4.6k tokens
    Legal & ComplianceAuto-check: notes
  • Fda Consultant Specialist

    davila7/claude-code-templates

    Senior FDA consultant and specialist for medical device companies including HIPAA compliance and requirement management.

    33k GitHub starsUsed in 1 repo~2.7k tokens
    Legal & ComplianceAuto-check passed
  • Grc Knowledge

    mlunato47/claude-grc-plugin

    Senior GRC analyst expertise across 18 compliance frameworks — NIST 800-53, FedRAMP (Rev5 + 20x/CR26, KSIs, VDR/VER, Certification Classes A–D), DoD/DoW Impact Levels (IL2–IL6, DISA Cloud SRG), ITAR…

    184 GitHub stars~6.1k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Hipaa Baa Management

What does Hipaa Baa Management do?

Manages HIPAA Business Associate Agreements under 45 CFR §164.502(e) and §164.504(e). Hipaa Baa Management is an agent skill from mukul975/Privacy-Data-Protection-Skills.504(e).

When should I use Hipaa Baa Management?

Hipaa Baa Management fits situations like: tasks that involve Healthcare and finance regulation.

How do I install Hipaa Baa Management in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-baa-management -a claude-code`. Or copy the skill folder (skills/privacy/hipaa-baa-management in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/hipaa-baa-management in your project. Claude Code loads it when a task matches its description.

How do I install Hipaa Baa Management in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-baa-management -a codex`. Or copy the skill folder (skills/privacy/hipaa-baa-management in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/hipaa-baa-management in your project. Codex loads it when a task matches its description.

Can I use Hipaa Baa Management in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-baa-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hipaa-baa-management, .gemini/skills/hipaa-baa-management, .github/skills/hipaa-baa-management and .opencode/skills/hipaa-baa-management in your project.

What does Hipaa Baa Management need to run?

Going by SKILL.md and its folder, Hipaa Baa Management needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Hipaa Baa Management access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hipaa Baa Management safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Hipaa Baa Management use?

Hipaa Baa Management is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hipaa Baa Management use?

About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.7k tokens, read only when the agent opens those files.

What are the alternatives to Hipaa Baa Management?

Skills that share tags, products or a category with Hipaa Baa Management: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), HIPAA Pre-Deployment Compliance Check (maziyarpanahi/openmed, 5.5k stars), Hipaa Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars) and ISO Standards Readiness Evidence (K-Dense-AI/scientific-agent-skills, 48k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hipaa Baa Management?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.