Agent skill

Hipaa Deidentification

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Implements HIPAA de-identification methods under 45 CFR §164.514(a)-(b).

Apache-2.0Auto-check passedLegal & Compliance

Install Hipaa Deidentification

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-deidentification -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills hipaa-deidentification --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/hipaa-deidentification .claude/skills/hipaa-deidentification && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hipaa-deidentification
GitHub stars
297
Token cost
~4k tokens
SKILL.md length
2,022 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Implements HIPAA de-identification methods under 45 CFR §164.514(a)-(b).

  • Works in 4 steps: Threat Modeling → Risk Quantification → Transformation Application → …
  • Tasks that involve Healthcare and finance regulation
  • SKILL.md covers Overview, Legal Framework, Method 1: Expert Determination… and Method 2: Safe Harbor —…, plus 5 more sections
  • Runs Python scripts from its folder

What it does

Hipaa Deidentification is an agent skill from mukul975/Privacy-Data-Protection-Skills. Implements HIPAA de-identification methods under 45 CFR §164.514(a)-(b). Covers expert determination method and safe harbor method with 18 identifiers removal, re-identification risk assessment, limited dataset requirements, and data use agreements. Keywords: HIPAA de-identification, safe harbor, expert determination, 18 identifiers, limited dataset, PHI.

Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Healthcare and finance regulation. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Healthcare and finance regulation

Example prompts

  • “Use the hipaa-deidentification skill to implement HIPAA de-identification methods under 45 CFR §164.514(a)-(b)”
  • “/hipaa-deidentification”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Threat Modeling
  2. Risk Quantification
  3. Transformation Application
  4. Documentation

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hipaa Deidentification loads about 4k tokens when it runs, and up to ~6.2k if it reads all its reference files. Until then it costs about 95 tokens; SKILL.md has 2,022 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~95
When it runs · the whole SKILL.md, loaded when a task matches
~4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 2,022 words, ~4,034 tokens.

Download SKILL.mdSave it as .claude/skills/hipaa-deidentification/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
hipaa-deidentification
description
Implements HIPAA de-identification methods under 45 CFR §164.514(a)-(b). Covers expert determination method and safe harbor method with 18 identifiers removal, re-identification risk assessment, limited dataset requirements, and data use agreements. Keywords: HIPAA de-identification, safe harbor, expert determination, 18 identifiers, limited dataset, PHI.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
healthcare-privacy
metadata.tags
hipaa, de-identification, safe-harbor, expert-determination, 18-identifiers, limited-dataset, phi

HIPAA De-Identification Methods — 45 CFR §164.514(a)-(b)

Overview

De-identification is the process by which protected health information (PHI) is stripped of identifying elements such that it no longer identifies an individual and there is no reasonable basis to believe it can be used to identify an individual. Under 45 CFR §164.514(a), health information that has been de-identified is no longer PHI and is not subject to the HIPAA Privacy Rule. HIPAA provides two permissible methods for de-identification: expert determination (§164.514(b)(1)) and safe harbor (§164.514(b)(2)). The choice of method depends on the nature of the data, the intended use, and the organization's risk tolerance and resources. OCR published detailed guidance on de-identification methods in November 2012 (updated September 2023), providing extensive clarification on both methods.

Definition of De-Identified Information — §164.514(a)

Health information is de-identified if it does not identify an individual and if the covered entity has no reasonable basis to believe it can be used to identify an individual. The standard is met by applying either the expert determination or safe harbor method.

Key Distinction: De-Identification vs Anonymization

HIPAA uses the term "de-identification" rather than "anonymization." De-identified data under HIPAA may still carry some theoretical re-identification risk — the standard is "no reasonable basis" to believe identification is possible, not absolute impossibility. This contrasts with GDPR's concept of anonymization, which requires irreversibility.

Method 1: Expert Determination — §164.514(b)(1)

Requirements

A person with appropriate knowledge of and experience with generally accepted statistical and scientific principles and methods for rendering information not individually identifiable must:

  1. Apply such principles and methods to determine that the risk is very small that the information could be used, alone or in combination with other reasonably available information, to identify an individual who is a subject of the information
  2. Document the methods and results of the analysis that justify the determination
Qualified Expert

OCR guidance does not specify required credentials but indicates the expert should have knowledge in:

  • Statistical methods for assessing disclosure risk (k-anonymity, l-diversity, t-closeness)
  • Re-identification attack methodologies (linkage attacks, inference attacks)
  • Publicly available data sources and their linkage potential
  • Health data characteristics and population uniqueness

Typical qualifications include PhD-level training in statistics, biostatistics, data science, or computer science with specialization in privacy or disclosure limitation.

Expert Determination Process
Step 1: Threat Modeling

The expert identifies plausible re-identification scenarios:

Attack TypeDescriptionExample
Prosecutor attackAdversary knows the target is in the dataset and attempts to match recordsResearcher knows a specific person visited the hospital and tries to find their record in a published dataset
Journalist attackAdversary attempts to re-identify any individual in the datasetReporter uses voter registration data to link de-identified hospital discharge records to named individuals
Marketer attackAdversary attempts to re-identify as many individuals as possibleData broker combines de-identified health data with consumer databases
Step 2: Risk Quantification

The expert applies statistical methods to quantify re-identification risk:

Population Uniqueness Analysis: Assess how unique combinations of quasi-identifiers are in the relevant population.

Commonly used metrics:

MetricDefinitionThreshold
k-anonymityEvery record in the dataset is identical to at least k-1 other records with respect to quasi-identifiersk ≥ 5 is commonly accepted; k ≥ 10 for higher sensitivity
l-diversityWithin each equivalence class (k-anonymous group), there are at least l distinct values for sensitive attributesl ≥ 3 to protect against homogeneity attacks
t-closenessDistribution of sensitive attributes within each equivalence class is within distance t of the overall distributiont ≤ 0.15 (application-dependent)
Maximum re-identification probabilityProbability that any single record can be matched to a specific individual≤ 0.04 (4%) — commonly cited by experts; some use 0.05 or 0.09
Step 3: Transformation Application

The expert specifies transformations to reduce risk to an acceptable level:

TransformationApplication
GeneralizationReplace specific values with ranges (age 47 → age 45-49; ZIP 02139 → 021**)
SuppressionRemove records or values that are too unique (suppress records with rare diseases in small populations)
PerturbationAdd controlled noise to numerical values (date of birth shifted by random offset within ±7 days)
AggregationReplace individual-level data with group-level statistics
Top/bottom codingCap extreme values (age >89 → 90+; weight >300 → 300+)
Step 4: Documentation

The expert must document:

  • Qualifications and experience
  • Methodology applied
  • Data analyzed (original and transformed)
  • Risk metrics computed
  • Justification for risk thresholds selected
  • Residual risk assessment
  • Any conditions on data use that affect the risk determination

Asclepius Health Network engages an external expert (PhD biostatistician with healthcare disclosure risk expertise) for expert determination on research datasets. The expert's report is retained as required documentation.

Method 2: Safe Harbor — §164.514(b)(2)

Requirements

Remove the following 18 categories of identifiers of the individual or of relatives, employers, or household members:

#IdentifierRemoval Specification
1NamesAll names
2Geographic dataAll geographic subdivisions smaller than a state. Exception: first 3 digits of ZIP code may be retained if the geographic unit formed by combining all ZIP codes with the same first 3 digits contains more than 20,000 persons (per Census Bureau data). ZIP codes where the 3-digit prefix has ≤20,000 persons must be replaced with 000
3DatesAll elements of dates (except year) directly related to an individual, including birth date, admission date, discharge date, death date. All ages over 89 and all elements of dates (including year) indicative of such age must be aggregated into a single category of 90+
4Telephone numbersAll telephone numbers
5Fax numbersAll fax numbers
6Email addressesAll email addresses
7Social Security numbersAll SSNs
8Medical record numbersAll MRNs
9Health plan beneficiary numbersAll plan IDs
10Account numbersAll account numbers
11Certificate/license numbersAll certificate and license numbers
12Vehicle identifiersAll vehicle identifiers and serial numbers including license plate numbers
13Device identifiersAll device identifiers and serial numbers
14Web URLsAll web Universal Resource Locators
15IP addressesAll Internet Protocol address numbers
16Biometric identifiersIncluding finger and voice prints
17Full-face photographsAnd any comparable images
18Any other unique identifying number, characteristic, or codeExcept as permitted by re-identification under §164.514(c)
Additional Safe Harbor Requirement

The covered entity must have no actual knowledge that the remaining information could be used alone or in combination with other information to identify an individual.

Asclepius Health Network Safe Harbor Implementation

Asclepius Health Network uses an automated de-identification pipeline for data released under the safe harbor method:

  1. Structured data: EHR extraction scripts strip all 18 identifier categories from structured fields. Date fields are transformed to retain year only (or year and quarter if research protocol requires and dates are not directly related to the individual). Ages over 89 are mapped to 90+. ZIP codes are truncated to 3 digits and validated against the Census Bureau threshold table.

  2. Unstructured data (clinical notes): NLP-based named entity recognition (NER) system identifies and redacts names, locations, dates, phone numbers, SSNs, MRNs, email addresses, URLs, and other identifiers in free-text clinical notes. Redacted text is replaced with category-specific tags (e.g., [DATE], [NAME], [LOCATION]). Human review sample (10% of documents) validates NER accuracy.

  3. Imaging data: DICOM header scrubbing removes patient name, ID, dates, institution name, and all private tags. Burned-in annotations on images are reviewed and redacted for identifiers (facial photographs require defacing algorithms).

  4. Quality assurance: Post-de-identification audit scans output datasets for residual identifiers using regular expressions, dictionaries of patient names, and cross-reference against the source dataset. Any residual identifiers trigger re-processing and root cause analysis.

Show full SKILL.md (791 more words)Show less

Re-Identification — §164.514(c)

Code-Based Re-Identification

A covered entity may assign a code or other record identification mechanism to de-identified information, enabling re-identification under the following conditions:

  1. The code is not derived from or related to information about the individual (cannot be a hash of SSN or MRN)
  2. The code is not otherwise capable of being translated to identify the individual
  3. The covered entity does not use or disclose the code for any other purpose
  4. The covered entity does not disclose the mechanism for re-identification

The re-identification key must be maintained securely and separately from the de-identified dataset.

Asclepius Health Network: Research datasets are assigned a study-specific random identifier. The crosswalk (random ID ↔ MRN) is encrypted and stored separately from the de-identified dataset in a restricted-access key management system accessible only to the IRB-approved honest broker.

Limited Data Set — §164.514(e)

Definition

A limited data set is PHI that excludes the following direct identifiers of the individual or of relatives, employers, or household members:

  • Names
  • Street addresses (city, state, ZIP code may be retained)
  • Telephone numbers, fax numbers, email addresses
  • Social Security numbers
  • Medical record numbers, health plan beneficiary numbers, account numbers
  • Certificate/license numbers
  • Vehicle identifiers, device identifiers
  • Web URLs, IP addresses
  • Biometric identifiers
  • Full-face photographs

A limited data set retains dates (birth, admission, discharge, death), city, state, ZIP code, and ages (including over 89).

Data Use Agreement (DUA) — §164.514(e)(4)

A limited data set may be used or disclosed only if the covered entity enters into a data use agreement with the recipient. The DUA must:

  1. Establish the permitted uses and purposes of the limited data set (limited to research, public health, or healthcare operations)
  2. Establish who is permitted to use or receive the limited data set
  3. Provide that the recipient will not use or further disclose the information other than as permitted by the DUA or as required by law
  4. Provide that the recipient will use appropriate safeguards to prevent unauthorized use or disclosure
  5. Provide that the recipient will report any unauthorized use or disclosure to the covered entity
  6. Provide that the recipient will ensure that any agents to whom it provides the limited data set agree to the same restrictions and conditions
  7. Provide that the recipient will not attempt to identify the individuals or contact the individuals
Limited Data Set vs De-Identified Data
FeatureDe-Identified (Safe Harbor)Limited Data Set
HIPAA statusNot PHI; not subject to Privacy RuleStill PHI; subject to Privacy Rule
Dates permittedYear onlyFull dates
Geographic dataFirst 3 digits of ZIP (if population threshold met)City, state, full ZIP code
Ages over 89Must be aggregated to 90+Retained
Agreement requiredNoneData Use Agreement
Permitted usesAny (not PHI)Research, public health, healthcare operations only
Breach notificationNot applicable (not PHI)Required if unsecured

Re-Identification Risk Considerations

Publicly Available Data Sources

The expert determination method requires assessment of "reasonably available" data that could be combined with de-identified health data:

Data SourceRe-Identification RiskAvailability
Voter registration recordsName, address, DOB, genderPublicly available in most states
Property recordsName, address, purchase dateCounty recorder offices; commercial aggregators
News/media reportsSpecific incident details (accident, shooting, notable illness)Internet search
Social mediaSelf-disclosed health information, location, activitiesPublicly posted profiles
Death recordsName, DOB, date of death, causeState vital statistics; SSDI
Court recordsName, address, case detailsPACER; state court systems
Commercial data brokersDemographics, purchasing behavior, inferred attributesCommercially available
OCR Guidance on Re-Identification Risk

OCR has noted that:

  • Small geographic areas (census tracts, block groups) combined with birth dates and gender can uniquely identify a high percentage of the US population
  • Rare diseases and unusual procedures increase uniqueness even after safe harbor de-identification
  • Temporal specificity (exact dates of admission/discharge) combined with institution identity can enable re-identification via news reports
  • The "no actual knowledge" requirement under safe harbor is a substantive obligation, not merely a formality

Enforcement

  • Aetna (2017): Settled with multiple state AGs and OCR for $1.15 million (state AG settlement) plus separate OCR resolution — mailing envelopes with visible window revealed HIV medication status of approximately 12,000 members. While not a de-identification case per se, it demonstrated the risk of identifiable health information exposure through seemingly innocuous channels.

OCR has not imposed penalties specifically for de-identification methodology failures, but has included de-identification review in corrective action plans and emphasized the importance of proper de-identification in guidance documents.

Integration Points

  • hipaa-privacy-rule: De-identification removes data from Privacy Rule scope; failure to properly de-identify means all Privacy Rule requirements apply
  • hipaa-minimum-necessary: De-identification and limited datasets serve minimum necessary purposes for research and analytics
  • healthcare-ai-privacy: AI training data often requires de-identification; model memorization risk can undermine de-identification
  • hipaa-risk-analysis: Re-identification risk assessment parallels security risk analysis methodology

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/hipaa-deidentification of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Hipaa Deidentification next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hipaa Deidentification compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hipaa Deidentification this skillmukul975/Privacy-Data-Protection-Skills297—~4kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
HIPAA Pre-Deployment Compliance Checkmaziyarpanahi/openmed5.5k—~2kAutomated safety check: PassApache-2.0
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~2.3kAutomated safety check: PassMIT
ISO Standards Readiness EvidenceK-Dense-AI/scientific-agent-skills48k1 repos~4.6kAutomated safety check: NotesMIT
Fda Consultant Specialistdavila7/claude-code-templates32k1 repos~2.7kAutomated safety check: PassMIT

Similar skills

  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Walks a data pipeline against the HIPAA Privacy and Security Rule checklist and produces a gap report before it processes patient data.

    5.5k GitHub stars~2k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    943 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • ISO Standards Readiness Evidence

    K-Dense-AI/scientific-agent-skills

    Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.

    48k GitHub starsUsed in 1 repo~4.6k tokens
    Legal & ComplianceAuto-check: notes
  • Fda Consultant Specialist

    davila7/claude-code-templates

    Senior FDA consultant and specialist for medical device companies including HIPAA compliance and requirement management.

    32k GitHub starsUsed in 1 repo~2.7k tokens
    Legal & ComplianceAuto-check passed
  • Grc Knowledge

    mlunato47/claude-grc-plugin

    Senior GRC analyst expertise across 18 compliance frameworks — NIST 800-53, FedRAMP (Rev5 + 20x/CR26, KSIs, VDR/VER, Certification Classes A–D), DoD/DoW Impact Levels (IL2–IL6, DISA Cloud SRG), ITAR…

    184 GitHub stars~6.1k tokensUpdated 3 days ago
    Legal & ComplianceAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    297 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    297 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    297 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    297 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    297 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    297 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Hipaa Deidentification

What does Hipaa Deidentification do?

Implements HIPAA de-identification methods under 45 CFR §164.514(a)-(b). Hipaa Deidentification is an agent skill from mukul975/Privacy-Data-Protection-Skills.514(a)-(b).

When should I use Hipaa Deidentification?

Hipaa Deidentification fits situations like: tasks that involve Healthcare and finance regulation.

How do I install Hipaa Deidentification in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-deidentification -a claude-code`. Or copy the skill folder (skills/privacy/hipaa-deidentification in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/hipaa-deidentification in your project. Claude Code loads it when a task matches its description.

How do I install Hipaa Deidentification in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-deidentification -a codex`. Or copy the skill folder (skills/privacy/hipaa-deidentification in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/hipaa-deidentification in your project. Codex loads it when a task matches its description.

Can I use Hipaa Deidentification in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-deidentification -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hipaa-deidentification, .gemini/skills/hipaa-deidentification, .github/skills/hipaa-deidentification and .opencode/skills/hipaa-deidentification in your project.

What does Hipaa Deidentification need to run?

Going by SKILL.md and its folder, Hipaa Deidentification needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Hipaa Deidentification access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hipaa Deidentification safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Hipaa Deidentification use?

Hipaa Deidentification is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hipaa Deidentification use?

About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.2k tokens, read only when the agent opens those files.

What are the alternatives to Hipaa Deidentification?

Skills that share tags, products or a category with Hipaa Deidentification: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), HIPAA Pre-Deployment Compliance Check (maziyarpanahi/openmed, 5.5k stars), Hipaa Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 943 stars) and ISO Standards Readiness Evidence (K-Dense-AI/scientific-agent-skills, 48k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hipaa Deidentification?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 297 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.