Agent skill

Hipaa Risk Analysis

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Conducts HIPAA risk analysis per 45 CFR §164.308(a)(1) following OCR guidance methodology.

Apache-2.0Auto-check passedLegal & Compliance

Install Hipaa Risk Analysis

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-risk-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills hipaa-risk-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/hipaa-risk-analysis .claude/skills/hipaa-risk-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hipaa-risk-analysis
GitHub stars
301
Token cost
~4.1k tokens
SKILL.md length
1,862 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Conducts HIPAA risk analysis per 45 CFR §164.308(a)(1) following OCR guidance methodology.

  • Works in 6 steps: The scope covered all ePHI → Threats and vulnerabilities were… → Current security measures were evaluated → …
  • Tasks that involve Healthcare and finance regulation
  • SKILL.md covers Overview, Legal Foundation, OCR Nine Essential Elements and Risk Management and Mitigation…, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Hipaa Risk Analysis is an agent skill from mukul975/Privacy-Data-Protection-Skills. Conducts HIPAA risk analysis per 45 CFR §164.308(a)(1) following OCR guidance methodology. Covers threat identification, vulnerability assessment, likelihood and impact determination, risk scoring, and mitigation planning for electronic protected health information. Keywords: HIPAA risk analysis, OCR guidance, threat assessment, vulnerability, risk management, ePHI.

Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Healthcare and finance regulation and Vulnerability scanning. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Healthcare and finance regulation
  • Tasks that involve Vulnerability scanning

Example prompts

  • “Use the hipaa-risk-analysis skill to conduct HIPAA risk analysis per 45 CFR §164.308(a)(1) following OCR guidance methodology”
  • “/hipaa-risk-analysis”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. The scope covered all ePHI
  2. Threats and vulnerabilities were comprehensively identified
  3. Current security measures were evaluated
  4. Likelihood and impact were assessed using a consistent methodology
  5. Risk levels were determined
  6. The analysis was conducted by qualified personnel

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hipaa Risk Analysis loads about 4.1k tokens when it runs, and up to ~6.2k if it reads all its reference files. Until then it costs about 97 tokens; SKILL.md has 1,862 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~97
When it runs · the whole SKILL.md, loaded when a task matches
~4.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,862 words, ~4,086 tokens.

Download SKILL.mdSave it as .claude/skills/hipaa-risk-analysis/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
hipaa-risk-analysis
description
Conducts HIPAA risk analysis per 45 CFR §164.308(a)(1) following OCR guidance methodology. Covers threat identification, vulnerability assessment, likelihood and impact determination, risk scoring, and mitigation planning for electronic protected health information. Keywords: HIPAA risk analysis, OCR guidance, threat assessment, vulnerability, risk management, ePHI.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
healthcare-privacy
metadata.tags
hipaa, risk-analysis, ocr-guidance, threat-assessment, vulnerability, risk-management, ephi

HIPAA Risk Analysis — 45 CFR §164.308(a)(1)

Overview

The HIPAA Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI held by the organization. Risk analysis under §164.308(a)(1)(ii)(A) is the foundational requirement of the Security Rule — it drives all subsequent safeguard decisions. OCR has identified failure to conduct a comprehensive, enterprise-wide risk analysis as the most common finding in breach investigations and compliance reviews. The risk analysis must be ongoing, not a one-time event, and must be updated whenever significant changes occur in the environment or in response to security incidents.

Regulatory Text

45 CFR §164.308(a)(1)(ii)(A) — Risk Analysis (Required):

"Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate."

45 CFR §164.308(a)(1)(ii)(B) — Risk Management (Required):

"Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level to comply with §164.306(a)."

OCR Guidance Documents

OCR published "Guidance on Risk Analysis Requirements under the HIPAA Security Rule" (July 14, 2010) establishing nine essential elements that an adequate risk analysis must address. This guidance, while not binding regulation, represents OCR's enforcement expectations and has been consistently applied in settlement agreements and corrective action plans.

OCR Nine Essential Elements

Element 1: Scope of the Analysis

The risk analysis must encompass all ePHI that the organization creates, receives, maintains, or transmits, in every form and location:

Asclepius Health Network Scope Inventory:

ePHI LocationSystem/MediumData CategoriesVolume
Electronic Health Record (Epic)Production servers, disaster recovery siteComplete clinical records, demographics, insurance4.2 million patient records
Practice Management SystemCloud-hosted (Azure US East)Scheduling, billing, referrals4.2 million patients
Laboratory Information SystemOn-premises serversLab orders, results, specimen tracking12 million results annually
Radiology PACSOn-premises SAN storageDiagnostic images, reports850 TB imaging data
Email System (Exchange Online)Microsoft 365 tenantIncidental ePHI in clinical communicationsEstimated 15,000 messages/day containing ePHI
Mobile Devices3,200 organization-owned tablets, 800 BYOD smartphonesClinical reference, secure messaging, patient photosVariable
Medical Devices1,400 networked devices (infusion pumps, monitors, ventilators)Real-time patient data, device logsContinuous streaming
Paper-to-digital ConversionScanning workstations, OCR serversScanned historical records, faxed referrals2,000 pages/day
Business Associate Systems47 BA relationships with ePHI accessVaries by BA (billing, transcription, cloud hosting, analytics)Varies
Backup and ArchiveTape library, offsite vault, cloud archiveComplete system backups6-year retention
Health Information ExchangeRegional HIE platformADT feeds, CCD documents, lab results150,000 transactions/month
Element 2: Data Collection

Identify and document where ePHI is stored, received, maintained, or transmitted. Methods include:

  • Automated discovery: Network scanning tools identifying systems communicating health data (HL7, FHIR, DICOM traffic analysis)
  • Data flow mapping: Documenting how ePHI moves between systems, departments, and external parties
  • Workforce interviews: Structured interviews with department managers, clinical informaticists, and IT staff
  • System inventory review: Cross-referencing CMDB (Configuration Management Database) with ePHI classification tags
  • Vendor assessment questionnaire responses: BA-reported ePHI handling practices
  • Physical walkthroughs: Identifying workstations, printers, fax machines, and storage locations processing ePHI
Element 3: Identify and Document Potential Threats and Vulnerabilities
Threat Categories
Threat CategorySpecific ThreatsSource
NaturalFlood, earthquake, tornado, hurricane, wildfire, pandemicGeographic and climate risk assessment
Human — IntentionalHacking/IT incident, ransomware, phishing, insider theft, social engineering, nation-state APTFBI IC3 reports, HHS cybersecurity alerts, threat intelligence feeds
Human — UnintentionalMisdirected email/fax, lost device, improper disposal, misconfiguration, training failureIncident history, OCR breach portal patterns
EnvironmentalPower failure, HVAC failure, water damage, fire, electromagnetic interferenceFacility assessments, utility reliability data
TechnicalSoftware vulnerability, hardware failure, network outage, cryptographic weaknessCVE databases, vendor advisories, penetration test results
Vulnerability Assessment Methods
  • Penetration testing: Annual external and internal penetration test by independent third party
  • Vulnerability scanning: Weekly automated scans of all network-connected assets (Qualys, Nessus, or equivalent)
  • Configuration auditing: Quarterly review of system configurations against CIS benchmarks
  • Social engineering testing: Semi-annual phishing simulations; annual physical penetration attempts
  • Application security testing: SAST/DAST scanning of internally developed applications; third-party code review for critical systems
  • Wireless security assessment: Quarterly rogue access point scanning; annual wireless penetration test
Element 4: Assess Current Security Measures

Document existing safeguards and their effectiveness:

Asclepius Health Network Current Controls Assessment (Sample):

Control AreaImplemented MeasureEffectiveness RatingGap Identified
Access ControlRole-based access in EHR with unique user IDsEffectiveQuarterly access reviews not consistently completed for all departments
Encryption at RestAES-256 FDE on servers and endpointsEffective12 legacy medical devices running unencrypted embedded systems
Encryption in TransitTLS 1.2+ enforced on all external connectionsEffective3 internal legacy interfaces still using TLS 1.0
Audit LoggingCentralized SIEM with 6-year retentionEffectiveLog review staffing insufficient for alert volume
BackupDaily incremental, weekly full, offsite replicationEffectiveRestore testing frequency needs improvement
Physical SecurityBadge access, CCTV, visitor managementPartially EffectiveServer room access badge list includes 15 individuals who no longer require access
Anti-MalwareEDR deployed on all managed endpointsEffectiveCoverage gap on BYOD devices with MDM enrollment below 100%
Patch ManagementMonthly patch cycle, 14-day critical patch SLAPartially EffectiveMedical device patching delayed by manufacturer certification requirements
Element 5: Determine the Likelihood of Threat Occurrence

Assign likelihood ratings based on threat capability, motivation, and existing controls:

Likelihood LevelDefinitionScoring
Very HighAlmost certain to occur within the next year; active exploitation observed5
HighLikely to occur; threat source is capable and motivated; controls have known weaknesses4
MediumPossible occurrence; threat source exists and has some capability; controls are partially effective3
LowUnlikely but possible; limited threat capability or motivation; controls are generally effective2
Very LowRemote possibility; no known threat source targeting this vulnerability; strong controls in place1
Element 6: Determine the Potential Impact of Threat Occurrence

Assess the magnitude of harm if a threat exploits a vulnerability:

Impact LevelDefinitionExamplesScoring
CriticalCatastrophic harm to individuals or organizationBreach of >500K records, permanent patient harm from data integrity failure, organizational insolvency5
HighSignificant harm to many individuals or severe organizational impactBreach of 10K-500K records, extended system outage affecting patient care, OCR investigation4
MediumModerate harm to limited individuals or substantial operational disruptionBreach of 500-10K records, multi-day system unavailability, significant remediation costs3
LowLimited harm to few individuals or manageable operational impactBreach of <500 records, brief system disruption, contained incident2
NegligibleMinimal or no harmNo ePHI exposure confirmed, minor operational inconvenience1
Show full SKILL.md (779 more words)Show less
Element 7: Determine the Level of Risk

Risk is calculated as the product of likelihood and impact:

Risk Score = Likelihood × Impact
Risk ScoreRisk LevelAction Required
20-25CriticalImmediate mitigation required; senior leadership notification; consider system suspension
12-19HighMitigation plan required within 30 days; management approval to accept risk
6-11MediumMitigation plan required within 90 days; documented risk acceptance alternative
2-5LowMonitor and address in normal operations; annual review
1MinimalAccept and document; review at next scheduled risk analysis

Asclepius Health Network Risk Register (Sample Entries):

Risk IDThreat/VulnerabilityLikelihoodImpactRisk ScoreRisk Level
R-001Ransomware attack on clinical systems4 (High)5 (Critical)20Critical
R-002Insider unauthorized access to celebrity patient records4 (High)3 (Medium)12High
R-003Unencrypted legacy medical device data exposure3 (Medium)4 (High)12High
R-004Phishing leading to credential compromise4 (High)4 (High)16High
R-005Lost/stolen unencrypted mobile device2 (Low)3 (Medium)6Medium
R-006Misdirected fax containing ePHI3 (Medium)2 (Low)6Medium
R-007Natural disaster affecting primary data center2 (Low)5 (Critical)10Medium
Element 8: Finalize Documentation

The risk analysis must be documented in sufficient detail to demonstrate:

  1. The scope covered all ePHI
  2. Threats and vulnerabilities were comprehensively identified
  3. Current security measures were evaluated
  4. Likelihood and impact were assessed using a consistent methodology
  5. Risk levels were determined
  6. The analysis was conducted by qualified personnel

Required Documentation Components:

  • Date of analysis and date range covered
  • Personnel conducting the analysis (names, qualifications)
  • Methodology description
  • Complete asset inventory with ePHI classification
  • Threat and vulnerability catalog
  • Current controls inventory
  • Risk scoring matrix and ratings
  • Risk register with all identified risks
  • Executive summary for leadership
Element 9: Periodic Review and Updates

The risk analysis is not a one-time activity. It must be updated:

  • At least annually as a scheduled comprehensive review
  • When new systems, applications, or technologies are implemented
  • When significant changes to the operating environment occur (mergers, relocations, new facilities)
  • After a security incident or breach
  • When new threats are identified (new malware families, regulatory changes, threat intelligence alerts)
  • When OCR or industry guidance identifies new risk areas

Risk Management and Mitigation Planning — §164.308(a)(1)(ii)(B)

For each risk above the organization's acceptable risk threshold, develop and implement a mitigation plan:

Mitigation Plan Template (Risk R-001: Ransomware):

ElementDetail
Risk IDR-001
Risk DescriptionRansomware attack encrypting clinical systems, rendering ePHI unavailable
Current Risk Score20 (Critical)
Mitigation Measures(1) Deploy advanced EDR with behavioral ransomware detection; (2) Implement network segmentation isolating clinical systems; (3) Maintain immutable backup copies with air-gapped storage; (4) Conduct quarterly tabletop ransomware exercises; (5) Implement application whitelisting on clinical workstations
Implementation TimelineEDR: Complete; Segmentation: 60 days; Immutable backups: 90 days; Tabletop: Quarterly; Whitelisting: 120 days
Responsible PartyCISO (overall); Network Engineering (segmentation); Backup Administrator (immutable backups)
Target Risk Score8 (Medium) — likelihood reduced from 4 to 2 through layered controls
Residual Risk AcceptanceApproved by CIO and CPO on documented risk acceptance form
Review DateNext comprehensive review or 90 days post-implementation

Common OCR Findings

OCR consistently identifies the following deficiencies in risk analyses:

  1. Not enterprise-wide: Analysis limited to EHR system only, excluding email, mobile devices, medical devices, and BA systems
  2. Not updated: One-time analysis without periodic review or updates after significant changes
  3. Not thorough: Failure to identify all ePHI assets, particularly shadow IT, personal devices, and cloud services
  4. No documentation: Analysis conducted informally without written documentation
  5. No risk management follow-through: Risks identified but no mitigation plans developed or implemented
  6. Inadequate methodology: No structured approach to likelihood/impact determination; subjective risk ratings without defined criteria

Enforcement Actions for Risk Analysis Failures

Risk analysis deficiency is cited in the majority of OCR enforcement actions:

  • Anthem Inc. (2018): $16 million — failed to conduct enterprise-wide risk analysis prior to breach affecting 78.8 million
  • Premera Blue Cross (2020): $6.85 million — risk analysis failed to identify risks across the enterprise; did not assess all systems with ePHI
  • Banner Health (2023): $1.25 million — risk analysis was not accurate and thorough; did not identify all risks to ePHI
  • CHSPSC LLC (2020): $2.3 million — failed to conduct accurate risk analysis and implement risk management measures
  • University of Massachusetts Amherst (2020): $650,000 — failure to conduct risk analysis of ePHI maintained by research programs
  • Metro Community Provider Network (2017): $400,000 — risk analysis not conducted to sufficient depth

Integration Points

  • hipaa-security-rule: Risk analysis drives implementation decisions for all technical, administrative, and physical safeguards
  • hipaa-breach-notify: Post-breach risk analysis updates feed into breach risk assessment under §164.402
  • hipaa-baa-management: Risk analysis must include ePHI held by or accessible to business associates
  • hipaa-privacy-rule: Privacy risk assessments complement security risk analysis for comprehensive PHI protection

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/hipaa-risk-analysis of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Hipaa Risk Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hipaa Risk Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hipaa Risk Analysis this skillmukul975/Privacy-Data-Protection-Skills301—~4.1kAutomated safety check: PassApache-2.0
Senior Secopsalirezarezvani/claude-skills28k1 repos~4kAutomated safety check: PassMIT
Senior Secopsborghei/Claude-Skills891—~1.7kAutomated safety check: PassMIT
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
HIPAA Pre-Deployment Compliance Checkmaziyarpanahi/openmed5.5k—~2kAutomated safety check: PassApache-2.0
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • Senior Secops

    alirezarezvani/claude-skills

    Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices.

    28k GitHub starsUsed in 1 repo~4k tokens
    SecurityAuto-check passed
  • Senior Secops

    borghei/Claude-Skills

    SecOps for application security, vulnerability management, compliance, and secure development.

    891 GitHub stars~1.7k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Walks a data pipeline against the HIPAA Privacy and Security Rule checklist and produces a gap report before it processes patient data.

    5.5k GitHub stars~2k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • ISO Standards Readiness Evidence

    K-Dense-AI/scientific-agent-skills

    Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.

    48k GitHub starsUsed in 1 repo~4.6k tokens
    Legal & ComplianceAuto-check: notes

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Hipaa Risk Analysis

What does Hipaa Risk Analysis do?

Conducts HIPAA risk analysis per 45 CFR §164.308(a)(1) following OCR guidance methodology. Hipaa Risk Analysis is an agent skill from mukul975/Privacy-Data-Protection-Skills.308(a)(1) following OCR guidance methodology.

When should I use Hipaa Risk Analysis?

Hipaa Risk Analysis fits situations like: tasks that involve Healthcare and finance regulation; tasks that involve Vulnerability scanning.

How do I install Hipaa Risk Analysis in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-risk-analysis -a claude-code`. Or copy the skill folder (skills/privacy/hipaa-risk-analysis in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/hipaa-risk-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Hipaa Risk Analysis in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-risk-analysis -a codex`. Or copy the skill folder (skills/privacy/hipaa-risk-analysis in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/hipaa-risk-analysis in your project. Codex loads it when a task matches its description.

Can I use Hipaa Risk Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-risk-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hipaa-risk-analysis, .gemini/skills/hipaa-risk-analysis, .github/skills/hipaa-risk-analysis and .opencode/skills/hipaa-risk-analysis in your project.

What does Hipaa Risk Analysis need to run?

Going by SKILL.md and its folder, Hipaa Risk Analysis needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Hipaa Risk Analysis access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hipaa Risk Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Hipaa Risk Analysis use?

Hipaa Risk Analysis is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hipaa Risk Analysis use?

About 4.1k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.1k tokens, read only when the agent opens those files.

What are the alternatives to Hipaa Risk Analysis?

Skills that share tags, products or a category with Hipaa Risk Analysis: Senior Secops (alirezarezvani/claude-skills, 28k stars), Senior Secops (borghei/Claude-Skills, 891 stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars) and HIPAA Pre-Deployment Compliance Check (maziyarpanahi/openmed, 5.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hipaa Risk Analysis?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.