Healthcare Phi Compliance
affaan-m/ECC
Protected Health Information (PHI) and PII compliance patterns for healthcare applications: data classification, row-level access control, tamper-proof audit trails, schema tagging, and common leak…
Implements HIPAA Security Rule technical safeguards under 45 CFR §164.312 for electronic protected health information.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-security-rule -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills hipaa-security-rule --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/hipaa-security-rule .claude/skills/hipaa-security-rule && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "hipaa-security-rule" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/hipaa-security-rule into .claude/skills/hipaa-security-rule/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hipaa-security-rule", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/hipaa-security-ruleType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-security-rule -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills hipaa-security-rule --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/hipaa-security-rule .agents/skills/hipaa-security-rule && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "hipaa-security-rule" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/hipaa-security-rule into .agents/skills/hipaa-security-rule/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hipaa-security-rule", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-security-rule -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills hipaa-security-rule --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/hipaa-security-rule .cursor/skills/hipaa-security-rule && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "hipaa-security-rule" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/hipaa-security-rule into .cursor/skills/hipaa-security-rule/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hipaa-security-rule", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/hipaa-security-rule--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-security-rule -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills hipaa-security-rule --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/hipaa-security-rule .gemini/skills/hipaa-security-rule && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "hipaa-security-rule" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/hipaa-security-rule into .gemini/skills/hipaa-security-rule/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hipaa-security-rule", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills hipaa-security-ruleInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-security-rule -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/hipaa-security-rule .github/skills/hipaa-security-rule && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "hipaa-security-rule" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/hipaa-security-rule into .github/skills/hipaa-security-rule/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hipaa-security-rule", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-security-rule -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills hipaa-security-rule --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/hipaa-security-rule .opencode/skills/hipaa-security-rule && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "hipaa-security-rule" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/hipaa-security-rule into .opencode/skills/hipaa-security-rule/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hipaa-security-rule", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
hipaa-security-ruleImplements HIPAA Security Rule technical safeguards under 45 CFR §164.312 for electronic protected health information.
Hipaa Security Rule is an agent skill from mukul975/Privacy-Data-Protection-Skills. Implements HIPAA Security Rule technical safeguards under 45 CFR §164.312 for electronic protected health information. Covers access controls with unique user identification, emergency access procedures, automatic logoff, encryption, audit controls, integrity controls, and transmission security. Keywords: HIPAA Security Rule, ePHI, access controls, encryption, audit controls, technical safeguards.
Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Legal & Compliance, covering Healthcare and finance regulation and Authorization and RBAC. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Hipaa Security Rule loads about 4.1k tokens when it runs, and up to ~7.1k if it reads all its reference files. Until then it costs about 105 tokens; SKILL.md has 1,775 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,775 words, ~4,051 tokens.
.claude/skills/hipaa-security-rule/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.The HIPAA Security Rule establishes national standards for protecting electronic protected health information (ePHI) that is created, received, used, or maintained by a covered entity or business associate. Published as a final rule on February 20, 2003 (68 FR 8334), with compliance required by April 20, 2005 (April 20, 2006 for small health plans), the Security Rule operationalizes the Privacy Rule's confidentiality protections through administrative, physical, and technical safeguards. The rule adopts a risk-based, technology-neutral approach — it specifies what must be achieved but allows flexibility in how covered entities implement protections based on their size, complexity, and capabilities.
The Security Rule applies only to ePHI, unlike the Privacy Rule which covers PHI in all forms. The rule organizes its requirements into three safeguard categories (administrative §164.308, physical §164.310, technical §164.312) plus organizational requirements (§164.314) and policies/procedures/documentation (§164.316).
Technical safeguards are the technology and related policies and procedures that protect ePHI and control access to it. Each standard has required implementation specifications (mandatory) and addressable implementation specifications (must be implemented if reasonable and appropriate, with documented rationale if an alternative measure is adopted or the specification is not implemented).
Standard: Implement technical policies and procedures for electronic information systems that maintain ePHI to allow access only to those persons or software programs that have been granted access rights.
| Implementation Specification | Type | Requirement |
|---|---|---|
| Unique User Identification — §164.312(a)(2)(i) | Required | Assign a unique name and/or number for identifying and tracking user identity |
| Emergency Access Procedure — §164.312(a)(2)(ii) | Required | Establish and implement procedures for obtaining necessary ePHI during an emergency |
| Automatic Logoff — §164.312(a)(2)(iii) | Addressable | Implement electronic procedures that terminate an electronic session after a predetermined time of inactivity |
| Encryption and Decryption — §164.312(a)(2)(iv) | Addressable | Implement a mechanism to encrypt and decrypt ePHI |
Every workforce member, administrator, and system account accessing ePHI must have a unique identifier. Shared accounts and generic logins are prohibited.
Asclepius Health Network Implementation:
[first initial][last name][employee number] (e.g., jsmith4821)svc-[application]-[function] (e.g., svc-epic-hl7)adm-jsmith4821)Covered entities must have documented procedures for accessing ePHI during emergencies when normal access controls cannot function.
Asclepius Health Network Implementation:
Asclepius Health Network Implementation:
Although addressable, OCR has consistently found that failing to encrypt ePHI without documented equivalent alternative measures constitutes a Security Rule violation.
Asclepius Health Network Implementation:
Standard: Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use ePHI.
No implementation specifications are designated — the standard itself is required.
Asclepius Health Network Implementation:
What is logged:
Log management:
Audit triggers and alerts:
| Trigger | Response SLA | Action |
|---|---|---|
| 5+ failed login attempts in 10 minutes | Immediate | Account lockout, alert to SOC |
| Access to VIP/employee patient records | Immediate | Alert to Privacy Office for review |
| Bulk record access (>50 records in 1 hour by single user) | 15 minutes | SOC review, possible account suspension |
| After-hours access from unusual location | 1 hour | Review by SOC next business day or immediate if high risk |
| Break-the-glass event | 24 hours | Privacy Office justification review |
| Administrative privilege escalation | Immediate | SOC verification of change ticket |
Standard: Implement policies and procedures to protect ePHI from improper alteration or destruction.
| Implementation Specification | Type | Requirement |
|---|---|---|
| Mechanism to Authenticate ePHI — §164.312(c)(2) | Addressable | Implement electronic mechanisms to corroborate that ePHI has not been altered or destroyed in an unauthorized manner |
Asclepius Health Network Implementation:
Standard: Implement procedures to verify that a person or entity seeking access to ePHI is the one claimed. This standard is required with no implementation specifications.
Asclepius Health Network Implementation:
Standard: Implement technical security measures to guard against unauthorized access to ePHI that is being transmitted over an electronic communications network.
| Implementation Specification | Type | Requirement |
|---|---|---|
| Integrity Controls — §164.312(e)(2)(i) | Addressable | Implement security measures to ensure electronically transmitted ePHI is not improperly modified without detection |
| Encryption — §164.312(e)(2)(ii) | Addressable | Implement a mechanism to encrypt ePHI whenever deemed appropriate |
Asclepius Health Network Implementation:
| Implementation Specification | Type |
|---|---|
| Risk Analysis | Required |
| Risk Management | Required |
| Sanction Policy | Required |
| Information System Activity Review | Required |
| Implementation Specification | Type |
|---|---|
| Authorization and/or Supervision | Addressable |
| Workforce Clearance Procedure | Addressable |
| Termination Procedures | Addressable |
| Implementation Specification | Type |
|---|---|
| Isolating Healthcare Clearinghouse Functions | Required |
| Access Authorization | Addressable |
| Access Establishment and Modification | Addressable |
| Implementation Specification | Type |
|---|---|
| Security Reminders | Addressable |
| Protection from Malicious Software | Addressable |
| Log-in Monitoring | Addressable |
| Password Management | Addressable |
| Implementation Specification | Type |
|---|---|
| Response and Reporting | Required |
| Implementation Specification | Type |
|---|---|
| Data Backup Plan | Required |
| Disaster Recovery Plan | Required |
| Emergency Mode Operation Plan | Required |
| Testing and Revision Procedures | Addressable |
| Applications and Data Criticality Analysis | Addressable |
Addressable specifications: Contingency operations, facility security plan, access control and validation procedures, maintenance records.
Required standard specifying appropriate physical environment and manner of use for workstations accessing ePHI.
Required standard implementing physical safeguards restricting access to workstations that access ePHI.
Required specifications for disposal and media re-use; addressable specifications for accountability and data backup/storage.
OCR has clarified that "addressable" does not mean "optional." For each addressable specification, covered entities must:
OCR enforcement actions have found violations where entities failed to encrypt ePHI (addressable) without documenting any alternative measure. In practice, encryption of ePHI at rest and in transit is expected by OCR absent extraordinary documented justification.
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/hipaa-security-rule of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Hipaa Security Rule next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Hipaa Security Rule this skillmukul975/Privacy-Data-Protection-Skills | 301 | — | ~4.1k | Automated safety check: Pass | Apache-2.0 | |
| Healthcare Phi Complianceaffaan-m/ECC | 276k | 1 repos | ~1.4k | Automated safety check: Pass | MIT | |
| Policy OpaAgentSecOps/SecOpsAgentKit | 220 | 1 repos | ~3.5k | Automated safety check: Pass | Custom licence | |
| Implementing Delinea Secret Server For Pammukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~4.3k | Automated safety check: Pass | Apache-2.0 | |
| Implementing Network Access Controlmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.8k | Automated safety check: Notes | Apache-2.0 | |
| HealthclawLeoYeAI/openclaw-master-skills | 2.2k | — | ~4.9k | Automated safety check: Pass | MIT |
affaan-m/ECC
Protected Health Information (PHI) and PII compliance patterns for healthcare applications: data classification, row-level access control, tamper-proof audit trails, schema tagging, and common leak…
AgentSecOps/SecOpsAgentKit
Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA).
mukul975/Anthropic-Cybersecurity-Skills
Implements Delinea Secret Server for privileged access management, covering secret vault configuration, role-based access policies, automated password rotation, session recording, and Active…
mukul975/Anthropic-Cybersecurity-Skills
Implements 802.1X port-based network access control using RADIUS authentication, PacketFence NAC, and switch configuration to enforce identity-based access policies, posture assessment, and…
LeoYeAI/openclaw-master-skills
AI-native hospital and multi-department healthcare ERP. An agent skill from LeoYeAI/openclaw-master-skills.
automateyournetwork/netclaw
Cisco ISE posture and policy audit - authorization rules, posture compliance, profiling gaps, TrustSec SGT matrix, active session health.
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
Categories
Implements HIPAA Security Rule technical safeguards under 45 CFR §164.312 for electronic protected health information. Hipaa Security Rule is an agent skill from mukul975/Privacy-Data-Protection-Skills.312 for electronic protected health information.
Hipaa Security Rule fits situations like: tasks that involve Healthcare and finance regulation; tasks that involve Authorization and RBAC.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-security-rule -a claude-code`. Or copy the skill folder (skills/privacy/hipaa-security-rule in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/hipaa-security-rule in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-security-rule -a codex`. Or copy the skill folder (skills/privacy/hipaa-security-rule in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/hipaa-security-rule in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-security-rule -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hipaa-security-rule, .gemini/skills/hipaa-security-rule, .github/skills/hipaa-security-rule and .opencode/skills/hipaa-security-rule in your project.
Going by SKILL.md and its folder, Hipaa Security Rule needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Hipaa Security Rule is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.1k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Hipaa Security Rule: Healthcare Phi Compliance (affaan-m/ECC, 276k stars), Policy Opa (AgentSecOps/SecOpsAgentKit, 220 stars), Implementing Delinea Secret Server For Pam (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Implementing Network Access Control (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.