Agent skill

Hipaa Security Rule

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Implements HIPAA Security Rule technical safeguards under 45 CFR §164.312 for electronic protected health information.

Apache-2.0Auto-check passedLegal & Compliance

Install Hipaa Security Rule

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-security-rule -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills hipaa-security-rule --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/hipaa-security-rule .claude/skills/hipaa-security-rule && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hipaa-security-rule
GitHub stars
301
Token cost
~4.1k tokens
SKILL.md length
1,775 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Implements HIPAA Security Rule technical safeguards under 45 CFR §164.312 for electronic protected health information.

  • Works in 3 steps: Assess whether the implementation… → If yes, implement it → If not, document why it is not…
  • Tasks that involve Healthcare and finance regulation
  • SKILL.md covers Overview, Technical Safeguards — §164.312, Administrative Safeguards —… and Physical Safeguards — §164.310…, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Hipaa Security Rule is an agent skill from mukul975/Privacy-Data-Protection-Skills. Implements HIPAA Security Rule technical safeguards under 45 CFR §164.312 for electronic protected health information. Covers access controls with unique user identification, emergency access procedures, automatic logoff, encryption, audit controls, integrity controls, and transmission security. Keywords: HIPAA Security Rule, ePHI, access controls, encryption, audit controls, technical safeguards.

Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Healthcare and finance regulation and Authorization and RBAC. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Healthcare and finance regulation
  • Tasks that involve Authorization and RBAC

Example prompts

  • “Use the hipaa-security-rule skill to implement HIPAA Security Rule technical safeguards under 45 CFR §164.312 for electronic protected health…”
  • “/hipaa-security-rule”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Assess whether the implementation specification is a reasonable and appropriate safeguard in their environment
  2. If yes, implement it
  3. If not, document why it is not reasonable and appropriate AND implement an equivalent alternative measure that is reasonable and…

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hipaa Security Rule loads about 4.1k tokens when it runs, and up to ~7.1k if it reads all its reference files. Until then it costs about 105 tokens; SKILL.md has 1,775 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~105
When it runs · the whole SKILL.md, loaded when a task matches
~4.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,775 words, ~4,051 tokens.

Download SKILL.mdSave it as .claude/skills/hipaa-security-rule/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
hipaa-security-rule
description
Implements HIPAA Security Rule technical safeguards under 45 CFR §164.312 for electronic protected health information. Covers access controls with unique user identification, emergency access procedures, automatic logoff, encryption, audit controls, integrity controls, and transmission security. Keywords: HIPAA Security Rule, ePHI, access controls, encryption, audit controls, technical safeguards.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
healthcare-privacy
metadata.tags
hipaa, security-rule, ephi, access-controls, encryption, audit-controls, technical-safeguards

HIPAA Security Rule — Technical Safeguards 45 CFR §164.312

Overview

The HIPAA Security Rule establishes national standards for protecting electronic protected health information (ePHI) that is created, received, used, or maintained by a covered entity or business associate. Published as a final rule on February 20, 2003 (68 FR 8334), with compliance required by April 20, 2005 (April 20, 2006 for small health plans), the Security Rule operationalizes the Privacy Rule's confidentiality protections through administrative, physical, and technical safeguards. The rule adopts a risk-based, technology-neutral approach — it specifies what must be achieved but allows flexibility in how covered entities implement protections based on their size, complexity, and capabilities.

The Security Rule applies only to ePHI, unlike the Privacy Rule which covers PHI in all forms. The rule organizes its requirements into three safeguard categories (administrative §164.308, physical §164.310, technical §164.312) plus organizational requirements (§164.314) and policies/procedures/documentation (§164.316).

Technical Safeguards — §164.312

Technical safeguards are the technology and related policies and procedures that protect ePHI and control access to it. Each standard has required implementation specifications (mandatory) and addressable implementation specifications (must be implemented if reasonable and appropriate, with documented rationale if an alternative measure is adopted or the specification is not implemented).

Access Control — §164.312(a)(1)

Standard: Implement technical policies and procedures for electronic information systems that maintain ePHI to allow access only to those persons or software programs that have been granted access rights.

Implementation SpecificationTypeRequirement
Unique User Identification — §164.312(a)(2)(i)RequiredAssign a unique name and/or number for identifying and tracking user identity
Emergency Access Procedure — §164.312(a)(2)(ii)RequiredEstablish and implement procedures for obtaining necessary ePHI during an emergency
Automatic Logoff — §164.312(a)(2)(iii)AddressableImplement electronic procedures that terminate an electronic session after a predetermined time of inactivity
Encryption and Decryption — §164.312(a)(2)(iv)AddressableImplement a mechanism to encrypt and decrypt ePHI
Unique User Identification

Every workforce member, administrator, and system account accessing ePHI must have a unique identifier. Shared accounts and generic logins are prohibited.

Asclepius Health Network Implementation:

  • Active Directory assigns unique user IDs in the format [first initial][last name][employee number] (e.g., jsmith4821)
  • Service accounts for application-to-application communication use the format svc-[application]-[function] (e.g., svc-epic-hl7)
  • Privileged administrative accounts are separate from standard user accounts (adm-jsmith4821)
  • All user accounts are tied to the HR system — terminated employees are automatically disabled within 1 hour of separation processing
  • Biometric authentication (fingerprint) is deployed at clinical workstations for single sign-on
  • Multi-factor authentication is required for remote access and administrative functions
Emergency Access Procedure

Covered entities must have documented procedures for accessing ePHI during emergencies when normal access controls cannot function.

Asclepius Health Network Implementation:

  • Break-the-glass procedures allow any clinician to access any patient record during declared emergencies
  • Break-the-glass events generate immediate alerts to the Privacy Office and require post-event justification within 24 hours
  • Disaster recovery accounts with elevated privileges are maintained in sealed envelopes in the IT Operations Center safe
  • Emergency access accounts are tested quarterly and passwords rotated after each test or use
  • The EHR system maintains a separate emergency mode with simplified authentication (badge + PIN) activated during IT system failures
Automatic Logoff

Asclepius Health Network Implementation:

  • Clinical workstations: 5-minute inactivity timeout with screen lock, 15-minute session termination
  • Administrative workstations: 10-minute inactivity timeout with screen lock, 30-minute session termination
  • Patient portal sessions: 15-minute inactivity timeout with session termination
  • Mobile devices (tablets on clinical carts): 2-minute inactivity lock, requiring biometric re-authentication
  • Proximity-based logoff using RFID badges — session locks when clinician's badge moves more than 10 feet from the workstation
Encryption and Decryption

Although addressable, OCR has consistently found that failing to encrypt ePHI without documented equivalent alternative measures constitutes a Security Rule violation.

Asclepius Health Network Implementation:

  • Data at rest: AES-256 encryption on all storage volumes containing ePHI (database tablespace encryption, full disk encryption on endpoints)
  • Data in transit: TLS 1.2 minimum (TLS 1.3 preferred) for all network communications containing ePHI
  • Database field-level encryption for highly sensitive fields (SSN, substance abuse diagnoses, HIV status, mental health notes)
  • Encryption key management through a FIPS 140-2 Level 3 validated hardware security module (HSM)
  • Key rotation: Annual for data-at-rest keys, per-session for TLS, quarterly for application-level encryption keys
Audit Controls — §164.312(b)

Standard: Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use ePHI.

No implementation specifications are designated — the standard itself is required.

Asclepius Health Network Implementation:

What is logged:

  • All authentication events (successful and failed logins, logoffs, account lockouts)
  • All access to ePHI (reads, writes, modifications, deletions) including the specific records accessed
  • All administrative actions (user creation, privilege changes, configuration modifications)
  • All system events (startup, shutdown, errors, backup operations)
  • All network events involving ePHI systems (connections, disconnections, firewall events)
  • Break-the-glass access events with enhanced detail

Log management:

  • Centralized log aggregation using SIEM (Security Information and Event Management) platform
  • Real-time correlation and alerting for suspicious patterns (multiple failed logins, unusual access volumes, after-hours access to records outside care team)
  • Immutable log storage — logs are write-once to prevent tampering
  • Log retention: minimum 6 years (aligned with HIPAA documentation retention requirement under §164.530(j))
  • Daily automated log review reports provided to the Security Operations Center
  • Monthly audit sample: random selection of 50 patient records reviewed for access appropriateness

Audit triggers and alerts:

TriggerResponse SLAAction
5+ failed login attempts in 10 minutesImmediateAccount lockout, alert to SOC
Access to VIP/employee patient recordsImmediateAlert to Privacy Office for review
Bulk record access (>50 records in 1 hour by single user)15 minutesSOC review, possible account suspension
After-hours access from unusual location1 hourReview by SOC next business day or immediate if high risk
Break-the-glass event24 hoursPrivacy Office justification review
Administrative privilege escalationImmediateSOC verification of change ticket
Integrity — §164.312(c)(1)

Standard: Implement policies and procedures to protect ePHI from improper alteration or destruction.

Implementation SpecificationTypeRequirement
Mechanism to Authenticate ePHI — §164.312(c)(2)AddressableImplement electronic mechanisms to corroborate that ePHI has not been altered or destroyed in an unauthorized manner

Asclepius Health Network Implementation:

  • Database integrity: SHA-256 checksums on clinical document records; tamper-evident logging of all modifications
  • Append-only clinical documentation model — original entries are never deleted or overwritten; amendments are linked to original records with author, timestamp, and reason
  • Digital signatures on laboratory results, radiology reports, and medication orders using PKI certificates
  • Daily integrity verification scans comparing file checksums against known-good baselines
  • Backup integrity verification: automated restore testing of randomly selected backup sets weekly
Show full SKILL.md (718 more words)Show less
Person or Entity Authentication — §164.312(d)

Standard: Implement procedures to verify that a person or entity seeking access to ePHI is the one claimed. This standard is required with no implementation specifications.

Asclepius Health Network Implementation:

  • Internal workforce: Multi-factor authentication (badge + PIN for workstations; authenticator app + password for remote)
  • External providers (Health Information Exchange): Digital certificate-based mutual TLS authentication
  • Patient portal: Knowledge-based authentication for enrollment; username + password + SMS/email verification code for ongoing access
  • Business associates accessing Asclepius systems: VPN with certificate + password + hardware token
  • Application-to-application: OAuth 2.0 with client credentials and mutual TLS
Transmission Security — §164.312(e)(1)

Standard: Implement technical security measures to guard against unauthorized access to ePHI that is being transmitted over an electronic communications network.

Implementation SpecificationTypeRequirement
Integrity Controls — §164.312(e)(2)(i)AddressableImplement security measures to ensure electronically transmitted ePHI is not improperly modified without detection
Encryption — §164.312(e)(2)(ii)AddressableImplement a mechanism to encrypt ePHI whenever deemed appropriate

Asclepius Health Network Implementation:

  • All internal network traffic containing ePHI is encrypted using TLS 1.2+ (network segmentation with ePHI VLAN)
  • External transmissions: mandatory TLS 1.2+ or VPN tunnels; unencrypted email containing ePHI is blocked by DLP gateway
  • HL7 FHIR API endpoints: mutual TLS with SMART on FHIR authorization
  • Direct secure messaging for provider-to-provider ePHI exchange (Direct Protocol with S/MIME encryption)
  • Integrity controls: TLS provides built-in integrity via HMAC; additional checksums on batch file transfers (HL7 batch, X12 EDI)
  • Wireless networks: WPA3 Enterprise with 802.1X RADIUS authentication on all clinical wireless networks; separate guest network with no ePHI system access

Administrative Safeguards — §164.308 (Selected Key Requirements)

Security Management Process — §164.308(a)(1)
Implementation SpecificationType
Risk AnalysisRequired
Risk ManagementRequired
Sanction PolicyRequired
Information System Activity ReviewRequired
Workforce Security — §164.308(a)(3)
Implementation SpecificationType
Authorization and/or SupervisionAddressable
Workforce Clearance ProcedureAddressable
Termination ProceduresAddressable
Information Access Management — §164.308(a)(4)
Implementation SpecificationType
Isolating Healthcare Clearinghouse FunctionsRequired
Access AuthorizationAddressable
Access Establishment and ModificationAddressable
Security Awareness and Training — §164.308(a)(5)
Implementation SpecificationType
Security RemindersAddressable
Protection from Malicious SoftwareAddressable
Log-in MonitoringAddressable
Password ManagementAddressable
Security Incident Procedures — §164.308(a)(6)
Implementation SpecificationType
Response and ReportingRequired
Contingency Plan — §164.308(a)(7)
Implementation SpecificationType
Data Backup PlanRequired
Disaster Recovery PlanRequired
Emergency Mode Operation PlanRequired
Testing and Revision ProceduresAddressable
Applications and Data Criticality AnalysisAddressable

Physical Safeguards — §164.310 (Summary)

Facility Access Controls — §164.310(a)(1)

Addressable specifications: Contingency operations, facility security plan, access control and validation procedures, maintenance records.

Workstation Use — §164.310(b)

Required standard specifying appropriate physical environment and manner of use for workstations accessing ePHI.

Workstation Security — §164.310(c)

Required standard implementing physical safeguards restricting access to workstations that access ePHI.

Device and Media Controls — §164.310(d)(1)

Required specifications for disposal and media re-use; addressable specifications for accountability and data backup/storage.

Required vs Addressable: OCR Expectations

OCR has clarified that "addressable" does not mean "optional." For each addressable specification, covered entities must:

  1. Assess whether the implementation specification is a reasonable and appropriate safeguard in their environment
  2. If yes, implement it
  3. If not, document why it is not reasonable and appropriate AND implement an equivalent alternative measure that is reasonable and appropriate OR document why the standard can still be met without the specification or alternative

OCR enforcement actions have found violations where entities failed to encrypt ePHI (addressable) without documenting any alternative measure. In practice, encryption of ePHI at rest and in transit is expected by OCR absent extraordinary documented justification.

Enforcement Precedents

  • Anthem Inc. (2018): $16 million — failure to implement technical safeguards including access controls sufficient to prevent unauthorized access to ePHI of 78.8 million individuals
  • Premera Blue Cross (2020): $6.85 million — failure to implement security measures sufficient to reduce risks and vulnerabilities to ePHI; inadequate audit controls
  • CHSPSC LLC (2020): $2.3 million — failure to implement information system activity review, inadequate response to known security incident (APT attack affecting 6.1 million individuals)
  • Excellus Health Plan (2021): $5.1 million — inadequate access controls, failure to conduct enterprise-wide risk analysis, insufficient technical policies
  • Banner Health (2023): $1.25 million — failure to implement audit controls and conduct accurate technical risk analysis after breach of 2.81 million records

Integration Points

  • hipaa-privacy-rule: Privacy Rule establishes what must be protected; Security Rule establishes how
  • hipaa-risk-analysis: Detailed risk analysis methodology mandated by §164.308(a)(1)(ii)(A)
  • hipaa-breach-notify: Security incidents that result in unauthorized access trigger breach notification
  • hipaa-baa-management: Business associates must independently comply with all Security Rule standards

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/hipaa-security-rule of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Hipaa Security Rule next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hipaa Security Rule compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hipaa Security Rule this skillmukul975/Privacy-Data-Protection-Skills301—~4.1kAutomated safety check: PassApache-2.0
Healthcare Phi Complianceaffaan-m/ECC276k1 repos~1.4kAutomated safety check: PassMIT
Policy OpaAgentSecOps/SecOpsAgentKit2201 repos~3.5kAutomated safety check: PassCustom licence
Implementing Delinea Secret Server For Pammukul975/Anthropic-Cybersecurity-Skills34k—~4.3kAutomated safety check: PassApache-2.0
Implementing Network Access Controlmukul975/Anthropic-Cybersecurity-Skills34k—~3.8kAutomated safety check: NotesApache-2.0
HealthclawLeoYeAI/openclaw-master-skills2.2k—~4.9kAutomated safety check: PassMIT

Similar skills

  • Protected Health Information (PHI) and PII compliance patterns for healthcare applications: data classification, row-level access control, tamper-proof audit trails, schema tagging, and common leak…

    276k GitHub starsUsed in 1 repo~1.4k tokens
    Legal & ComplianceAuto-check passed
  • Policy Opa

    AgentSecOps/SecOpsAgentKit

    Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA).

    220 GitHub starsUsed in 1 repo~3.5k tokens
    Legal & ComplianceAuto-check passed
  • Implementing Delinea Secret Server For Pam

    mukul975/Anthropic-Cybersecurity-Skills

    Implements Delinea Secret Server for privileged access management, covering secret vault configuration, role-based access policies, automated password rotation, session recording, and Active…

    34k GitHub stars~4.3k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Implementing Network Access Control

    mukul975/Anthropic-Cybersecurity-Skills

    Implements 802.1X port-based network access control using RADIUS authentication, PacketFence NAC, and switch configuration to enforce identity-based access policies, posture assessment, and…

    34k GitHub stars~3.8k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check: notes
  • Healthclaw

    LeoYeAI/openclaw-master-skills

    AI-native hospital and multi-department healthcare ERP. An agent skill from LeoYeAI/openclaw-master-skills.

    2.2k GitHub stars~4.9k tokensUpdated 2 mo ago
    Legal & ComplianceAuto-check passed
  • Ise Posture Audit

    automateyournetwork/netclaw

    Cisco ISE posture and policy audit - authorization rules, posture compliance, profiling gaps, TrustSec SGT matrix, active session health.

    676 GitHub stars~3k tokensUpdated today
    Legal & ComplianceAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Hipaa Security Rule

What does Hipaa Security Rule do?

Implements HIPAA Security Rule technical safeguards under 45 CFR §164.312 for electronic protected health information. Hipaa Security Rule is an agent skill from mukul975/Privacy-Data-Protection-Skills.312 for electronic protected health information.

When should I use Hipaa Security Rule?

Hipaa Security Rule fits situations like: tasks that involve Healthcare and finance regulation; tasks that involve Authorization and RBAC.

How do I install Hipaa Security Rule in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-security-rule -a claude-code`. Or copy the skill folder (skills/privacy/hipaa-security-rule in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/hipaa-security-rule in your project. Claude Code loads it when a task matches its description.

How do I install Hipaa Security Rule in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-security-rule -a codex`. Or copy the skill folder (skills/privacy/hipaa-security-rule in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/hipaa-security-rule in your project. Codex loads it when a task matches its description.

Can I use Hipaa Security Rule in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill hipaa-security-rule -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hipaa-security-rule, .gemini/skills/hipaa-security-rule, .github/skills/hipaa-security-rule and .opencode/skills/hipaa-security-rule in your project.

What does Hipaa Security Rule need to run?

Going by SKILL.md and its folder, Hipaa Security Rule needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Hipaa Security Rule access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hipaa Security Rule safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Hipaa Security Rule use?

Hipaa Security Rule is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hipaa Security Rule use?

About 4.1k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.1k tokens, read only when the agent opens those files.

What are the alternatives to Hipaa Security Rule?

Skills that share tags, products or a category with Hipaa Security Rule: Healthcare Phi Compliance (affaan-m/ECC, 276k stars), Policy Opa (AgentSecOps/SecOpsAgentKit, 220 stars), Implementing Delinea Secret Server For Pam (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Implementing Network Access Control (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hipaa Security Rule?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.