Agent skill

Implementing Hipaa Security Rule Safeguards

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Implement the HIPAA Security Rule (45 CFR Part 164 Subpart C) to protect electronic protected health information (ePHI): conduct the required risk analysis, deploy the administrative, physical, and…

Apache-2.0Auto-check passedLegal & Compliance

Install Implementing Hipaa Security Rule Safeguards

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-hipaa-security-rule-safeguards -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-hipaa-security-rule-safeguards --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-hipaa-security-rule-safeguards .claude/skills/implementing-hipaa-security-rule-safeguards && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implementing-hipaa-security-rule-safeguards
GitHub stars
34k
Token cost
~2.4k tokens
SKILL.md length
1,027 words
Files
5 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Implement the HIPAA Security Rule (45 CFR Part 164 Subpart C) to protect electronic protected health information (ePHI): conduct the required risk analysis, deploy the administrative, physical, and…

  • Works in 9 steps: Conduct the Security Risk Analysis… → Implement Administrative Safeguards… → Implement Physical Safeguards (§164.310) → …
  • An organization is a HIPAA covered entity
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Implementing Hipaa Security Rule Safeguards is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Implement the HIPAA Security Rule (45 CFR Part 164 Subpart C) to protect electronic protected health information (ePHI): conduct the required risk analysis, deploy the administrative, physical, and technical safeguards, handle required vs addressable implementation specifications, execute Business Associate Agreements, and stand up breach-notification readiness. Use when an organization is a HIPAA covered entity or business associate, when protecting ePHI, when preparing for an OCR audit or responding to a…

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `scripts/process.py`).

It sits in Legal & Compliance, covering Healthcare and finance regulation. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • An organization is a HIPAA covered entity
  • Business associate
  • Protecting ePHI
  • Preparing for an OCR audit

Example prompts

  • “/implementing-hipaa-security-rule-safeguards”

Requirements

  • Python 3

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Conduct the Security Risk Analysis (§164.308(a)(1)(ii)(A))
  2. Implement Administrative Safeguards (§164.308)
  3. Implement Physical Safeguards (§164.310)
  4. Implement Technical Safeguards (§164.312)
  5. Resolve "Required" vs "Addressable" specifications
  6. Execute Business Associate Agreements (§164.314 / §164.308(b))
  7. Track the 2025 NPRM proposed changes (NOT yet final)
  8. Stand up breach-notification readiness (45 CFR §§164.400–414)
  9. Document everything (§164.316)

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Implementing Hipaa Security Rule Safeguards loads about 2.4k tokens when it runs, and up to ~3.8k if it reads all its reference files. Until then it costs about 263 tokens; SKILL.md has 1,027 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~263
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 1,027 words, ~2,422 tokens.

Download SKILL.mdSave it as .claude/skills/implementing-hipaa-security-rule-safeguards/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
implementing-hipaa-security-rule-safeguards
description
Implement the HIPAA Security Rule (45 CFR Part 164 Subpart C) to protect electronic protected health information (ePHI): conduct the required risk analysis, deploy the administrative, physical, and technical safeguards, handle required vs addressable implementation specifications, execute Business Associate Agreements, and stand up breach-notification readiness. Use when an organization is a HIPAA covered entity or business associate, when protecting ePHI, when preparing for an OCR audit or responding to a breach, when performing a HIPAA Security Risk Analysis, when drafting or reviewing a BAA, or when mapping security controls to the §164.308/310/312/314/316 safeguards. Notes the 2025 NPRM proposed changes (not yet final). Keywords: HIPAA, HIPAA Security Rule, ePHI, PHI, 45 CFR 164, risk analysis, administrative safeguards, physical safeguards, technical safeguards, addressable, required, Business Associate Agreement, BAA, OCR, breach notification, HITECH, covered entity, business associate.
domain
cybersecurity
subdomain
compliance-governance
tags
hipaa, hipaa-security-rule, ephi, phi, 45-cfr-164, risk-analysis, baa, breach-notification, ocr, compliance, governance
version
1.0
author
andrewibrah
license
Apache-2.0
nist_csf
GV.OC-03, GV.RM-01, ID.RA-01, ID.RA-05, PR.DS-01, PR.AA-01, DE.CM-01
mitre_attack
T1078, T1566, T1486, T1530, T1048

Implementing HIPAA Security Rule Safeguards

When to Use

  • When an organization is a covered entity (health plan, clearinghouse, or provider transmitting electronic transactions) or a business associate handling ePHI on their behalf.
  • When standing up or maturing controls to protect electronic protected health information.
  • When performing the mandatory HIPAA Security Risk Analysis (§164.308(a)(1)(ii)(A)) — the single most-cited gap in OCR enforcement.
  • When preparing for an OCR audit/investigation or responding to a suspected breach.
  • When drafting, reviewing, or remediating a Business Associate Agreement (BAA).
  • When mapping existing security controls to the HIPAA safeguard standards and implementation specifications.

Scope note: this skill covers the Security Rule (ePHI). The Privacy Rule (uses/disclosures of all PHI) and the Breach Notification Rule are related but distinct; this skill touches breach readiness and BAAs where they intersect security.

Prerequisites

  • A clear determination of the organization's role (covered entity vs business associate) and where ePHI lives, flows, and is stored (an ePHI data map).
  • An asset inventory of systems that create, receive, maintain, or transmit ePHI.
  • Knowledge of the current rule's structure (45 CFR §§164.302–318) and the required vs addressable distinction.
  • Awareness that a 2025 NPRM proposes significant changes (see Workflow step 7 and references/standards.md) — track but do not assume them as in force.

Workflow

1. Conduct the Security Risk Analysis (§164.308(a)(1)(ii)(A))

This is required and foundational. Inventory ePHI and systems, identify threats and vulnerabilities, assess current controls, determine likelihood and impact, and assign risk levels. (Pair with the NIST 800-30 methodology and HHS's SRA Tool.) Output is a documented, dated risk analysis — the artifact OCR asks for first.

2. Implement Administrative Safeguards (§164.308)

The largest section. Includes the Security Management Process (risk analysis, risk management, sanction policy, information-system activity review), assigned security responsibility (a named Security Official), workforce security, information access management, security awareness and training, security incident procedures, contingency planning (data backup, disaster recovery, emergency-mode operation), evaluation, and BAAs with business associates.

3. Implement Physical Safeguards (§164.310)

Facility access controls, workstation use and workstation security, and device and media controls (disposal, media re-use, accountability, data backup and storage).

4. Implement Technical Safeguards (§164.312)

Access control (unique user ID, emergency access, automatic logoff, encryption/decryption), audit controls, integrity (mechanisms to authenticate ePHI), person/entity authentication, and transmission security (integrity controls + encryption).

5. Resolve "Required" vs "Addressable" specifications

Under the current rule, each implementation specification is Required (must implement) or Addressable (assess whether reasonable and appropriate; if so implement, if not document why and implement an equivalent alternative). Addressable does not mean optional — it means make and document a risk-based decision.

6. Execute Business Associate Agreements (§164.314 / §164.308(b))

Every business associate that touches ePHI needs a BAA binding it to safeguard ePHI, report incidents, and flow requirements to subcontractors. Maintain the BAA inventory.

7. Track the 2025 NPRM proposed changes (NOT yet final)

HHS OCR published an NPRM (Jan 6, 2025) proposing to remove the required/addressable distinction (make nearly all specifications required), and to mandate MFA, encryption of ePHI at rest and in transit, asset inventory and network maps, vulnerability scans every 6 months, annual penetration testing, 72-hour restoration of certain systems/data, and annual risk-analysis updates. These are proposals — the current rule remains in force until a final rule is published and effective. Plan toward them, but comply with what is current.

8. Stand up breach-notification readiness (45 CFR §§164.400–414)

Define how you detect, assess (the four-factor risk assessment), and report breaches of unsecured PHI: to individuals and HHS (and media for breaches affecting 500+ in a state/jurisdiction), within the required timelines. Encryption to NIST standards renders PHI "secured" and is a safe harbor from breach notification.

9. Document everything (§164.316)

Maintain policies, procedures, and records of actions/decisions in writing, retain for six years, review periodically, and update in response to environmental or operational change.

Show full SKILL.md (402 more words)Show less

Key Concepts

ConceptDefinition
ePHIElectronic protected health information — the Security Rule's scope.
Covered entityHealth plan, clearinghouse, or provider doing electronic transactions.
Business associateA vendor that handles ePHI for a covered entity; bound by a BAA.
Risk analysisRequired, documented assessment of risks to ePHI (§164.308(a)(1)(ii)(A)).
Required vs addressableMust-implement vs risk-based-decision implementation specifications.
Administrative / Physical / Technical safeguards§164.308 / §164.310 / §164.312.
BAABusiness Associate Agreement — contractually binds vendors to safeguard ePHI.
Breach (unsecured PHI)Triggers notification under §§164.400–414; encryption is a safe harbor.
OCRHHS Office for Civil Rights — enforces HIPAA.
Six-year retentionDocumentation retention requirement (§164.316).

Tools & Systems

  • 45 CFR Part 164 Subpart C — the Security Rule text (and Subpart D, Breach Notification).
  • HHS Security Risk Assessment (SRA) Tool — free guided risk analysis.
  • NIST SP 800-66 Rev 2 — implementing the HIPAA Security Rule (NIST guidance, maps to 800-53).
  • NIST SP 800-30 — risk-assessment methodology to ground the SRA.
  • GRC / compliance platforms — to manage policies, the BAA inventory, and evidence.
  • Encryption / MFA / SIEM / audit-logging tooling — to satisfy technical safeguards and the proposed mandates.

Common Scenarios

  • OCR investigation after a breach. First request is almost always the current, dated risk analysis and the risk-management plan — have them ready.
  • New SaaS handling ePHI. Sign a BAA before any ePHI flows; confirm the vendor's safeguards.
  • Addressable spec you won't implement as written. Document the risk-based rationale and the equivalent alternative you implemented instead.
  • Preparing for the proposed rule. Pre-position MFA, at-rest/in-transit encryption, asset inventory, scanning, and pen-testing so a final rule is a small step, not a scramble.
  • Lost/stolen device. If ePHI was encrypted to NIST standards, the safe harbor applies; if not, run the four-factor breach assessment and notify as required.

Output Format

Produce a HIPAA Security Rule Gap Assessment using assets/template.md, containing:

  1. Role & ePHI scope — covered entity vs BA; ePHI data map and systems.
  2. Risk analysis summary — top risks to ePHI with likelihood/impact (feeds risk management).
  3. Safeguard status — Administrative / Physical / Technical, each specification marked Implemented / Partial / Gap with required-vs-addressable noted.
  4. BAA inventory — business associates and BAA status.
  5. Breach-notification readiness — detection, four-factor assessment, notification workflow.
  6. 2025 NPRM gap view — readiness against the proposed mandates (clearly labeled proposed).
  7. Remediation plan — prioritized, with owners and dates; required specs and risk-analysis gaps first.

Use scripts/process.py to score a safeguard-status JSON across the §164.308/310/312 standards, weight required gaps above addressable ones, and emit the gap table plus a remediation-priority list.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/implementing-hipaa-security-rule-safeguards of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/standards.md
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Implementing Hipaa Security Rule Safeguards next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Implementing Hipaa Security Rule Safeguards compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Implementing Hipaa Security Rule Safeguards this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.4kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
HIPAA Pre-Deployment Compliance Checkmaziyarpanahi/openmed5.5k—~2kAutomated safety check: PassApache-2.0
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT
ISO Standards Readiness EvidenceK-Dense-AI/scientific-agent-skills48k1 repos~4.6kAutomated safety check: NotesMIT
Fda Consultant Specialistdavila7/claude-code-templates33k1 repos~2.7kAutomated safety check: PassMIT

Similar skills

  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Walks a data pipeline against the HIPAA Privacy and Security Rule checklist and produces a gap report before it processes patient data.

    5.5k GitHub stars~2k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • ISO Standards Readiness Evidence

    K-Dense-AI/scientific-agent-skills

    Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.

    48k GitHub starsUsed in 1 repo~4.6k tokens
    Legal & ComplianceAuto-check: notes
  • Fda Consultant Specialist

    davila7/claude-code-templates

    Senior FDA consultant and specialist for medical device companies including HIPAA compliance and requirement management.

    33k GitHub starsUsed in 1 repo~2.7k tokens
    Legal & ComplianceAuto-check passed
  • Grc Knowledge

    mlunato47/claude-grc-plugin

    Senior GRC analyst expertise across 18 compliance frameworks — NIST 800-53, FedRAMP (Rev5 + 20x/CR26, KSIs, VDR/VER, Certification Classes A–D), DoD/DoW Impact Levels (IL2–IL6, DISA Cloud SRG), ITAR…

    184 GitHub stars~6.1k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Implementing Hipaa Security Rule Safeguards

What does Implementing Hipaa Security Rule Safeguards do?

Implement the HIPAA Security Rule (45 CFR Part 164 Subpart C) to protect electronic protected health information (ePHI): conduct the required risk analysis, deploy the administrative, physical, and…. Implementing Hipaa Security Rule Safeguards is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Implement the HIPAA Security Rule (45 CFR Part 164 Subpart C) to protect electronic protected health information (ePHI): conduct the required risk analysis, deploy the administrative, physical, and technical safeguards, handle required vs addressable implementation specifications, execute Business Associate Agreements, and stand up breach-notification readiness.

When should I use Implementing Hipaa Security Rule Safeguards?

Implementing Hipaa Security Rule Safeguards fits situations like: an organization is a HIPAA covered entity; business associate; protecting ePHI; preparing for an OCR audit.

How do I install Implementing Hipaa Security Rule Safeguards in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-hipaa-security-rule-safeguards -a claude-code`. Or copy the skill folder (skills/implementing-hipaa-security-rule-safeguards in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-hipaa-security-rule-safeguards in your project. Claude Code loads it when a task matches its description.

How do I install Implementing Hipaa Security Rule Safeguards in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-hipaa-security-rule-safeguards -a codex`. Or copy the skill folder (skills/implementing-hipaa-security-rule-safeguards in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-hipaa-security-rule-safeguards in your project. Codex loads it when a task matches its description.

Can I use Implementing Hipaa Security Rule Safeguards in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-hipaa-security-rule-safeguards -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-hipaa-security-rule-safeguards, .gemini/skills/implementing-hipaa-security-rule-safeguards, .github/skills/implementing-hipaa-security-rule-safeguards and .opencode/skills/implementing-hipaa-security-rule-safeguards in your project.

What does Implementing Hipaa Security Rule Safeguards need to run?

Going by SKILL.md and its folder, Implementing Hipaa Security Rule Safeguards needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Implementing Hipaa Security Rule Safeguards access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Implementing Hipaa Security Rule Safeguards safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Implementing Hipaa Security Rule Safeguards use?

Implementing Hipaa Security Rule Safeguards is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Implementing Hipaa Security Rule Safeguards use?

About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.4k tokens, read only when the agent opens those files.

What are the alternatives to Implementing Hipaa Security Rule Safeguards?

Skills that share tags, products or a category with Implementing Hipaa Security Rule Safeguards: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), HIPAA Pre-Deployment Compliance Check (maziyarpanahi/openmed, 5.5k stars), Hipaa Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars) and ISO Standards Readiness Evidence (K-Dense-AI/scientific-agent-skills, 48k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Implementing Hipaa Security Rule Safeguards?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.