HIPAA Safe Harbor Coverage Audit
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
Implements telehealth privacy compliance covering HIPAA requirements for virtual care, state licensing and recording consent laws, platform security with BAA requirements for telehealth vendors…
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill telehealth-privacy -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills telehealth-privacy --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/telehealth-privacy .claude/skills/telehealth-privacy && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "telehealth-privacy" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/telehealth-privacy into .claude/skills/telehealth-privacy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "telehealth-privacy", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/telehealth-privacyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill telehealth-privacy -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills telehealth-privacy --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/privacy/telehealth-privacy .agents/skills/telehealth-privacy && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "telehealth-privacy" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/telehealth-privacy into .agents/skills/telehealth-privacy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "telehealth-privacy", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill telehealth-privacy -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills telehealth-privacy --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/privacy/telehealth-privacy .cursor/skills/telehealth-privacy && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "telehealth-privacy" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/telehealth-privacy into .cursor/skills/telehealth-privacy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "telehealth-privacy", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Privacy-Data-Protection-Skills.git --path skills/privacy/telehealth-privacy--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill telehealth-privacy -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills telehealth-privacy --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/privacy/telehealth-privacy .gemini/skills/telehealth-privacy && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "telehealth-privacy" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/telehealth-privacy into .gemini/skills/telehealth-privacy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "telehealth-privacy", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Privacy-Data-Protection-Skills telehealth-privacyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill telehealth-privacy -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/privacy/telehealth-privacy .github/skills/telehealth-privacy && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "telehealth-privacy" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/telehealth-privacy into .github/skills/telehealth-privacy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "telehealth-privacy", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill telehealth-privacy -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Privacy-Data-Protection-Skills telehealth-privacy --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/privacy/telehealth-privacy .opencode/skills/telehealth-privacy && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "telehealth-privacy" agent skill from https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/telehealth-privacy into .opencode/skills/telehealth-privacy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "telehealth-privacy", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
telehealth-privacyImplements telehealth privacy compliance covering HIPAA requirements for virtual care, state licensing and recording consent laws, platform security with BAA requirements for telehealth vendors…
Telehealth Privacy is an agent skill from mukul975/Privacy-Data-Protection-Skills. Implements telehealth privacy compliance covering HIPAA requirements for virtual care, state licensing and recording consent laws, platform security with BAA requirements for telehealth vendors, cross-state prescribing rules, and OCR enforcement discretion during public health emergencies. Keywords: telehealth privacy, virtual care, HIPAA, recording consent, platform BAA, cross-state licensing, OCR enforcement.
Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).
It sits in Legal & Compliance, covering Privacy and GDPR and Healthcare and finance regulation. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Telehealth Privacy loads about 4.2k tokens when it runs, and up to ~6.4k if it reads all its reference files. Until then it costs about 108 tokens; SKILL.md has 1,984 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,984 words, ~4,248 tokens.
.claude/skills/telehealth-privacy/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Telehealth (also termed telemedicine, virtual care, or remote patient monitoring) involves the delivery of healthcare services through electronic communications technologies when the patient and provider are in different locations. The rapid expansion of telehealth — accelerated during the COVID-19 public health emergency — created a complex regulatory environment where HIPAA, state privacy laws, telecommunications regulations, and professional licensing requirements converge. Privacy compliance for telehealth requires addressing the security of the communication platform, the privacy of the encounter, state-specific consent and recording requirements, cross-state practice considerations, and the obligations of technology vendors as business associates.
Telehealth encounters involve the creation, transmission, and storage of ePHI and are fully subject to HIPAA:
| HIPAA Requirement | Telehealth Application |
|---|---|
| Privacy Rule (§164.500-534) | Telehealth encounters create PHI (notes, prescriptions, diagnoses); all Privacy Rule provisions apply including individual rights, minimum necessary, and authorization requirements |
| Security Rule (§164.312) | Telehealth platform must meet technical safeguards: access controls, audit logs, encryption in transit and at rest, integrity controls |
| Breach Notification Rule (§164.400-414) | Unauthorized access to telehealth session data (recording, transcript, chat) triggers breach notification analysis |
| BAA Requirement (§164.502(e)) | Telehealth technology vendor that creates, receives, maintains, or transmits ePHI must have a BAA with the covered entity |
Asclepius Health Network evaluates telehealth platforms against these Security Rule requirements:
Access Controls (§164.312(a)):
Audit Controls (§164.312(b)):
Transmission Security (§164.312(e)):
Integrity Controls (§164.312(c)):
| Platform Type | BAA Required | Rationale |
|---|---|---|
| Dedicated telehealth platform (Teladoc, Amwell, Doxy.me) | Yes | Creates, receives, maintains, or transmits ePHI |
| Video conferencing adapted for telehealth (Zoom for Healthcare, Microsoft Teams with BAA) | Yes | ePHI transmitted and potentially stored (recordings, chat) |
| Consumer video platforms without BAA (standard Zoom, FaceTime, Skype, Google Hangouts) | No BAA available — generally not compliant | No BAA offered; ePHI not adequately protected |
| EHR-integrated telehealth (Epic MyChart Video Visit) | Covered by existing EHR BAA | ePHI managed within existing BAA relationship |
| Remote patient monitoring devices | Yes (for cloud-connected devices) | Device data transmitted to vendor cloud containing ePHI |
| Asynchronous telehealth (store-and-forward) | Yes | Images, data transmitted and stored by vendor |
| Patient messaging/portal | Covered by existing EHR/portal BAA | Secure messaging within covered platform |
On March 17, 2020, OCR issued a Notification of Enforcement Discretion for Telehealth Remote Communications (85 FR 22024), stating that during the COVID-19 public health emergency, OCR would exercise enforcement discretion and would not impose penalties for noncompliance with HIPAA related to the good-faith provision of telehealth using non-public-facing remote communication technologies:
What was permitted during enforcement discretion:
What was NOT permitted even during enforcement discretion:
Post-PHE Status: The COVID-19 PHE ended on May 11, 2023. OCR enforcement discretion for telehealth formally expired on August 9, 2023. All telehealth must now be conducted on HIPAA-compliant platforms with BAAs in place.
Asclepius Health Network: Asclepius transitioned all telehealth to BAA-covered platforms (Epic MyChart Video Visit as primary; Zoom for Healthcare as backup) prior to the enforcement discretion expiration. All consumer-grade platform use for clinical telehealth was discontinued.
Healthcare providers are generally licensed by individual states. Providing telehealth services to a patient in a state where the provider is not licensed may violate that state's medical practice act.
Key Licensing Models:
| Model | Description | Participating States |
|---|---|---|
| Interstate Medical Licensure Compact (IMLC) | Expedited licensure pathway for physicians seeking multi-state licenses | 42 states, DC, and Guam as of 2024 |
| Nurse Licensure Compact (NLC) | Multistate license allowing RNs and LPN/VNs to practice across member states | 41 states as of 2024 |
| Psychology Interjurisdictional Compact (PSYPACT) | Allows psychologists to practice telepsychology across member states | 42 states as of 2024 |
| Individual state telehealth licenses | Some states offer special telehealth-only or limited-scope licenses | Varies by state (e.g., Florida, Texas telehealth registrations) |
| Full state licensure | Traditional full license in each state where patients are located | All states |
Privacy Implication: The state where the patient is physically located at the time of the telehealth encounter generally controls which state's privacy laws apply. This means the provider must comply with that state's specific privacy, consent, and recording requirements even if the provider is located in a different state.
Asclepius Health Network: Asclepius providers are licensed in the 4 states where Asclepius operates. For telehealth, the EHR prompts the provider to confirm the patient's physical location at the start of each encounter. The system applies location-specific consent requirements and recording notices based on the patient's state.
HIPAA does not specifically address recording of telehealth encounters, but recordings containing ePHI are subject to all HIPAA protections. Recordings become part of or associated with the medical record and must be:
State wiretapping and eavesdropping laws impose consent requirements on the recording of communications:
| Consent Model | Requirement | States |
|---|---|---|
| One-party consent | Only one participant needs to consent to recording (the provider can record without patient consent, but best practice is to inform) | 38 states + DC including New York, Texas, Ohio, Georgia, Virginia |
| Two-party (all-party) consent | All participants must consent to recording | 12 states: California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, New Hampshire, Pennsylvania, Washington |
Two-party consent states require particular attention: A provider in a one-party state conducting telehealth with a patient in a two-party state must obtain the patient's consent before recording. The more restrictive state law controls.
Asclepius Health Network Recording Policy:
| State Requirement | Privacy Implication |
|---|---|
| Prescriber must be licensed in patient's state | Provider credential verification creates PHI (license lookup, verification) |
| State prescription drug monitoring program (PDMP) check required | Provider must access the patient's state PDMP — cross-state PDMP data sharing involves PHI |
| State formulary restrictions | May require disclosure of diagnosis to justify off-formulary prescriptions |
| E-prescribing mandates (most states for controlled substances) | Electronic prescription transmission must be HIPAA-compliant; DEA EPCS standards apply |
Asclepius Health Network: The telehealth platform integrates with the state PDMP for the patient's location. Providers must complete PDMP checks before prescribing controlled substances. The integration uses a HIPAA-compliant API with the state PDMP system. For cross-state encounters, the system automatically routes prescriptions to the correct state PDMP.
Remote patient monitoring involves continuous or periodic collection of health data from devices in the patient's home or on their person:
| RPM Component | Privacy Consideration | HIPAA Requirement |
|---|---|---|
| Monitoring devices (blood pressure cuffs, glucometers, pulse oximeters) | Device data is ePHI; device may store data locally | Encryption on device storage; secure transmission |
| Wearable devices (smartwatches, continuous glucose monitors) | Continuous data collection; potential for excessive data collection beyond medical necessity | Minimum necessary — collect only clinically relevant data; patient consent for monitoring scope |
| Cloud platform for data aggregation | Vendor receives and stores ePHI | BAA required with RPM platform vendor |
| Alerts and notifications | Transmitted health data may reach patient's personal device | Patient education on securing personal devices; notification content should minimize PHI |
| Data integration with EHR | RPM data flows into clinical record | Secure integration (FHIR API with OAuth 2.0); data quality validation |
While HIPAA does not require consent for treatment, RPM programs should obtain informed consent addressing:
| Component | Implementation |
|---|---|
| Telehealth Privacy Policy | Comprehensive policy covering platform selection, consent, recording, cross-state compliance, RPM; reviewed annually |
| Platform Approval Process | All telehealth platforms must be approved by IT Security and Privacy Office; BAA executed; security assessment completed |
| Provider Training | Annual telehealth-specific privacy training covering: location verification, consent procedures, recording requirements, secure environment setup |
| Patient Education | Telehealth privacy information provided at scheduling; pre-visit checklist includes privacy tips (private location, headphones, secure WiFi) |
| Incident Response | Telehealth-specific incident playbook covering: unauthorized access to session, recording breach, platform compromise |
| Compliance Monitoring | Monthly audit of telehealth session compliance: location verification completion, consent documentation, platform adherence |
Asclepius requires providers conducting telehealth to:
© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/telehealth-privacy of mukul975/Privacy-Data-Protection-Skills.
Open the folder on GitHubat commit 9b2ef9e
Telehealth Privacy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Telehealth Privacy this skillmukul975/Privacy-Data-Protection-Skills | 301 | — | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~2.3k | Automated safety check: Pass | MIT | |
| Audit Reportharness/harness-skills | 115 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| Anne WojcickiK-Dense-AI/mimeographs | 129 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Dpa Checklist ReviewLegalQuants/lq-ai | 150 | — | ~3.7k | Automated safety check: Pass | Apache-2.0 |
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
harness/harness-skills
Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.
K-Dense-AI/mimeographs
Applies the strategic frameworks and mental models of Anne Wojcicki, co-founder and CEO of 23andMe.
LegalQuants/lq-ai
A skill your agent uses when the user provides a Data Processing Agreement, Data Processing Addendum, or HIPAA Business Associate Agreement and asks whether it contains the terms required under the…
maziyarpanahi/openmed
Produce a signed, reproducible, no-PHI audit trail for an OpenMed de-identification run via deidentify(audit=True).
mukul975/Privacy-Data-Protection-Skills
Implements age-gating mechanisms for online services to restrict access based on user age.
mukul975/Privacy-Data-Protection-Skills
Manages AI model retention and machine unlearning requirements.
mukul975/Privacy-Data-Protection-Skills
Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.
mukul975/Privacy-Data-Protection-Skills
Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).
mukul975/Privacy-Data-Protection-Skills
Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.
mukul975/Privacy-Data-Protection-Skills
Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.
Categories
Implements telehealth privacy compliance covering HIPAA requirements for virtual care, state licensing and recording consent laws, platform security with BAA requirements for telehealth vendors…. Telehealth Privacy is an agent skill from mukul975/Privacy-Data-Protection-Skills. Implements telehealth privacy compliance covering HIPAA requirements for virtual care, state licensing and recording consent laws, platform security with BAA requirements for telehealth vendors, cross-state prescribing rules, and OCR enforcement discretion during public health emergencies.
Telehealth Privacy fits situations like: tasks that involve Privacy and GDPR; tasks that involve Healthcare and finance regulation.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill telehealth-privacy -a claude-code`. Or copy the skill folder (skills/privacy/telehealth-privacy in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/telehealth-privacy in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill telehealth-privacy -a codex`. Or copy the skill folder (skills/privacy/telehealth-privacy in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/telehealth-privacy in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill telehealth-privacy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/telehealth-privacy, .gemini/skills/telehealth-privacy, .github/skills/telehealth-privacy and .opencode/skills/telehealth-privacy in your project.
Going by SKILL.md and its folder, Telehealth Privacy needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Telehealth Privacy is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Telehealth Privacy: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Hipaa Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), Audit Report (harness/harness-skills, 115 stars) and Anne Wojcicki (K-Dense-AI/mimeographs, 129 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.
Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.