Agent skill

Telehealth Privacy

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Implements telehealth privacy compliance covering HIPAA requirements for virtual care, state licensing and recording consent laws, platform security with BAA requirements for telehealth vendors…

Apache-2.0Auto-check passedLegal & Compliance

Install Telehealth Privacy

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill telehealth-privacy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills telehealth-privacy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/telehealth-privacy .claude/skills/telehealth-privacy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
telehealth-privacy
GitHub stars
301
Token cost
~4.2k tokens
SKILL.md length
1,984 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Implements telehealth privacy compliance covering HIPAA requirements for virtual care, state licensing and recording consent laws, platform security with BAA requirements for telehealth vendors…

  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, HIPAA Compliance for Telehealth, State Licensing Requirements and Recording Consent Requirements, plus 5 more sections
  • Runs Python scripts from its folder
  • Tasks that involve Healthcare and finance regulation

What it does

Telehealth Privacy is an agent skill from mukul975/Privacy-Data-Protection-Skills. Implements telehealth privacy compliance covering HIPAA requirements for virtual care, state licensing and recording consent laws, platform security with BAA requirements for telehealth vendors, cross-state prescribing rules, and OCR enforcement discretion during public health emergencies. Keywords: telehealth privacy, virtual care, HIPAA, recording consent, platform BAA, cross-state licensing, OCR enforcement.

Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR and Healthcare and finance regulation. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR
  • Tasks that involve Healthcare and finance regulation

Example prompts

  • “Use the telehealth-privacy skill to implement telehealth privacy compliance covering HIPAA requirements for virtual care, state licensing and…”
  • “/telehealth-privacy”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Telehealth Privacy loads about 4.2k tokens when it runs, and up to ~6.4k if it reads all its reference files. Until then it costs about 108 tokens; SKILL.md has 1,984 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~108
When it runs · the whole SKILL.md, loaded when a task matches
~4.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,984 words, ~4,248 tokens.

Download SKILL.mdSave it as .claude/skills/telehealth-privacy/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
telehealth-privacy
description
Implements telehealth privacy compliance covering HIPAA requirements for virtual care, state licensing and recording consent laws, platform security with BAA requirements for telehealth vendors, cross-state prescribing rules, and OCR enforcement discretion during public health emergencies. Keywords: telehealth privacy, virtual care, HIPAA, recording consent, platform BAA, cross-state licensing, OCR enforcement.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
healthcare-privacy
metadata.tags
telehealth, virtual-care, hipaa, recording-consent, platform-baa, cross-state-licensing, ocr-enforcement

Telehealth Privacy Compliance

Overview

Telehealth (also termed telemedicine, virtual care, or remote patient monitoring) involves the delivery of healthcare services through electronic communications technologies when the patient and provider are in different locations. The rapid expansion of telehealth — accelerated during the COVID-19 public health emergency — created a complex regulatory environment where HIPAA, state privacy laws, telecommunications regulations, and professional licensing requirements converge. Privacy compliance for telehealth requires addressing the security of the communication platform, the privacy of the encounter, state-specific consent and recording requirements, cross-state practice considerations, and the obligations of technology vendors as business associates.

HIPAA Compliance for Telehealth

Core HIPAA Requirements

Telehealth encounters involve the creation, transmission, and storage of ePHI and are fully subject to HIPAA:

HIPAA RequirementTelehealth Application
Privacy Rule (§164.500-534)Telehealth encounters create PHI (notes, prescriptions, diagnoses); all Privacy Rule provisions apply including individual rights, minimum necessary, and authorization requirements
Security Rule (§164.312)Telehealth platform must meet technical safeguards: access controls, audit logs, encryption in transit and at rest, integrity controls
Breach Notification Rule (§164.400-414)Unauthorized access to telehealth session data (recording, transcript, chat) triggers breach notification analysis
BAA Requirement (§164.502(e))Telehealth technology vendor that creates, receives, maintains, or transmits ePHI must have a BAA with the covered entity
Platform Security Requirements

Asclepius Health Network evaluates telehealth platforms against these Security Rule requirements:

Access Controls (§164.312(a)):

  • Unique user identification for all providers and patients
  • Multi-factor authentication for provider access
  • Patient authentication through verified identity (DOB verification, registered email/phone, patient portal credentials)
  • Session-level access controls — each encounter creates a separate, access-controlled session
  • Automatic session termination after provider disconnect or 5-minute inactivity

Audit Controls (§164.312(b)):

  • Logging of all session events: initiation, connection, disconnection, duration, participants
  • Recording access logs (who accessed any stored recordings)
  • Chat/messaging logs maintained as part of the medical record
  • Logs retained for minimum 6 years

Transmission Security (§164.312(e)):

  • End-to-end encryption for video, audio, and data channels (minimum AES-128; Asclepius requires AES-256)
  • TLS 1.2 or higher for signaling and data transport
  • No unencrypted fallback — session fails rather than downgrades
  • SRTP (Secure Real-time Transport Protocol) for media streams

Integrity Controls (§164.312(c)):

  • Tamper-evident session metadata
  • Digital signatures on stored encounter records
  • Integrity verification on transmitted prescriptions and orders
Platforms Requiring BAA
Platform TypeBAA RequiredRationale
Dedicated telehealth platform (Teladoc, Amwell, Doxy.me)YesCreates, receives, maintains, or transmits ePHI
Video conferencing adapted for telehealth (Zoom for Healthcare, Microsoft Teams with BAA)YesePHI transmitted and potentially stored (recordings, chat)
Consumer video platforms without BAA (standard Zoom, FaceTime, Skype, Google Hangouts)No BAA available — generally not compliantNo BAA offered; ePHI not adequately protected
EHR-integrated telehealth (Epic MyChart Video Visit)Covered by existing EHR BAAePHI managed within existing BAA relationship
Remote patient monitoring devicesYes (for cloud-connected devices)Device data transmitted to vendor cloud containing ePHI
Asynchronous telehealth (store-and-forward)YesImages, data transmitted and stored by vendor
Patient messaging/portalCovered by existing EHR/portal BAASecure messaging within covered platform
OCR Enforcement Discretion During Public Health Emergency

On March 17, 2020, OCR issued a Notification of Enforcement Discretion for Telehealth Remote Communications (85 FR 22024), stating that during the COVID-19 public health emergency, OCR would exercise enforcement discretion and would not impose penalties for noncompliance with HIPAA related to the good-faith provision of telehealth using non-public-facing remote communication technologies:

What was permitted during enforcement discretion:

  • Use of non-public-facing video platforms (Apple FaceTime, Facebook Messenger video, Google Hangouts video, Zoom, Skype) without a BAA
  • Covered entities were expected to use encryption and privacy settings available on these platforms
  • OCR encouraged providers to notify patients of potential privacy risks

What was NOT permitted even during enforcement discretion:

  • Use of public-facing platforms (Facebook Live, Twitch, TikTok) where communications are open to the public
  • Abandonment of all privacy protections (providers still had to use reasonable precautions)

Post-PHE Status: The COVID-19 PHE ended on May 11, 2023. OCR enforcement discretion for telehealth formally expired on August 9, 2023. All telehealth must now be conducted on HIPAA-compliant platforms with BAAs in place.

Asclepius Health Network: Asclepius transitioned all telehealth to BAA-covered platforms (Epic MyChart Video Visit as primary; Zoom for Healthcare as backup) prior to the enforcement discretion expiration. All consumer-grade platform use for clinical telehealth was discontinued.

State Licensing Requirements

Cross-State Telehealth Practice

Healthcare providers are generally licensed by individual states. Providing telehealth services to a patient in a state where the provider is not licensed may violate that state's medical practice act.

Key Licensing Models:

ModelDescriptionParticipating States
Interstate Medical Licensure Compact (IMLC)Expedited licensure pathway for physicians seeking multi-state licenses42 states, DC, and Guam as of 2024
Nurse Licensure Compact (NLC)Multistate license allowing RNs and LPN/VNs to practice across member states41 states as of 2024
Psychology Interjurisdictional Compact (PSYPACT)Allows psychologists to practice telepsychology across member states42 states as of 2024
Individual state telehealth licensesSome states offer special telehealth-only or limited-scope licensesVaries by state (e.g., Florida, Texas telehealth registrations)
Full state licensureTraditional full license in each state where patients are locatedAll states

Privacy Implication: The state where the patient is physically located at the time of the telehealth encounter generally controls which state's privacy laws apply. This means the provider must comply with that state's specific privacy, consent, and recording requirements even if the provider is located in a different state.

Asclepius Health Network: Asclepius providers are licensed in the 4 states where Asclepius operates. For telehealth, the EHR prompts the provider to confirm the patient's physical location at the start of each encounter. The system applies location-specific consent requirements and recording notices based on the patient's state.

HIPAA and Recording

HIPAA does not specifically address recording of telehealth encounters, but recordings containing ePHI are subject to all HIPAA protections. Recordings become part of or associated with the medical record and must be:

  • Stored securely with encryption
  • Subject to access controls
  • Retained per the entity's record retention policy
  • Made available to patients under the right of access (§164.524) if part of the designated record set

State wiretapping and eavesdropping laws impose consent requirements on the recording of communications:

Consent ModelRequirementStates
One-party consentOnly one participant needs to consent to recording (the provider can record without patient consent, but best practice is to inform)38 states + DC including New York, Texas, Ohio, Georgia, Virginia
Two-party (all-party) consentAll participants must consent to recording12 states: California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, New Hampshire, Pennsylvania, Washington

Two-party consent states require particular attention: A provider in a one-party state conducting telehealth with a patient in a two-party state must obtain the patient's consent before recording. The more restrictive state law controls.

Asclepius Health Network Recording Policy:

  • All telehealth encounters may be recorded for quality assurance and medical record purposes
  • Prior to recording, the platform displays a notice and requires patient acknowledgment: "This telehealth visit may be recorded for quality assurance and medical record purposes. Your provider will also be taking notes during the visit. Do you consent to the recording of this visit?"
  • For patients in two-party consent states, recording does not proceed without affirmative consent
  • For patients who decline recording, the encounter proceeds without recording; the provider documents clinical notes manually
  • Recordings are encrypted and stored in the EHR document management system; access is restricted to the care team and authorized quality reviewers
Show full SKILL.md (762 more words)Show less

Cross-State Prescribing

Federal Requirements
  • DEA: Practitioners must be registered with the DEA to prescribe controlled substances. For telehealth prescribing of controlled substances, the Ryan Haight Act (21 USC §829(e)) generally requires at least one in-person medical evaluation before prescribing controlled substances via telehealth, with exceptions:
    • During DEA-declared telemedicine exceptions
    • When the patient is at a DEA-registered location (hospital, clinic)
    • Under specific state exemptions authorized by DEA
    • 2024 DEA proposed rule would establish a pathway for initial telehealth prescribing of Schedule III-V controlled substances with conditions
State Prescribing Rules
State RequirementPrivacy Implication
Prescriber must be licensed in patient's stateProvider credential verification creates PHI (license lookup, verification)
State prescription drug monitoring program (PDMP) check requiredProvider must access the patient's state PDMP — cross-state PDMP data sharing involves PHI
State formulary restrictionsMay require disclosure of diagnosis to justify off-formulary prescriptions
E-prescribing mandates (most states for controlled substances)Electronic prescription transmission must be HIPAA-compliant; DEA EPCS standards apply

Asclepius Health Network: The telehealth platform integrates with the state PDMP for the patient's location. Providers must complete PDMP checks before prescribing controlled substances. The integration uses a HIPAA-compliant API with the state PDMP system. For cross-state encounters, the system automatically routes prescriptions to the correct state PDMP.

Remote Patient Monitoring (RPM) Privacy

RPM-Specific Considerations

Remote patient monitoring involves continuous or periodic collection of health data from devices in the patient's home or on their person:

RPM ComponentPrivacy ConsiderationHIPAA Requirement
Monitoring devices (blood pressure cuffs, glucometers, pulse oximeters)Device data is ePHI; device may store data locallyEncryption on device storage; secure transmission
Wearable devices (smartwatches, continuous glucose monitors)Continuous data collection; potential for excessive data collection beyond medical necessityMinimum necessary — collect only clinically relevant data; patient consent for monitoring scope
Cloud platform for data aggregationVendor receives and stores ePHIBAA required with RPM platform vendor
Alerts and notificationsTransmitted health data may reach patient's personal devicePatient education on securing personal devices; notification content should minimize PHI
Data integration with EHRRPM data flows into clinical recordSecure integration (FHIR API with OAuth 2.0); data quality validation

While HIPAA does not require consent for treatment, RPM programs should obtain informed consent addressing:

  • What data will be collected and how frequently
  • Who will access the data (care team, monitoring center, BA)
  • How data will be used (clinical decision-making, AI analytics, quality improvement)
  • Patient's ability to pause or stop monitoring
  • Security measures protecting transmitted data
  • Limitations of RPM (not a substitute for emergency services)

Asclepius Health Network Telehealth Privacy Program

Governance
ComponentImplementation
Telehealth Privacy PolicyComprehensive policy covering platform selection, consent, recording, cross-state compliance, RPM; reviewed annually
Platform Approval ProcessAll telehealth platforms must be approved by IT Security and Privacy Office; BAA executed; security assessment completed
Provider TrainingAnnual telehealth-specific privacy training covering: location verification, consent procedures, recording requirements, secure environment setup
Patient EducationTelehealth privacy information provided at scheduling; pre-visit checklist includes privacy tips (private location, headphones, secure WiFi)
Incident ResponseTelehealth-specific incident playbook covering: unauthorized access to session, recording breach, platform compromise
Compliance MonitoringMonthly audit of telehealth session compliance: location verification completion, consent documentation, platform adherence
Environmental Security for Providers

Asclepius requires providers conducting telehealth to:

  • Use a private room with closed door (no shared/open workspaces)
  • Ensure no patient information visible on whiteboards, screens, or papers behind the provider
  • Use headphones or earbuds to prevent audio leakage
  • Lock workstation screen when stepping away during a session
  • Not conduct telehealth visits from public locations (coffee shops, airports)
  • Use only Asclepius-managed or approved devices for telehealth

Enforcement

  • OCR Enforcement Discretion (2020-2023): During the COVID-19 PHE, OCR exercised enforcement discretion for good-faith telehealth. Post-PHE, full HIPAA enforcement applies.
  • No OCR enforcement actions specific to telehealth privacy violations as of early 2025, but OCR has emphasized that the return to normal enforcement means platforms must be HIPAA-compliant with BAAs.
  • State AG actions: Multiple state AGs have investigated telehealth companies for privacy practices, particularly regarding consumer-facing telehealth apps that may not be HIPAA-covered entities (Cerebral, Done Health — FTC and state AG investigations in 2023-2024 for unauthorized PHI disclosure to third-party advertisers).

Integration Points

  • hipaa-privacy-rule: All telehealth encounters are subject to full Privacy Rule compliance
  • hipaa-security-rule: Telehealth platforms must meet all technical safeguards; transmission security is paramount
  • hipaa-baa-management: Telehealth vendors require BAAs; evaluation of vendor security posture is critical
  • hipaa-breach-notify: Platform compromises or unauthorized recording access trigger breach analysis
  • healthcare-ai-privacy: AI integrated into telehealth (AI scribes, clinical decision support during visits) creates compound obligations
  • 42-cfr-part-2: Telehealth SUD treatment encounters are subject to Part 2 protections in addition to HIPAA

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/telehealth-privacy of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Telehealth Privacy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Telehealth Privacy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Telehealth Privacy this skillmukul975/Privacy-Data-Protection-Skills301—~4.2kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT
Audit Reportharness/harness-skills115—~1.3kAutomated safety check: PassApache-2.0
Anne WojcickiK-Dense-AI/mimeographs129—~1.5kAutomated safety check: PassMIT
Dpa Checklist ReviewLegalQuants/lq-ai150—~3.7kAutomated safety check: PassApache-2.0

Similar skills

  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed
  • Anne Wojcicki

    K-Dense-AI/mimeographs

    Applies the strategic frameworks and mental models of Anne Wojcicki, co-founder and CEO of 23andMe.

    129 GitHub stars~1.5k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Dpa Checklist Review

    LegalQuants/lq-ai

    A skill your agent uses when the user provides a Data Processing Agreement, Data Processing Addendum, or HIPAA Business Associate Agreement and asks whether it contains the terms required under the…

    150 GitHub stars~3.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Auditing Deidentification Runs

    maziyarpanahi/openmed

    Produce a signed, reproducible, no-PHI audit trail for an OpenMed de-identification run via deidentify(audit=True).

    5.5k GitHub stars~1.8k tokensUpdated today
    Legal & ComplianceAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Telehealth Privacy

What does Telehealth Privacy do?

Implements telehealth privacy compliance covering HIPAA requirements for virtual care, state licensing and recording consent laws, platform security with BAA requirements for telehealth vendors…. Telehealth Privacy is an agent skill from mukul975/Privacy-Data-Protection-Skills. Implements telehealth privacy compliance covering HIPAA requirements for virtual care, state licensing and recording consent laws, platform security with BAA requirements for telehealth vendors, cross-state prescribing rules, and OCR enforcement discretion during public health emergencies.

When should I use Telehealth Privacy?

Telehealth Privacy fits situations like: tasks that involve Privacy and GDPR; tasks that involve Healthcare and finance regulation.

How do I install Telehealth Privacy in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill telehealth-privacy -a claude-code`. Or copy the skill folder (skills/privacy/telehealth-privacy in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/telehealth-privacy in your project. Claude Code loads it when a task matches its description.

How do I install Telehealth Privacy in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill telehealth-privacy -a codex`. Or copy the skill folder (skills/privacy/telehealth-privacy in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/telehealth-privacy in your project. Codex loads it when a task matches its description.

Can I use Telehealth Privacy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill telehealth-privacy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/telehealth-privacy, .gemini/skills/telehealth-privacy, .github/skills/telehealth-privacy and .opencode/skills/telehealth-privacy in your project.

What does Telehealth Privacy need to run?

Going by SKILL.md and its folder, Telehealth Privacy needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Telehealth Privacy access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Telehealth Privacy safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Telehealth Privacy use?

Telehealth Privacy is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Telehealth Privacy use?

About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.2k tokens, read only when the agent opens those files.

What are the alternatives to Telehealth Privacy?

Skills that share tags, products or a category with Telehealth Privacy: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Hipaa Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), Audit Report (harness/harness-skills, 115 stars) and Anne Wojcicki (K-Dense-AI/mimeographs, 129 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Telehealth Privacy?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.