Agent skill

Hipaa Validate

by softspark in softspark/ai-toolkit

HIPAA validator: PHI exposure, audit logging, encryption, access control, BAA refs.

Apache-2.0Auto-check: notesLegal & Compliance

Install Hipaa Validate

skills CLI
$ npx skills add softspark/ai-toolkit --skill hipaa-validate -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install softspark/ai-toolkit hipaa-validate --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/app/skills/hipaa-validate .claude/skills/hipaa-validate && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hipaa-validate
GitHub stars
179
Token cost
~2.8k tokens
SKILL.md length
1,164 words
Files
5 (incl. scripts)
Skills in repo
112
Repo updated
First seen
Licence
Apache-2.0

At a glance

HIPAA validator: PHI exposure, audit logging, encryption, access control, BAA refs.

  • Works in 3 steps: Run the Scanner Script → Interpret and Enrich Results → Compile and Report
  • Tasks that involve Healthcare and finance regulation
  • SKILL.md covers Usage, What This Command Does, Steps and Output Format, plus 4 more sections
  • Runs Python scripts from its folder; calls python3

What it does

Hipaa Validate is an agent skill from softspark/ai-toolkit. HIPAA validator: PHI exposure, audit logging, encryption, access control, BAA refs. Triggers: HIPAA, PHI, healthcare compliance, audit log, BAA.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts (for example `reference/hipaa-rules.md`, `reference/phi-identifiers.md` and `reference/scanner-categories.md`).

It sits in Legal & Compliance, covering Healthcare and finance regulation. The repository describes itself as: Professional-grade AI coding toolkit: 94 skills, 44 agents, multi-platform (Claude, Cursor, Windsurf, Copilot, Gemini, Cline, Roo Code, Aider, Augment, Antigravity, Codex CLI… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Healthcare and finance regulation

Example prompts

  • “/hipaa-validate”

Requirements

  • Python 3
  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Run the Scanner Script
  2. Interpret and Enrich Results
  3. Compile and Report

What it can do on your machine

Read from SKILL.md and the folder at commit d64db2b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hipaa Validate loads about 2.8k tokens when it runs. Until then it costs about 40 tokens; SKILL.md has 1,164 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~40
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:159
    flag PHI-adjacent config files without `.env` or secret-manager references as a WARN category, even when no PHI pattern
  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Grep, Glob, Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from softspark/ai-toolkit at commit d64db2b, republished under its Apache-2.0 licence (© softspark). 1,164 words, ~2,775 tokens.

Download SKILL.mdSave it as .claude/skills/hipaa-validate/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
hipaa-validate
description
HIPAA validator: PHI exposure, audit logging, encryption, access control, BAA refs. Triggers: HIPAA, PHI, healthcare compliance, audit log, BAA.
allowed-tools
Read, Grep, Glob, Bash
user-invocable
true
effort
medium
disable-model-invocation
true
context
fork
agent
security-auditor
argument-hint
[path] [--mode developer|compliance] [--severity high|warn] [--keywords term1,term2] [--output json]

/hipaa-validate - HIPAA Compliance Scanner

$ARGUMENTS

Scan a codebase for HIPAA compliance issues using pattern-matching heuristics. Detects PHI exposure in logs, missing audit trails, unencrypted transmission/storage, hardcoded patient data, access control gaps, and missing Business Associate Agreement references. Read-only — never modifies files.

Regulation basis: 45 CFR Parts 160, 162, 164 (HIPAA Administrative Simplification, as amended through March 26, 2013). Covers Security Rule (§164.302-318), Privacy Rule (§164.500-534), Breach Notification Rule (§164.400-414), and enforcement penalties (§160.400-426).

Usage

/hipaa-validate                              # Scan full project (developer mode — definitives only)
/hipaa-validate src/                         # Scan specific path
/hipaa-validate --mode compliance            # Full audit sweep including heuristic categories
/hipaa-validate --severity high              # Filter to HIGH findings only
/hipaa-validate --keywords member,enrollee   # Extend healthcare keyword list
/hipaa-validate --output json                # Structured JSON output for CI integration

Modes:

  • developer (default): Categories 1, 3, 4, 7, 8 — definitive regex matches only, low false-positive rate, suited for daily use
  • compliance: All 8 categories — includes heuristic checks (Cat 2, 5, 6) for audit sweep coverage, suited for pre-audit sweeps

Severity filtering: --severity high shows only HIGH findings, --severity warn shows HIGH + WARN. Default shows all.

What This Command Does

  1. Run scanner script — execute scripts/hipaa_scan.py with passed arguments
  2. Interpret results — analyze findings, add context, suggest specific fixes
  3. Report — present findings with file paths, line numbers, severity, confidence, and HIPAA rule citations

Steps

Step 1: Run the Scanner Script

Execute the Python scanner with the user's arguments:

bash
python3 ${CLAUDE_SKILL_DIR}/scripts/hipaa_scan.py [path] [--mode developer|compliance] [--severity high|warn] [--keywords term1,term2] [--output json]

The script handles all scanning logic deterministically:

  • Context gate — identifies PHI-adjacent files via healthcare keyword matching
  • Language detection — detects project languages from manifest files
  • 8 check categories — runs regex patterns and co-occurrence heuristics
  • Deduplication — removes duplicate findings (same file+line+category)
  • .hipaaignore support — honors exclusion patterns from project root
  • .hipaa-config support — reads covered_vendors for BAA checks

If the script reports "No healthcare context detected", relay the message and suggest the --keywords flag with alternative terminology.

If --output json is used, the script outputs structured JSON suitable for CI pipelines. The exit code is 1 if any HIGH findings exist, 0 otherwise.

Step 2: Interpret and Enrich Results

Read reference/scanner-categories.md once before starting — you cannot judge a heuristic finding without the pattern that produced it.

For each finding from the script output:

  1. Read the flagged file and line to understand the actual code context
  2. Add a specific fix suggestion — not generic advice, but concrete code changes based on what you see
  3. For heuristic findings (confidence: "heuristic"), check if the concern is actually addressed elsewhere in the codebase (e.g., auth middleware at router level, audit logging in a shared module)
  4. Mark confirmed false positives and suggest adding them to .hipaaignore
Scanner Reference

The eight scan categories are implemented in scripts/hipaa_scan.py. The pattern tables, severities, per-language coverage and rule citations live in reference/scanner-categories.md.

Read that file once, in full, before enriching findings in Step 2 — it is what lets you explain why a line matched and judge whether a heuristic hit is a false positive. The scan itself does not need it; the script already holds the patterns.

#CategoryScopeMode
1PHI in logs / console output (+ minimum-necessary violations)full projectdeveloper
2Missing audit loggingfull projectcompliance only, heuristic
3Unencrypted transmissionPHI-adjacentdeveloper
4Hardcoded PHI test dataPHI-adjacentdeveloper
5Access control gapsPHI-adjacentcompliance only, heuristic
6Missing BAA referencesPHI-adjacentcompliance only, heuristic
7Encryption at restPHI-adjacentdeveloper
8PHI temp file exposurePHI-adjacentdeveloper

Categories 1 and 2 scan the full project; categories 3–8 scan only PHI-adjacent files. Compliance mode adds the heuristic categories 2, 5 and 6 to the developer set.

Step 3: Compile and Report

Present the scanner output to the user. Sort by severity (HIGH first), then by file path.

Output Format

markdown
## HIPAA Validation Report

### Summary
| Metric | Value |
|--------|-------|
| Mode | developer / compliance |
| PHI-adjacent files | N |
| Files scanned | N |
| Categories run | 1,3,4,7,8 (developer) / 1,2,3,4,5,6,7,8 (compliance) |
| Severity HIGH | N |
| Severity WARN | N |

### Findings

#### [HIGH] src/api/patients.ts:42
Category: PHI in Logs
Confidence: definitive (regex match)
Pattern: `console.log(patient.name)`
HIPAA Rule: §164.502(b) — Minimum Necessary Standard
Fix: Replace with `safeLog()` or remove PHI from log output

#### [HIGH] src/routes/patient-api.ts:15
Category: Missing Audit Logging
Confidence: heuristic (co-occurrence check — may be false positive)
Pattern: PHI route file without audit keywords
HIPAA Rule: §164.312(b) — Audit Controls
Fix: Verify audit logging exists in call chain; add AuditEvent creation if missing

#### [WARN] src/services/patient-sync.ts:88
Category: Unencrypted PHI Transmission
Confidence: definitive (regex match)
Pattern: `http://external-api.example.com/patients`
HIPAA Rule: §164.312(e)(1) — Transmission Security
Fix: Use HTTPS for all PHI transmission

Confidence values:

  • definitive — Categories 1, 3, 4, 7, 8: regex matched actual code
  • heuristic — Categories 2, 5, 6: co-occurrence/absence check, may be false positive

This distinction helps compliance officers prioritize immediate remediation (definitive) vs. investigation (heuristic).

Rules

  • MUST remain read-only — never modify any file. This skill reports findings only.
  • MUST cite a specific HIPAA rule section (§ number) for every finding — uncited findings are not actionable
  • MUST run the healthcare keyword context gate before applying PHI identifier regex (Category 4) — without it, false-positive rate is ~90%
  • NEVER label a heuristic finding as "definitive" — clearly mark POTENTIAL and confidence: heuristic
  • NEVER scan binary files, lock files (*.lock, package-lock.json, yarn.lock, pnpm-lock.yaml), or vendored dirs (node_modules/, vendor/, .git/, dist/, build/, out/, .next/) — noise and zero signal
  • CRITICAL: respect .hipaaignore exclusion patterns — teams use it to mark known-safe data fixtures
  • MANDATORY: flag PHI-adjacent config files without .env or secret-manager references as a WARN category, even when no PHI pattern matches
  • NEVER auto-fix in this version. Auto-fixing requires project-specific knowledge of logging and audit infrastructure that regex alone cannot provide.
Show full SKILL.md (426 more words)Show less

Gotchas

  • Check language_detection in the summary before trusting a zero. Category 1, 3, 4 and 7 patterns are language-tagged and only fire for a detected language. Manifests decide first (pyproject.toml, package.json, go.mod, …); without one the scanner falls back to file extensions. If it reports languages: ["any"] with language_detection: "none", the language rules never ran and HIGH: 0 means unscanned, not compliant — the scanner prints that warning to stderr, so a run whose stderr is discarded loses it.

  • Scanning a monorepo package or a subdirectory can put you below the manifest. The extension fallback covers the common case, but a directory of .sql, .yaml or templates resolves to no language at all — scan from the level that holds the manifest.

  • Test fixtures and seed data often contain synthetic PHI that looks real (SSN-shaped IDs, formatted phone numbers, sample email addresses). Flag them but lower severity — production code handling the same patterns is the actual risk.

  • HIPAA §164.312(b) requires audit logging but does not specify a format. "Logs exist" is not evidence of compliance — the logs must capture WHO (authenticated user), WHAT (action), WHEN (timestamp), WHERE (resource), and they must be immutable (append-only or write-once storage).

  • Encryption-at-rest varies silently by storage layer. RDS auto-encrypts new volumes since 2017, but older DB snapshots may not be; S3 bucket policies can override instance-level encryption. Treat "encryption enabled" as a claim to verify with the cloud provider, not a state to trust.

  • PHI identifiers 1-18 differ from HIPAA's "limited data set" rules — date of service and city are permitted in a limited dataset but not in full PHI. Do not auto-flag any date as PHI without context; check for surrounding patient-name or diagnosis proximity.

  • PHI detection via regex misses data encoded in BLOBs, base64-embedded JSON, or encrypted-at-application-layer columns. A clean regex scan does not prove absence of PHI — document this explicitly in the report.

  • Healthcare keyword context gate has dialect drift: "patient" in a veterinary codebase is a dog, not a person under HIPAA. Review context before escalating findings from multi-tenant or vertical-adjacent codebases.

When NOT to Use

  • For generic security patterns (XSS, SQLi, CSRF) — use /security-patterns
  • For dependency vulnerabilities — use /cve-scan
  • For non-healthcare compliance regimes (PCI-DSS, SOC2, GDPR) — this skill is HIPAA-specific
  • For legal interpretation of compliance — this skill flags technical controls; only a QSA or attorney interprets compliance status
  • For PII/GDPR outside the HIPAA scope — overlapping but distinct; HIPAA covers PHI specifically

Reference Documents

© softspark, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts) in app/skills/hipaa-validate of softspark/ai-toolkit.

  • SKILL.md
  • reference/hipaa-rules.md
  • reference/phi-identifiers.md
  • reference/scanner-categories.md
  • scripts/hipaa_scan.py

Open the folder on GitHubat commit d64db2b

Compare with similar skills

Hipaa Validate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hipaa Validate compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hipaa Validate this skillsoftspark/ai-toolkit179—~2.8kAutomated safety check: NotesApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
HIPAA Pre-Deployment Compliance Checkmaziyarpanahi/openmed5.5k—~2kAutomated safety check: PassApache-2.0
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9391 repos~2.3kAutomated safety check: PassMIT
ISO Standards Readiness EvidenceK-Dense-AI/scientific-agent-skills48k1 repos~4.6kAutomated safety check: NotesMIT
Fda Consultant Specialistdavila7/claude-code-templates32k1 repos~2.7kAutomated safety check: PassMIT

Similar skills

  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Walks a data pipeline against the HIPAA Privacy and Security Rule checklist and produces a gap report before it processes patient data.

    5.5k GitHub stars~2k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    939 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • ISO Standards Readiness Evidence

    K-Dense-AI/scientific-agent-skills

    Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.

    48k GitHub starsUsed in 1 repo~4.6k tokens
    Legal & ComplianceAuto-check: notes
  • Fda Consultant Specialist

    davila7/claude-code-templates

    Senior FDA consultant and specialist for medical device companies including HIPAA compliance and requirement management.

    32k GitHub starsUsed in 1 repo~2.7k tokens
    Legal & ComplianceAuto-check passed
  • Grc Knowledge

    mlunato47/claude-grc-plugin

    Senior GRC analyst expertise across 18 compliance frameworks — NIST 800-53, FedRAMP (Rev5 + 20x/CR26, KSIs, VDR/VER, Certification Classes A–D), DoD/DoW Impact Levels (IL2–IL6, DISA Cloud SRG), ITAR…

    183 GitHub stars~6.1k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed

More from softspark/ai-toolkit

All 112 skills in this repo
  • Prepare Test Env

    softspark/ai-toolkit

    Prepare or verify a project QA environment with source identity, readiness, browser access, evidence paths and owned cleanup.

    179 GitHub stars~1.8k tokensUpdated today
    Auto-check: notes
  • A11y Validate

    softspark/ai-toolkit

    Accessibility validator: WCAG 2.1 AA, EN 301 549, EAA. An agent skill from softspark/ai-toolkit.

    179 GitHub stars~3.8k tokensUpdated today
    Auto-check: notes
  • Analyze

    softspark/ai-toolkit

    Analyzes code quality, complexity, patterns across codebase.

    179 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Autonomous Dev

    softspark/ai-toolkit

    Drives a brief, specification, issue or existing PR through implementation, review, tests and QA to a ready PR.

    179 GitHub stars~2.6k tokensUpdated today
    Auto-check: notes
  • Brand Voice

    softspark/ai-toolkit

    Direct technical voice for docs, README, user-facing text. An agent skill from softspark/ai-toolkit.

    179 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • CI

    softspark/ai-toolkit

    Detect/generate/debug CI pipeline config (GitHub Actions, GitLab CI).

    179 GitHub stars~1.1k tokensUpdated today
    Auto-check: notes

Questions about Hipaa Validate

What does Hipaa Validate do?

HIPAA validator: PHI exposure, audit logging, encryption, access control, BAA refs. Hipaa Validate is an agent skill from softspark/ai-toolkit. HIPAA validator: PHI exposure, audit logging, encryption, access control, BAA refs.

When should I use Hipaa Validate?

Hipaa Validate fits situations like: tasks that involve Healthcare and finance regulation.

How do I install Hipaa Validate in Claude Code?

Run `npx skills add softspark/ai-toolkit --skill hipaa-validate -a claude-code`. Or copy the skill folder (app/skills/hipaa-validate in softspark/ai-toolkit) into .claude/skills/hipaa-validate in your project. Claude Code loads it when a task matches its description.

How do I install Hipaa Validate in Codex?

Run `npx skills add softspark/ai-toolkit --skill hipaa-validate -a codex`. Or copy the skill folder (app/skills/hipaa-validate in softspark/ai-toolkit) into .agents/skills/hipaa-validate in your project. Codex loads it when a task matches its description.

Can I use Hipaa Validate in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add softspark/ai-toolkit --skill hipaa-validate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hipaa-validate, .gemini/skills/hipaa-validate, .github/skills/hipaa-validate and .opencode/skills/hipaa-validate in your project.

What does Hipaa Validate need to run?

Going by SKILL.md and its folder, Hipaa Validate needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash.

Does Hipaa Validate access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hipaa Validate safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file; pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Hipaa Validate use?

Hipaa Validate is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hipaa Validate use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hipaa Validate?

Skills that share tags, products or a category with Hipaa Validate: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), HIPAA Pre-Deployment Compliance Check (maziyarpanahi/openmed, 5.5k stars), Hipaa Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 939 stars) and ISO Standards Readiness Evidence (K-Dense-AI/scientific-agent-skills, 48k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hipaa Validate?

softspark (a GitHub user) maintains it in softspark/ai-toolkit, which has 179 GitHub stars. The repository holds 112 skills in this directory. The repository was last updated on October 7, 2026.

Source: softspark/ai-toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.