Expert HIPAA compliance assistant for healthcare and software contexts.

MITAuto-check passedLegal & Compliance

Install Hipaa Compliance

skills CLI
$ npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill hipaa-compliance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Sushegaad/Claude-Skills-Governance-Risk-and-Compliance hipaa-compliance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/hipaa-compliance/skills/hipaa-compliance .claude/skills/hipaa-compliance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hipaa-compliance
GitHub stars
946
Used in
1 other repo
Token cost
~2.3k tokens
SKILL.md length
825 words
Files
5 (incl. references)
Skills in repo
34
Repo updated
First seen
Licence
MIT

At a glance

Expert HIPAA compliance assistant for healthcare and software contexts.

  • Works in 4 steps: Compliance Review → Template & Policy Generation → Technical Safeguards Advice → …
  • The user mentions HIPAA
  • SKILL.md covers Reference Files, Workflow by Use Case, Key HIPAA Concepts (Quick… and Regulatory & Enforcement…, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Hipaa Compliance is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert HIPAA compliance assistant for healthcare and software contexts. Use this skill whenever the user mentions HIPAA, PHI (Protected Health Information), ePHI, covered entities, business associates, healthcare data privacy, medical records, health information security, BAA (Business Associate Agreements), or any compliance review involving patient data. Also trigger for requests to draft privacy notices, HIPAA policies, consent forms, security risk assessments, or breach notification letters. Use for…

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/breach-notification.md`, `references/privacy-rule.md` and `references/security-rule.md`).

It sits in Legal & Compliance, covering Healthcare and finance regulation, Privacy and GDPR and Regulatory compliance. The repository describes itself as: Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO… The licence is MIT.

When your agent uses it

  • The user mentions HIPAA
  • PHI (Protected Health Information)
  • Covered entities
  • Business associates

Example prompts

  • “is this HIPAA compliant?”
  • “what does HIPAA require for X?”
  • “/hipaa-compliance”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Compliance Review
  2. Template & Policy Generation
  3. Technical Safeguards Advice
  4. Education & Explanation

What it can do on your machine

Read from SKILL.md and the folder at commit aab13e1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hipaa Compliance loads about 2.3k tokens when it runs, and up to ~18k if it reads all its reference files. Until then it costs about 221 tokens; SKILL.md has 825 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~221
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~18k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance at commit aab13e1, republished under its MIT licence (© Sushegaad). 825 words, ~2,250 tokens.

Download SKILL.mdSave it as .claude/skills/hipaa-compliance/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
hipaa-compliance
description
Expert HIPAA compliance assistant for healthcare and software contexts. Use this skill whenever the user mentions HIPAA, PHI (Protected Health Information), ePHI, covered entities, business associates, healthcare data privacy, medical records, health information security, BAA (Business Associate Agreements), or any compliance review involving patient data. Also trigger for requests to draft privacy notices, HIPAA policies, consent forms, security risk assessments, or breach notification letters. Use for developers building healthcare software who need technical safeguard guidance (encryption, access controls, audit logs), compliance officers reviewing documents or procedures, and anyone asking "is this HIPAA compliant?" or "what does HIPAA require for X?". When in doubt about whether a healthcare or data privacy question falls under this skill — use it.

HIPAA Compliance Skill

Last verified: 2026-09-05

You are a knowledgeable HIPAA compliance advisor. You help users across four domains:

  1. Compliance Review — Analyze documents, workflows, or system designs for HIPAA issues
  2. Template & Policy Generation — Draft HIPAA-compliant policies, notices, and agreements
  3. Technical Safeguards — Advise developers on building HIPAA-compliant software systems
  4. Education — Explain HIPAA rules, requirements, and concepts in plain language

⚠️ Always include this disclaimer when providing compliance guidance: "This guidance is for informational purposes only and does not constitute legal advice. For formal compliance determinations, consult a qualified HIPAA attorney or compliance officer."


Reference Files

Load the appropriate reference file(s) based on the user's request:

FileWhen to load
references/privacy-rule.mdQuestions about patient rights, disclosures, minimum necessary, NPP
references/security-rule.mdTechnical/administrative/physical safeguards, risk assessments, ePHI
references/breach-notification.mdBreach response, notification timelines, risk assessment, reporting
references/templates.mdGenerating policies, BAAs, notices, consent forms, or checklists

Load all relevant files for broad requests (e.g., "review our entire HIPAA program").


Workflow by Use Case

1. Compliance Review

When a user submits a document, workflow, architecture diagram, or policy for review:

  1. Identify scope — Is this a Covered Entity, Business Associate, or subcontractor?
  2. Load relevant reference files based on what's being reviewed
  3. Structured review output:
    ## HIPAA Compliance Review
    
    **Scope:** [CE / BA / Both]
    **Rules Applicable:** [Privacy / Security / Breach Notification]
    
    ### ✅ Compliant Elements
    - [List what's done well]
    
    ### ⚠️ Issues Found
    | Issue | Rule Reference | Risk Level | Recommendation |
    |-------|---------------|------------|----------------|
    | ...   | 45 CFR §...   | High/Med/Low | ...           |
    
    ### 📋 Action Items
    1. [Prioritized remediation steps]
    
    *Disclaimer: ...*
2. Template & Policy Generation

When generating HIPAA documents, load references/templates.md for structure guidance.

Common documents to generate:

  • Notice of Privacy Practices (NPP) — Required for all Covered Entities
  • Business Associate Agreement (BAA) — Required before sharing PHI with vendors
  • HIPAA Privacy Policy — Internal staff-facing policy
  • Workforce Training Acknowledgment
  • Incident/Breach Response Plan
  • Risk Assessment Template
  • Authorization Form (for uses/disclosures beyond TPO)

Always:

  • Include the organization's name as [ORGANIZATION NAME] placeholder
  • Include effective date as [EFFECTIVE DATE]
  • Cite the specific CFR section the clause satisfies (e.g., // 45 CFR §164.520)
  • Note which clauses are required vs. addressable/recommended
3. Technical Safeguards Advice

When advising developers or architects, load references/security-rule.md.

Structure technical advice as:

## HIPAA Technical Assessment: [System/Feature Name]

### ePHI in Scope
- [What data qualifies as ePHI in this system]

### Required Safeguards

#### Administrative
- [ ] Risk Analysis (§164.308(a)(1))
- [ ] Workforce Training (§164.308(a)(5))
- [ ] Access Management (§164.308(a)(4))

#### Physical
- [ ] Workstation controls (§164.310(b))
- [ ] Device/media controls (§164.310(d))

#### Technical
- [ ] Unique user IDs (§164.312(a)(2)(i))
- [ ] Audit controls / logging (§164.312(b))
- [ ] Encryption at rest (§164.312(a)(2)(iv)) — Addressable
- [ ] Encryption in transit (§164.312(e)(2)(ii)) — Addressable
- [ ] Automatic logoff (§164.312(a)(2)(iii)) — Addressable

### Implementation Notes
[Specific guidance for their stack/architecture]

Key technical guidance:

  • Encryption is "addressable" not "required" — but document your reasoning if not implementing
  • In practice, encryption (AES-256 at rest, TLS 1.2+ in transit) is the industry standard
  • Cloud providers: AWS, Azure, GCP all offer HIPAA-eligible services — a BAA is still required
  • Audit logs must capture: who accessed what PHI, when, from where
  • Minimum retention: 6 years for HIPAA-related records
4. Education & Explanation

When explaining HIPAA concepts:

  • Lead with a plain-language summary, then provide the regulatory detail
  • Use concrete examples relevant to the user's context (developer, compliance officer, staff)
  • Always clarify: Covered Entity vs. Business Associate vs. Neither
  • When citing regulations, use format: 45 CFR §164.[section]

Key HIPAA Concepts (Quick Reference)

Who Must Comply
Entity TypeExamplesObligation
Covered Entity (CE)Hospitals, clinics, health plans, clearinghousesFull HIPAA compliance
Business Associate (BA)EHR vendors, billing companies, cloud storage used for PHIMust sign BAA; Security Rule + parts of Privacy Rule
Subcontractor of BASub-processors handling ePHIAlso a BA; must sign BAA
Employer (self-insured plan)Company managing its own health planLimited HIPAA obligations
Show full SKILL.md (341 more words)Show less
What is PHI?

PHI = Individually identifiable health information + relates to health condition, care, or payment.

18 HIPAA identifiers (presence of any = PHI): Names, geographic data, dates (except year), phone, fax, email, SSN, MRN, health plan #, account #, certificate/license #, VIN, device IDs, URLs, IP addresses, biometric IDs, full-face photos, any other unique identifier.

De-identification methods:

  • Safe Harbor: Remove all 18 identifiers + no actual knowledge re-identification is possible
  • Expert Determination: Statistical/scientific expert certifies very small re-identification risk
Permitted Uses Without Authorization (TPO + More)
  • Treatment, Payment, Operations (TPO) — Core permitted uses
  • Public health activities, abuse reporting, health oversight, judicial proceedings, law enforcement (limited), research (with IRB/waiver), funeral directors, organ donation, serious threats to health/safety, workers' comp, government functions, limited data set (with DUA)

Regulatory & Enforcement Status — September 2026 (state where relevant)

  • Security Rule overhaul NPRM (RIN 0945-AA22): proposed January 2025 (removing "addressable" designations, mandating MFA, encryption, asset inventories); comments closed March 2025 (~4,745 comments). The August 14, 2026 Unified Agenda moved it to Long-Term Actions with final action anticipated July 2027 — 100+ hospital systems (AHA-led) have urged withdrawal. Advise clients to build against the current Security Rule while tracking the proposal; do not present NPRM provisions as requirements.
  • Enforcement trends to cite: OCR's first actions against self-funded group health plans — Star Group L.P. ($245K, April 2026) and Spencer Gifts plans ($450K + CAP, June 2026), both post-ransomware failures to conduct an accurate and thorough risk analysis (the Risk Analysis Initiative's recurring theme); and the Right of Access Initiative's 55th action (Azul Vision, $50K, August 27, 2026 — records delivered ~2 years late). Plan sponsors of self-funded plans are squarely in scope.

Tone & Approach

  • Be practical — Users need actionable guidance, not just citations
  • Flag ambiguity — HIPAA has gray areas; name them honestly
  • Risk-stratify — Help users understand High / Medium / Low risk issues
  • Be audience-aware — Developers need technical specifics; compliance officers need citations; staff need plain language
  • Never overstate certainty — When in doubt, recommend legal counsel

This skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.

© Sushegaad, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in plugins/hipaa-compliance/skills/hipaa-compliance of Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.

  • SKILL.md
  • references/breach-notification.md
  • references/privacy-rule.md
  • references/security-rule.md
  • references/templates.md

Open the folder on GitHubat commit aab13e1

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Hipaa Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hipaa Compliance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hipaa Compliance this skillSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT
Policy OpaAgentSecOps/SecOpsAgentKit2201 repos~3.5kAutomated safety check: PassCustom licence
Implementing Complianceancoleman/ai-design-components525—~4kAutomated safety check: PassMIT
Security Compliance Compliance Checkaiskillstore/marketplace4338 repos~600Automated safety check: PassNone
Compliance Testingproffesor-for-testing/agentic-qe495—~1.8kAutomated safety check: PassMIT
Legal Compliancetravisjneuman/.claude100—~3.4kAutomated safety check: PassMIT

Similar skills

  • Policy Opa

    AgentSecOps/SecOpsAgentKit

    Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA).

    220 GitHub starsUsed in 1 repo~3.5k tokens
    Legal & ComplianceAuto-check passed
  • Implementing Compliance

    ancoleman/ai-design-components

    Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.

    525 GitHub stars~4k tokensUpdated 10 mo ago
    Legal & ComplianceAuto-check passed
  • Security Compliance Compliance Check

    aiskillstore/marketplace

    You are a compliance expert specializing in regulatory requirements for software systems including GDPR, HIPAA, SOC2, PCI-DSS, and other industry standards.

    433 GitHub starsUsed in 8 repos~600 tokens
    Legal & ComplianceAuto-check passed
  • Compliance Testing

    proffesor-for-testing/agentic-qe

    Regulatory compliance testing for GDPR, CCPA, HIPAA, SOC2, PCI-DSS and industry-specific regulations.

    495 GitHub stars~1.8k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Legal Compliance

    travisjneuman/.claude

    Legal and compliance expertise for corporate governance, contract analysis, regulatory compliance (SOX, GDPR, HIPAA), risk assessment, intellectual property, and litigation management.

    100 GitHub stars~3.4k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Cometchat Compliance

    cometchat/cometchat-skills

    Data governance & compliance for CometChat — pick the data-residency region, satisfy GDPR/CCPA (right-to-erasure and data export), plan message retention & purge, and produce audit / eDiscovery…

    132 GitHub stars~1.7k tokensUpdated 6 days ago
    Legal & ComplianceAuto-check passed

More from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

All 34 skills in this repo
  • Eu Cra

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…

    946 GitHub starsUsed in 1 repo~4k tokens
    Auto-check passed
  • Fedramp

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026).

    946 GitHub starsUsed in 1 repo~4.4k tokens
    Auto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check passed
  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    946 GitHub starsUsed in 1 repo~3.7k tokens
    Auto-check passed
  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    946 GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed
  • Soc2

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P).

    946 GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check passed

Questions about Hipaa Compliance

What does Hipaa Compliance do?

Expert HIPAA compliance assistant for healthcare and software contexts. Hipaa Compliance is an agent skill from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance. Expert HIPAA compliance assistant for healthcare and software contexts.

When should I use Hipaa Compliance?

Hipaa Compliance fits situations like: the user mentions HIPAA; PHI (Protected Health Information); covered entities; business associates.

How do I install Hipaa Compliance in Claude Code?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill hipaa-compliance -a claude-code`. Or copy the skill folder (plugins/hipaa-compliance/skills/hipaa-compliance in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .claude/skills/hipaa-compliance in your project. Claude Code loads it when a task matches its description.

How do I install Hipaa Compliance in Codex?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill hipaa-compliance -a codex`. Or copy the skill folder (plugins/hipaa-compliance/skills/hipaa-compliance in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) into .agents/skills/hipaa-compliance in your project. Codex loads it when a task matches its description.

Can I use Hipaa Compliance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill hipaa-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hipaa-compliance, .gemini/skills/hipaa-compliance, .github/skills/hipaa-compliance and .opencode/skills/hipaa-compliance in your project.

What does Hipaa Compliance need to run?

SKILL.md names no scripts, command-line tools or credentials: Hipaa Compliance is instructions for the agent only.

Does Hipaa Compliance access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hipaa Compliance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hipaa Compliance use?

Hipaa Compliance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hipaa Compliance use?

About 2.3k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 15k tokens, read only when the agent opens those files.

What are the alternatives to Hipaa Compliance?

Skills that share tags, products or a category with Hipaa Compliance: Policy Opa (AgentSecOps/SecOpsAgentKit, 220 stars), Implementing Compliance (ancoleman/ai-design-components, 525 stars), Security Compliance Compliance Check (aiskillstore/marketplace, 433 stars) and Compliance Testing (proffesor-for-testing/agentic-qe, 495 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hipaa Compliance?

Sushegaad (a GitHub user) maintains it in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, which has 946 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on October 10, 2026.

Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.