health-compliance-review

Installation
SKILL.md

Healthcare Regulatory & Security Compliance Review

When To Use

Invoke when you need to audit healthcare code, configurations, or delivery systems for regulatory and security control gaps. Use for HIPAA, GDPR, ONC, FDA, or multi-market compliance evidence — during security reviews, pre-release audits, or as a subagent from health-refactor or health-docs.

Overview

Use this skill to audit and validate healthcare software against regulatory and security controls. Every control gap is a finding. Every finding carries a declared severity. Jurisdiction is selected from evidence — not assumed.

Select one of us, eu, us+eu, or unclear before reviewing:

  1. Read .health-context.yaml if it exists.
  2. Check the repository scope for confirming or conflicting signals.
  3. Load the regulatory overlays matching the selected set: us → load references/us-regulatory-overlay.md; eu → load references/eu-regulatory-overlay.md; us+eu → load both; unclear → load both pending clarification.
  4. If evidence is mixed, state the conflict explicitly. Do not silently default to US assumptions. Declare the most defensible overlay set.
  5. If jurisdiction remains unclear after the evidence scan, ask the user to confirm before proceeding.

Operating Rules

Related skills

More from reason-healthcare/health-skills

Installs
8
GitHub Stars
7
First Seen
Apr 1, 2026