health-hipaa-review
Installation
SKILL.md
HIPAA Code Audit
Overview
Use this skill to inspect healthcare software and produce an audit report of code and delivery areas where HIPAA-aligned handling of PHI, ePHI, or adjacent sensitive PII appears incomplete, risky, or unsupported by evidence.
Operating Rules
- Never change code, configs, infrastructure, or documentation.
- Do not present the output as legal advice, certification, or a formal compliance determination.
- Bias toward code-observable evidence and clearly separate:
- confirmed evidence from the code or config
- likely inferences from nearby implementation
- non-code dependencies that require policy, vendor, ops, or legal validation
- If a safeguard is addressable under HIPAA, treat missing implementation or missing documented alternative as a finding candidate, not an automatic pass.
- When PII appears without clear PHI, still report the privacy risk and note that HIPAA scope may depend on context.