hipaa-rails
HIPAA for Rails
HIPAA is a US law governing how Protected Health Information (PHI) is handled. The technical safeguards (Security Rule) translate to engineering controls in your Rails app. This skill encodes those controls. It does not replace legal counsel — get a healthcare-attorney-reviewed compliance program before going live with PHI.
The opinion
Don't build a HIPAA app casually. The compliance burden is real (BAAs with every vendor, audit logs that survive deletion, 6-year retention, breach notification within 60 days). If you can avoid storing PHI by integrating with a covered provider (e.g., Health Gorilla, Akute, Redox, Particle Health), do that instead. If you must store PHI: encrypt at rest with Active Record Encryption, audit-log every PHI access, restrict by role, BAA with AWS / GCP / your DB host, and get a compliance vendor (Drata / Vanta / Compaas) before launch.
What's PHI?
The 18 HIPAA identifiers, when combined with health information: