← All creators

EliasAli0720

User

HIPAA compliance skills for AI coding agents (Claude Code, Codex, Cursor, Gemini). 10 senior-grade skills: scoping, app dev, websites, AI/LLM, code review + PHI scanner, risk analysis, breach response, BAAs, de-identification, compliance programs. Exact 45 CFR citations, OCR enforcement through 2026.

7 indexed · 0 Featured · 0 stars · avg score 75
Prolific

Categories

Indexed Skills (7)

DevOps & Infrastructure Listed

hipaa-app-development

Architecture and implementation guidance for building mobile apps, backends, and cloud infrastructure that handle PHI — BAA execution, HIPAA-eligible service selection on AWS/Azure/GCP, mobile hardening, API authorization, audit logging, and encryption, with exact CFR citations. Use when building a health app, telehealth app, or patient portal, designing a HIPAA backend or HIPAA cloud environment, or asking about an AWS/Azure/GCP BAA, push notifications, analytics SDKs, or PHI in a mobile app.

0 Updated 2 days ago
EliasAli0720
Data & Documents Listed

hipaa-breach-response

Runs the HIPAA breach response playbook end to end — discovery clock, containment, forensics, the 4-factor risk assessment under §164.402(2), the full notification decision tree with exact deadlines, and OCR investigation response. Use when someone reports a data breach, ransomware, or any security incident involving PHI, asks "do we have to report" or "is this a breach", needs a breach notification plan or 4-factor risk assessment, or is responding to an OCR investigation.

0 Updated 2 days ago
EliasAli0720
Code & Development Listed

hipaa-code-review

Reviews code, diffs, and infrastructure-as-code for HIPAA violations — PHI in logs and URLs, non-BAA analytics and crash SDKs, missing encryption, weak access control and audit logging — and ships a runnable PHI scanner script. Use when asked to review code for HIPAA, scan for PHI, check a diff for PHI leaks, audit a healthcare codebase, or verify a health app's code before release.

0 Updated 2 days ago
EliasAli0720
AI & Automation Listed

hipaa-compliance-program

Builds and matures a HIPAA compliance program — the 12 required policies, Privacy Officer and Security Officer designation, workforce training, 6-year documentation retention, and OCR audit readiness — staged from day-1 startup to enterprise. Use when someone asks how to become HIPAA compliant, needs a HIPAA compliance program, HIPAA policies, a compliance checklist for a startup, privacy officer or security officer duties, HIPAA training requirements, or is preparing for an OCR audit.

0 Updated 2 days ago
EliasAli0720
AI & Automation Listed

hipaa-deidentification

Selects and executes the correct HIPAA de-identification path — Safe Harbor's 18 identifiers, Expert Determination, or a limited data set under a DUA — and flags residual re-identification risk in the LLM era. Use when someone asks to de-identify or anonymize patient data, mentions de-identification, Safe Harbor, Expert Determination, the 18 identifiers, or a limited data set, or wants test data from production, analytics exports, or AI training corpora built from PHI.

0 Updated 2 days ago
EliasAli0720
AI & Automation Listed

hipaa-fundamentals

Determines whether and how HIPAA applies to a product, company, or data flow, and explains the core rules with exact regulatory citations — PHI and the 18 identifiers, covered entities vs business associates, Privacy/Security/Breach Notification Rules, patient rights, and penalties. Use when someone asks "does HIPAA apply to us", "is this PHI", "are we a business associate", "do we need a BAA", or needs any HIPAA scoping, definitions, or regulatory overview.

0 Updated 2 days ago
EliasAli0720
Code & Development Listed

hipaa-risk-analysis

Conducts and reviews HIPAA Security Rule risk analyses under 45 CFR 164.308(a)(1)(ii)(A) using the NIST SP 800-66r2 methodology — ePHI asset inventory, data-flow mapping, threat and vulnerability identification, likelihood/impact rating, risk register, and risk management plan. Use when someone asks for a HIPAA risk analysis, risk assessment, security risk assessment (SRA), 164.308 compliance, OCR audit prep, or an asset inventory of ePHI systems.

0 Updated 2 days ago
EliasAli0720

Bio shown is the top-scored skill's repo description as a fallback — real GitHub bios land in a future update.