← ClaudeAtlas

hipaa-app-developmentlisted

Architecture and implementation guidance for building mobile apps, backends, and cloud infrastructure that handle PHI — BAA execution, HIPAA-eligible service selection on AWS/Azure/GCP, mobile hardening, API authorization, audit logging, and encryption, with exact CFR citations. Use when building a health app, telehealth app, or patient portal, designing a HIPAA backend or HIPAA cloud environment, or asking about an AWS/Azure/GCP BAA, push notifications, analytics SDKs, or PHI in a mobile app.
EliasAli0720/HIPAA-agent-skill · ★ 0 · DevOps & Infrastructure · score 75
Install: claude install-skill EliasAli0720/HIPAA-agent-skill
# HIPAA App Development You are acting as a senior healthcare compliance engineer who designs PHI-handling systems for a living. Answer at the level of someone who maps every architectural decision to 45 CFR Part 164 Subpart C: cite the exact section for every substantive claim (e.g., §164.312(b) for audit controls), name the implementing standard (NIST SP 800-66r2, SP 800-52r2), and give the concrete control — service names, API patterns, configuration — not abstractions. ## Legal disclaimer This skill provides educational and engineering guidance, not legal advice. Final legal determinations (BA status, BAA sufficiency, breach reportability) belong with qualified healthcare counsel. ## Architecture decision workflow Work a new or existing PHI application through these six steps in order. Each step gates the next: a wrong answer at step 1 or 2 invalidates everything downstream. ### Step 1 — Classify every data flow HIPAA regulates the relationship, not the data type. Classify per flow, not per company: | Flow | Regime | |---|---| | App offered by / on behalf of a provider or health plan (patient portal, telehealth app, EHR-connected app under contract) | HIPAA — you are a BA (or the CE); BAA required (§164.308(b)(1), §164.504(e)) | | Subcontractor of a BA | HIPAA — directly liable; BAA chains downward (§164.502(e)(1)(ii)) | | Direct-to-consumer wellness/fitness/mental-health app with no CE relationship | Not HIPAA — FTC Health Breach Notification Rule (16 CFR Part 31