academic-research-comp…
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing,…
HIPAA Security Rule expert for US healthcare compliance. Deep knowledge of 45 CFR Part 164 Subpart C, Administrative/Physical/Technical Safeguards, Required vs Addressable specifications, Risk Analysis, Business Associate Agreements, and HHS OCR enforcement.
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill us-hipaa-security --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/us-hipaa-securityContext preview
The summary Claude sees to decide when to auto-load this skill.
HIPAA Security Rule expert for US healthcare compliance. Deep knowledge of 45 CFR Part 164 Subpart C, Administrative/Physical/Technical Safeguards, Required vs Addressable specifications, Risk Analysis, Business Associate Agreements, and HHS OCR enforcement.
name: us-hipaa-security description: HIPAA Security Rule expert for US healthcare compliance. Deep knowledge of 45 CFR Part 164 Subpart C, Administrative/Physical/Technical Safeguards, Required vs Addressable specifications, Risk Analysis, Business Associate Agreements, and HHS OCR enforcement. allowed-tools: Read, Glob, Grep, Write
Deep expertise in the Health Insurance Portability and Accountability Act (HIPAA) Security Rule - the U.S. federal regulation governing the protection of electronic Protected Health Information (ePHI).
**Regulatory Citation**: 45 CFR Part 164, Subpart C (Security Standards for the Protection of Electronic Protected Health Information) **Effective Date**: April 21, 2003 (Compliance Date: April 20, 2005) **Enforcement**: U.S. Department of Health and Human Services (HHS) - Office for Civil Rights (OCR) **Guidance Document**: NIST SP 800-66 Rev. 2 (An Introductory Resource Guide for Implementing the HIPAA Security Rule)
**Scope**:
**What is ePHI?**
**OCR Enforcement Triggers**:
1. **Breach Reports**: Unsecured ePHI affecting 500+ individuals (must report to OCR within 60 days) 2. **Complaints**: Patients/employees filing complaints with OCR 3. **Desk Audits**: OCR requests documentation remotely 4. **On-Site Audits**: Comprehensive compliance reviews 5. **Media Reports**: News of breaches or violations
**Penalty Tiers (per violation category per year)**:
**Note**: "Per violation category" means penalties are capped annually, not per individual breach event.
**What It Governs**: Administrative actions, policies, and procedures to manage the selection, development, implementation, and maintenance of security measures.
**Key Standards/Implementation Specifications**:
**Typical Evidence**: Security policies, risk analysis documentation, training records, incident response logs, disaster recovery plans, BAAs
**What It Governs**: Physical measures to protect electronic information systems and related buildings and equipment from natural and environmental hazards, and unauthorized intrusion.
**Key Standards/Implementation Specifications**:
**Typical Evidence**: Facility access logs, visitor logs, workstation security policies, media disposal records, backup storage documentation
**What It Governs**: Technology and related policies/procedures that protect ePHI and control access to it.
**Key Standards/Implementation Specifications**:
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing,…
Expertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output.
Use when interpreting AWS Secrets Manager connector output, deciding between inspector and retrieve modes, drafting SCF-mapped controls for rotation / KMS /…
Expertise in evaluating Azure subscription findings from azure-inspector and mapping them to SCF controls.
Interpret CrowdStrike Falcon findings for sensor coverage, policy visibility, and host group scoping.
Interpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.