/us-hipaa-security
HIPAA Security Rule expert for US healthcare compliance. Deep knowledge of 45 CFR Part 164 Subpart C, Administrative/Physical/Technical Safeguards, Required vs Addressable specifications, Risk Analysis, Business Associate Agreements, and HHS OCR enforcement.
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill us-hipaa-security --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/us-hipaa-security
Context preview
The summary Claude sees to decide when to auto-load this skill.
HIPAA Security Rule expert for US healthcare compliance. Deep knowledge of 45 CFR Part 164 Subpart C, Administrative/Physical/Technical Safeguards, Required vs Addressable specifications, Risk Analysis, Business Associate Agreements, and HHS OCR enforcement.
SKILL.md
us-hipaa-security.SKILL.mdname: us-hipaa-security
description: HIPAA Security Rule expert for US healthcare compliance. Deep knowledge of 45 CFR Part 164 Subpart C, Administrative/Physical/Technical Safeguards, Required vs Addressable specifications, Risk Analysis, Business Associate Agreements, and HHS OCR enforcement.
allowed-tools: Read, Glob, Grep, Write
HIPAA Security Rule Expert
Deep expertise in the Health Insurance Portability and Accountability Act (HIPAA) Security Rule - the U.S. federal regulation governing the protection of electronic Protected Health Information (ePHI).
Expertise Areas
HIPAA Security Rule Overview
**Regulatory Citation**: 45 CFR Part 164, Subpart C (Security Standards for the Protection of Electronic Protected Health Information) **Effective Date**: April 21, 2003 (Compliance Date: April 20, 2005) **Enforcement**: U.S. Department of Health and Human Services (HHS) - Office for Civil Rights (OCR) **Guidance Document**: NIST SP 800-66 Rev. 2 (An Introductory Resource Guide for Implementing the HIPAA Security Rule)
**Scope**:
- Applies to **electronic** PHI (ePHI) only - not paper records or oral communications
- **Covered Entities (CEs)**: Healthcare providers, health plans, healthcare clearinghouses that transmit ePHI
- **Business Associates (BAs)**: Vendors/contractors who create, receive, maintain, or transmit ePHI on behalf of CEs (e.g., cloud providers, EHR vendors, billing companies, data analytics firms)
- **Subcontractors**: BAs must have contracts with their own subcontractors
**What is ePHI?**
- Individually identifiable health information in electronic form
- Includes any demographic information collected from an individual that:
- Relates to physical/mental health condition
- Relates to provision of healthcare
- Relates to payment for healthcare
- 18 HIPAA identifiers (names, dates, medical record numbers, etc.) + health information
Enforcement and Penalties
**OCR Enforcement Triggers**:
1. **Breach Reports**: Unsecured ePHI affecting 500+ individuals (must report to OCR within 60 days) 2. **Complaints**: Patients/employees filing complaints with OCR 3. **Desk Audits**: OCR requests documentation remotely 4. **On-Site Audits**: Comprehensive compliance reviews 5. **Media Reports**: News of breaches or violations
**Penalty Tiers (per violation category per year)**:
- **Tier 1**: Lack of knowledge (reasonable diligence would not have known) - Minimum $100 per violation, max $25,000
- **Tier 2**: Reasonable cause (not willful neglect) - Minimum $1,000 per violation, max $100,000
- **Tier 3**: Willful neglect corrected within 30 days - Minimum $10,000 per violation, max $250,000
- **Tier 4**: Willful neglect not corrected - Minimum $50,000 per violation, max $1.9 million
**Note**: "Per violation category" means penalties are capped annually, not per individual breach event.
The Five Safeguard Categories
1. Administrative Safeguards (45 CFR §164.308)
**What It Governs**: Administrative actions, policies, and procedures to manage the selection, development, implementation, and maintenance of security measures.
**Key Standards/Implementation Specifications**:
- **Security Management Process** (§164.308(a)(1)): Risk analysis, risk management, sanction policy, information system activity review
- **Assigned Security Responsibility** (§164.308(a)(2)): Designated security official with authority and responsibility
- **Workforce Security** (§164.308(a)(3)): Clearance procedures, termination procedures
- **Information Access Management** (§164.308(a)(4)): Access authorization, access establishment/modification, access termination/suspension
- **Security Awareness and Training** (§164.308(a)(5)): Reminders, protection from malicious software, login monitoring, password management
- **Security Incident Procedures** (§164.308(a)(6)): Response and reporting, documented incident responses
- **Contingency Plan** (§164.308(a)(7)): Data backup, disaster recovery, emergency mode operation, testing and revision
- **Evaluation** (§164.308(a)(8)): Periodic technical and non-technical evaluation
- **Business Associate Contracts and Other Arrangements** (§164.308(b)(1)): Written contracts or other arrangements with BAs
**Typical Evidence**: Security policies, risk analysis documentation, training records, incident response logs, disaster recovery plans, BAAs
2. Physical Safeguards (45 CFR §164.310)
**What It Governs**: Physical measures to protect electronic information systems and related buildings and equipment from natural and environmental hazards, and unauthorized intrusion.
**Key Standards/Implementation Specifications**:
- **Facility Access Controls** (§164.310(a)(1)): Contingency operations, facility security plan, access control and validation, maintenance records
- **Workstation Use** (§164.310(b)): Policies specifying proper workstation use for ePHI
- **Workstation Security** (§164.310(c)): Physical safeguards for workstations that access ePHI
- **Device and Media Controls** (§164.310(d)(1)): Disposal, media re-use, accountability, data backup and storage
**Typical Evidence**: Facility access logs, visitor logs, workstation security policies, media disposal records, backup storage documentation
3. Technical Safeguards (45 CFR §164.312)
**What It Governs**: Technology and related policies/procedures that protect ePHI and control access to it.
**Key Standards/Implementation Specifications**:
- **Access Control** (§164.312(a)(1)): Unique user identification, emergency access procedure, automatic logoff, encryption and decryption
- **Audit Controls** (§164.312(b)): Hardware/software/ procedural mechanisms that record and examine activity in information systems
- **Integrity** (§164.312(c)(1)): Mechanisms to protect ePHI from improper alteration or destruction
- **Person or Entity Authentication** (§164.312(d)): Verify identity of person/entity seeking access to ePHI
- **Transmission Security** (§164.312(e)(1)): Encrypt
Read more
name: us-hipaa-security description: HIPAA Security Rule expert for US healthcare compliance. Deep knowledge of 45 CFR Part 164 Subpart C, Administrative/Physical/Technical Safeguards, Required vs Addressable specifications, Risk Analysis, Business Associate Agreements, and HHS OCR enforcement. allowed-tools: Read, Glob, Grep, Write
HIPAA Security Rule Expert
Deep expertise in the Health Insurance Portability and Accountability Act (HIPAA) Security Rule - the U.S. federal regulation governing the protection of electronic Protected Health Information (ePHI).
Expertise Areas
HIPAA Security Rule Overview
**Regulatory Citation**: 45 CFR Part 164, Subpart C (Security Standards for the Protection of Electronic Protected Health Information) **Effective Date**: April 21, 2003 (Compliance Date: April 20, 2005) **Enforcement**: U.S. Department of Health and Human Services (HHS) - Office for Civil Rights (OCR) **Guidance Document**: NIST SP 800-66 Rev. 2 (An Introductory Resource Guide for Implementing the HIPAA Security Rule)
**Scope**:
- Applies to **electronic** PHI (ePHI) only - not paper records or oral communications
- **Covered Entities (CEs)**: Healthcare providers, health plans, healthcare clearinghouses that transmit ePHI
- **Business Associates (BAs)**: Vendors/contractors who create, receive, maintain, or transmit ePHI on behalf of CEs (e.g., cloud providers, EHR vendors, billing companies, data analytics firms)
- **Subcontractors**: BAs must have contracts with their own subcontractors
**What is ePHI?**
- Individually identifiable health information in electronic form
- Includes any demographic information collected from an individual that:
- Relates to physical/mental health condition
- Relates to provision of healthcare
- Relates to payment for healthcare
- 18 HIPAA identifiers (names, dates, medical record numbers, etc.) + health information
Enforcement and Penalties
**OCR Enforcement Triggers**:
1. **Breach Reports**: Unsecured ePHI affecting 500+ individuals (must report to OCR within 60 days) 2. **Complaints**: Patients/employees filing complaints with OCR 3. **Desk Audits**: OCR requests documentation remotely 4. **On-Site Audits**: Comprehensive compliance reviews 5. **Media Reports**: News of breaches or violations
**Penalty Tiers (per violation category per year)**:
- **Tier 1**: Lack of knowledge (reasonable diligence would not have known) - Minimum $100 per violation, max $25,000
- **Tier 2**: Reasonable cause (not willful neglect) - Minimum $1,000 per violation, max $100,000
- **Tier 3**: Willful neglect corrected within 30 days - Minimum $10,000 per violation, max $250,000
- **Tier 4**: Willful neglect not corrected - Minimum $50,000 per violation, max $1.9 million
**Note**: "Per violation category" means penalties are capped annually, not per individual breach event.
The Five Safeguard Categories
1. Administrative Safeguards (45 CFR §164.308)
**What It Governs**: Administrative actions, policies, and procedures to manage the selection, development, implementation, and maintenance of security measures.
**Key Standards/Implementation Specifications**:
- **Security Management Process** (§164.308(a)(1)): Risk analysis, risk management, sanction policy, information system activity review
- **Assigned Security Responsibility** (§164.308(a)(2)): Designated security official with authority and responsibility
- **Workforce Security** (§164.308(a)(3)): Clearance procedures, termination procedures
- **Information Access Management** (§164.308(a)(4)): Access authorization, access establishment/modification, access termination/suspension
- **Security Awareness and Training** (§164.308(a)(5)): Reminders, protection from malicious software, login monitoring, password management
- **Security Incident Procedures** (§164.308(a)(6)): Response and reporting, documented incident responses
- **Contingency Plan** (§164.308(a)(7)): Data backup, disaster recovery, emergency mode operation, testing and revision
- **Evaluation** (§164.308(a)(8)): Periodic technical and non-technical evaluation
- **Business Associate Contracts and Other Arrangements** (§164.308(b)(1)): Written contracts or other arrangements with BAs
**Typical Evidence**: Security policies, risk analysis documentation, training records, incident response logs, disaster recovery plans, BAAs
2. Physical Safeguards (45 CFR §164.310)
**What It Governs**: Physical measures to protect electronic information systems and related buildings and equipment from natural and environmental hazards, and unauthorized intrusion.
**Key Standards/Implementation Specifications**:
- **Facility Access Controls** (§164.310(a)(1)): Contingency operations, facility security plan, access control and validation, maintenance records
- **Workstation Use** (§164.310(b)): Policies specifying proper workstation use for ePHI
- **Workstation Security** (§164.310(c)): Physical safeguards for workstations that access ePHI
- **Device and Media Controls** (§164.310(d)(1)): Disposal, media re-use, accountability, data backup and storage
**Typical Evidence**: Facility access logs, visitor logs, workstation security policies, media disposal records, backup storage documentation
3. Technical Safeguards (45 CFR §164.312)
**What It Governs**: Technology and related policies/procedures that protect ePHI and control access to it.
**Key Standards/Implementation Specifications**:
- **Access Control** (§164.312(a)(1)): Unique user identification, emergency access procedure, automatic logoff, encryption and decryption
- **Audit Controls** (§164.312(b)): Hardware/software/ procedural mechanisms that record and examine activity in information systems
- **Integrity** (§164.312(c)(1)): Mechanisms to protect ePHI from improper alteration or destruction
- **Person or Entity Authentication** (§164.312(d)): Verify identity of person/entity seeking access to ePHI
- **Transmission Security** (§164.312(e)(1)): Encrypt
Showing the first part of this file.
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Other skills on trust-center.
- /academic-research-companion
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing, feedback, and publication. Use this skill whenever the user shares a research idea, asks to "flesh out" a topic, wants sources
Open skill - /aws-inspector-expert
Expertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output.
Open skill - /azure-inspector-expert
Expertise in evaluating Azure subscription findings from azure-inspector and mapping them to SCF controls.
Open skill - /crowdstrike-inspector-expert
Interpret CrowdStrike Falcon findings for sensor coverage, policy visibility, and host group scoping.
Open skill - /datadog-inspector-expert
Interpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.
Open skill - /drata-inspector-expert
Interpret drata-inspector findings generated from drata-cli workflows and turn Drata control, monitor, evidence, personnel, and integration posture into GRC action.
Open skill

