Skip to content

/us-hipaa-security

HIPAA Security Rule expert for US healthcare compliance. Deep knowledge of 45 CFR Part 164 Subpart C, Administrative/Physical/Technical Safeguards, Required vs Addressable specifications, Risk Analysis, Business Associate Agreements, and HHS OCR enforcement.

shell
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill us-hipaa-security --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
  • You can call itInvoke it directly when you want it.
  • Slash command/us-hipaa-security
How auto-invocation works

Context preview

The summary Claude sees to decide when to auto-load this skill.

HIPAA Security Rule expert for US healthcare compliance. Deep knowledge of 45 CFR Part 164 Subpart C, Administrative/Physical/Technical Safeguards, Required vs Addressable specifications, Risk Analysis, Business Associate Agreements, and HHS OCR enforcement.

SKILL.md

us-hipaa-security.SKILL.md
name: us-hipaa-security
description: HIPAA Security Rule expert for US healthcare compliance. Deep knowledge of 45 CFR Part 164 Subpart C, Administrative/Physical/Technical Safeguards, Required vs Addressable specifications, Risk Analysis, Business Associate Agreements, and HHS OCR enforcement.
allowed-tools: Read, Glob, Grep, Write

HIPAA Security Rule Expert

Deep expertise in the Health Insurance Portability and Accountability Act (HIPAA) Security Rule - the U.S. federal regulation governing the protection of electronic Protected Health Information (ePHI).

Expertise Areas

HIPAA Security Rule Overview

**Regulatory Citation**: 45 CFR Part 164, Subpart C (Security Standards for the Protection of Electronic Protected Health Information) **Effective Date**: April 21, 2003 (Compliance Date: April 20, 2005) **Enforcement**: U.S. Department of Health and Human Services (HHS) - Office for Civil Rights (OCR) **Guidance Document**: NIST SP 800-66 Rev. 2 (An Introductory Resource Guide for Implementing the HIPAA Security Rule)

**Scope**:

  • Applies to **electronic** PHI (ePHI) only - not paper records or oral communications
  • **Covered Entities (CEs)**: Healthcare providers, health plans, healthcare clearinghouses that transmit ePHI
  • **Business Associates (BAs)**: Vendors/contractors who create, receive, maintain, or transmit ePHI on behalf of CEs (e.g., cloud providers, EHR vendors, billing companies, data analytics firms)
  • **Subcontractors**: BAs must have contracts with their own subcontractors

**What is ePHI?**

  • Individually identifiable health information in electronic form
  • Includes any demographic information collected from an individual that:
  • Relates to physical/mental health condition
  • Relates to provision of healthcare
  • Relates to payment for healthcare
  • 18 HIPAA identifiers (names, dates, medical record numbers, etc.) + health information

Enforcement and Penalties

**OCR Enforcement Triggers**:

1. **Breach Reports**: Unsecured ePHI affecting 500+ individuals (must report to OCR within 60 days) 2. **Complaints**: Patients/employees filing complaints with OCR 3. **Desk Audits**: OCR requests documentation remotely 4. **On-Site Audits**: Comprehensive compliance reviews 5. **Media Reports**: News of breaches or violations

**Penalty Tiers (per violation category per year)**:

  • **Tier 1**: Lack of knowledge (reasonable diligence would not have known) - Minimum $100 per violation, max $25,000
  • **Tier 2**: Reasonable cause (not willful neglect) - Minimum $1,000 per violation, max $100,000
  • **Tier 3**: Willful neglect corrected within 30 days - Minimum $10,000 per violation, max $250,000
  • **Tier 4**: Willful neglect not corrected - Minimum $50,000 per violation, max $1.9 million

**Note**: "Per violation category" means penalties are capped annually, not per individual breach event.

The Five Safeguard Categories

1. Administrative Safeguards (45 CFR §164.308)

**What It Governs**: Administrative actions, policies, and procedures to manage the selection, development, implementation, and maintenance of security measures.

**Key Standards/Implementation Specifications**:

  • **Security Management Process** (§164.308(a)(1)): Risk analysis, risk management, sanction policy, information system activity review
  • **Assigned Security Responsibility** (§164.308(a)(2)): Designated security official with authority and responsibility
  • **Workforce Security** (§164.308(a)(3)): Clearance procedures, termination procedures
  • **Information Access Management** (§164.308(a)(4)): Access authorization, access establishment/modification, access termination/suspension
  • **Security Awareness and Training** (§164.308(a)(5)): Reminders, protection from malicious software, login monitoring, password management
  • **Security Incident Procedures** (§164.308(a)(6)): Response and reporting, documented incident responses
  • **Contingency Plan** (§164.308(a)(7)): Data backup, disaster recovery, emergency mode operation, testing and revision
  • **Evaluation** (§164.308(a)(8)): Periodic technical and non-technical evaluation
  • **Business Associate Contracts and Other Arrangements** (§164.308(b)(1)): Written contracts or other arrangements with BAs

**Typical Evidence**: Security policies, risk analysis documentation, training records, incident response logs, disaster recovery plans, BAAs

2. Physical Safeguards (45 CFR §164.310)

**What It Governs**: Physical measures to protect electronic information systems and related buildings and equipment from natural and environmental hazards, and unauthorized intrusion.

**Key Standards/Implementation Specifications**:

  • **Facility Access Controls** (§164.310(a)(1)): Contingency operations, facility security plan, access control and validation, maintenance records
  • **Workstation Use** (§164.310(b)): Policies specifying proper workstation use for ePHI
  • **Workstation Security** (§164.310(c)): Physical safeguards for workstations that access ePHI
  • **Device and Media Controls** (§164.310(d)(1)): Disposal, media re-use, accountability, data backup and storage

**Typical Evidence**: Facility access logs, visitor logs, workstation security policies, media disposal records, backup storage documentation

3. Technical Safeguards (45 CFR §164.312)

**What It Governs**: Technology and related policies/procedures that protect ePHI and control access to it.

**Key Standards/Implementation Specifications**:

  • **Access Control** (§164.312(a)(1)): Unique user identification, emergency access procedure, automatic logoff, encryption and decryption
  • **Audit Controls** (§164.312(b)): Hardware/software/ procedural mechanisms that record and examine activity in information systems
  • **Integrity** (§164.312(c)(1)): Mechanisms to protect ePHI from improper alteration or destruction
  • **Person or Entity Authentication** (§164.312(d)): Verify identity of person/entity seeking access to ePHI
  • **Transmission Security** (§164.312(e)(1)): Encrypt
Read more
Read it on GitHub ↗

Showing the first part of this file.

Ships withtrust-center

Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.

Get the whole plugin, auto-invoked