CtrlK
BlogDocsLog inGet started
Tessl Logo

healthcare-phi-compliance

Protected Health Information (PHI) and PII compliance patterns for healthcare applications: data classification, row-level access control, tamper-proof audit trails, schema tagging, and common leak vectors such as logs, URLs, and browser storage. Use when code touches patient or clinician data, when implementing HIPAA or GDPR access controls, or when auditing a healthcare system for data exposure.

69

Quality

83%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, actionable pattern reference with concrete SQL/TypeScript examples and a verification-oriented deployment checklist. Its main gaps are redundant logging guidance, missing recovery guidance for failed checklist items, and no use of reference files for extended material.

Suggestions

Consolidate the near-duplicate logging rules from 'Console output', 'Logs and monitoring', the deployment checklist, and Example 3 into a single canonical statement to reduce redundancy (conciseness).

Add a short remediation loop after the deployment checklist — e.g. 'If any checklist item fails, fix it before deploying and re-verify' — to provide the validate→fix→retry feedback the workflow currently lacks (workflow_clarity).

Back the audit-trail section with a concrete logging function implementation rather than only the AuditEntry interface, and give a specific session-timeout configuration so checklist items are verifiable (actionability).

DimensionReasoningScore

Conciseness

The body is efficient — terse imperative rules ('Never put patient-identifying data in query strings... Use opaque UUIDs only') with no padding — but logging guidance is repeated nearly verbatim across 'Console output', 'Logs and monitoring', the deployment checklist, and Example 3, and the PHI definition enumerates identifiers exhaustively, so it is not fully lean.

4 / 5

Actionability

Mostly executable: concrete SQL RLS policies, insert-only audit policies, `COMMENT ON` tagging statements, a TypeScript AuditEntry interface, and BAD/GOOD code examples. Minor gaps keep it below fully copy-paste ready: the audit trail shows only an interface rather than a logging implementation, and checklist items like 'Session timeout configured' lack a concrete command or configuration.

4 / 5

Workflow Clarity

The three-layer model (classification → access control → audit) gives a clear sequence, and the deployment checklist plus Example 2's explicit test ('login as doctor-facility-a, query facility-b patients — Expected: 0 rows returned') serve as verification checkpoints. It falls short of the top anchor because there is no feedback loop telling Claude what to do when a checklist item or isolation test fails.

4 / 5

Progressive Disclosure

The skill has no bundle files and is a single well-sectioned document with clear headers and a logical overview-to-examples flow; content is appropriately inlined for its size. It misses the top anchor because at ~137 lines some material (worked examples, jurisdiction specifics like DISHA) could be split into reference files with clearly signaled links.

4 / 5

Total

16

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that states concrete capabilities and explicit, naturally-phrased trigger conditions in third person. Its only weakness is incomplete synonym coverage of trigger terms — users mentioning 'medical records', 'EHR', or India's DISHA might not surface the skill.

DimensionReasoningScore

Specificity

Enumerates multiple concrete capabilities — 'data classification, row-level access control, tamper-proof audit trails, schema tagging, and common leak vectors such as logs, URLs, and browser storage' — giving comprehensive coverage of the domain's action surface, matching the comprehensive anchor rather than the minor-gaps anchor.

5 / 5

Completeness

Clearly answers 'what' with an explicit capability list and 'when' with a three-clause 'Use when...' ('when code touches patient or clinician data, when implementing HIPAA or GDPR access controls, or when auditing a healthcare system for data exposure'), matching the explicit both-what-and-when anchor.

5 / 5

Trigger Term Quality

Good natural keyword coverage ('HIPAA', 'GDPR', 'PHI', 'PII', 'patient or clinician data', 'auditing a healthcare system'), but common variations users would naturally say — 'medical records', 'EHR/EMR', 'DISHA' (only in the body) — are missing, fitting the good-but-incomplete anchor rather than the comprehensive one.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear healthcare-PHI compliance niche with distinct regulatory and data-type triggers (HIPAA/GDPR, patient/clinician data); no other generic skill description would collide with these triggers, matching the clear-niche anchor.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
affaan-m/ECC
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.