CtrlK
BlogDocsLog inGet started
Tessl Logo

hipaa-audit

Audit applications and infrastructure handling Protected Health Information against HIPAA — Security Rule (administrative, physical, technical safeguards), Privacy Rule, Breach Notification Rule, plus HITECH. Covers ePHI scoping, the 18 HIPAA identifiers, Business Associate Agreement (BAA) chain-of-liability, minimum-necessary standard, and breach notification timing. Use when the user mentions 'HIPAA,' 'HIPAA Security Rule,' 'HIPAA Privacy Rule,' 'PHI,' 'ePHI,' 'protected health information,' 'BAA,' 'business associate agreement,' 'covered entity,' 'business associate,' 'minimum necessary,' 'HIPAA breach,' 'HITECH,' 'healthcare compliance,' 'medical data,' 'patient data,' or audits any system that creates, receives, maintains, or transmits PHI.

69

Quality

87%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, specialized HIPAA audit reference with actionable grep patterns, a complete checklist template, and precise regulatory detail. It is concise for a compliance skill and well-organized, though it could push actionability and progressive disclosure higher by extracting the identifier list and checklist template into bundle reference files and adding explicit verification checkpoints.

Suggestions

Extract the 18-identifier list and the full audit-checklist template into a references/ bundle file (e.g. references/checklist.md) and signal it from the body to improve progressive_disclosure and reduce inline bulk.

Tighten the opening narrative paragraphs (lines 9-15) which restate the rule structure already covered in later sections.

Add an explicit verification/validation checkpoint in the audit checklist (e.g. 'confirm every checkbox has evidence before recording disposition') to strengthen workflow clarity.

DimensionReasoningScore

Conciseness

Mostly information-dense reference material (CFR citations, 18-identifier list, timing table, grep patterns) that is specialized rather than common knowledge Claude already has, with only minor narrative padding in the opening framing paragraphs.

4 / 5

Actionability

Provides concrete, copy-paste-ready audit grep patterns (e.g. 'SELECT \*.*patient'), a complete fill-in audit-checklist template, specific timing thresholds (60 days, 6 years, 500 individuals) and CFR citations, with only minor gaps where the regexes are illustrative rather than complete tooling.

4 / 5

Workflow Clarity

Clear sequenced structure (scope → safeguards → privacy → breach → HITECH → checklist → findings → boundaries) anchored by a concrete audit checklist; the audit task is non-destructive so the validation-cap does not apply, though explicit verification checkpoints within the checklist are implicit rather than called out.

4 / 5

Progressive Disclosure

Well-organized with clear ## section headers and inline cross-references to sibling skills (iam-audit, crypto-audit, siem-detection, etc.); no bundle files exist so content lives in one file, but the section structure and References list keep it navigable with only minor organization gaps.

4 / 5

Total

16

/

20

Passed

Description

95%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, third-person description with comprehensive trigger coverage and an explicit Use-when clause covering both what and when. The only minor weakness is that the action vocabulary centers on a single 'audit' verb rather than enumerating several distinct concrete actions.

DimensionReasoningScore

Specificity

Names the concrete action ('Audit applications and infrastructure handling PHI against HIPAA') with comprehensive coverage of the four rules, ePHI scoping, the 18 identifiers, BAA chain, and breach timing, but the verb set is essentially a single audit action rather than multiple distinct concrete actions.

4 / 5

Completeness

Explicitly answers both 'what' (audit apps/infrastructure against the HIPAA rules + covered sub-topics) and 'when' via a concrete 'Use when the user mentions ...' clause with many trigger phrases.

5 / 5

Trigger Term Quality

Exhaustive natural trigger list including 'HIPAA,' 'PHI,' 'ePHI,' 'BAA,' 'covered entity,' 'business associate,' 'minimum necessary,' 'HITECH,' 'healthcare compliance,' 'medical data,' 'patient data' — covering synonyms and full expansions a user would actually say.

5 / 5

Distinctiveness Conflict Risk

Clear HIPAA-specific niche with distinct regulatory triggers (PHI, BAA, HITECH, covered entity) that are unlikely to fire for unrelated skills.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

allowed_tools_field

'allowed-tools' contains unusual tool name(s)

Warning

Total

15

/

16

Passed

Repository
briiirussell/cybersecurity-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.