CtrlK
BlogDocsLog inGet started
Tessl Logo

testland/hipaa-test-patterns

Reference catalog of HIPAA Security Rule-aligned test patterns - administrative safeguards (45 CFR §164.308: workforce training, access management, contingency planning), physical safeguards (§164.310: facility access, workstation security, device disposal), technical safeguards (§164.312: access control, audit logs, integrity, transmission security); PHI handling assertions in fixtures; minimum-necessary tests per §164.502(b); BAA-scope boundary verification. Use when authoring HIPAA-readiness tests for any product handling Protected Health Information.

69

Quality

87%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Overview
Quality
Evals
Security
Files

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-organized reference-catalog skill that externalizes detailed test patterns appropriately and provides a concrete workflow plus worked example. Main improvement room is moving the 18-identifier list into the reference and adding an explicit validation gate in the numbered steps.

Suggestions

Move the 18 Safe Harbor identifiers list into references/security-rule-test-patterns.md (or a dedicated PHI-identifiers reference) to tighten the body and reduce redundancy with the description.

Add an explicit validation checkpoint to the numbered workflow, e.g. 'Run the copied pattern locally; only commit when minimum-necessary AND audit assertions both pass'.

Inline one minimal copy-ready pytest skeleton in the body so authors have an executable starting point before opening the reference file.

DimensionReasoningScore

Conciseness

Largely lean with no padding of basic concepts, but the inlined 18-identifier list and the CFR breakdown (already in the description) are minor trim candidates that could partly live in the reference file.

4 / 5

Actionability

The 7-step workflow and worked example give concrete, executable direction (specific endpoint, assertions, tools), though the copy-ready test code itself lives one level deep in the reference file rather than inline.

4 / 5

Workflow Clarity

A clear 7-step sequence with a fix-and-retry loop shown in the worked example and CI pass/fail framed as evidence, but the numbered list lacks an explicit validate-before-proceeding checkpoint.

4 / 5

Progressive Disclosure

SKILL.md is a well-structured overview that externalizes bulk per-section patterns to a single, clearly signaled one-level-deep reference file (references/security-rule-test-patterns.md, verified present), making navigation easy.

5 / 5

Total

17

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that concretely maps capabilities to HIPAA Security Rule sections and gives an explicit 'Use when' trigger. It is highly distinctive with only minor gaps in trigger-term synonyms.

DimensionReasoningScore

Specificity

Enumerates multiple concrete test-pattern actions mapped to specific CFR sections (workforce training, access management, audit logs, integrity, transmission security, minimum-necessary, BAA-scope), giving comprehensive coverage rather than vague abstractions.

5 / 5

Completeness

Explicitly answers both 'what' (reference catalog of Security Rule-aligned test patterns across admin/physical/technical safeguards) and 'when' ('Use when authoring HIPAA-readiness tests for any product handling Protected Health Information').

5 / 5

Trigger Term Quality

Includes strong natural terms a user would say ('HIPAA', 'HIPAA-readiness tests', 'PHI', 'Protected Health Information', 'BAA'), but misses common synonyms like 'compliance tests' or 'regulatory tests'.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (HIPAA Security Rule test authoring) with distinct triggers and minimal overlap, explicitly differentiated from the sister gdpr-test-patterns skill.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

referenced_paths_exist

Referenced path issues: 1 missing

Warning

Total

15

/

16

Passed

Reviewed

Table of Contents