Skill-Details

healthcare compliance

Healthcare compliance, privacy, security, and HIPAA guidance.

ÜbereinstimmungDirektGeprüft für gesundheitswesen
Quelleeddiebelaval/squireExterne Quelle
Gemeldete Installationen1Nur Popularitätssignal

Vor Nutzung prüfen

Die automatische Prüfung bewertet Relevanz, nicht Sicherheit oder Empfehlung. Lies vor der Nutzung die Quellanweisungen.

Gespeicherte Quellvorschau

SKILL.md

Dieser Auszug wurde bei der Prüfung gespeichert. Die externe Quelle enthält die vollständige und aktuelle Version.

---
name: Healthcare Compliance
slug: healthcare-compliance
description: HIPAA compliance, healthcare regulations, privacy and security standards for medical organizations and providers
category: domain
complexity: complex
version: "1.0.0"
author: "ID8Labs"
triggers:
  - "HIPAA compliance"
  - "healthcare privacy"
  - "PHI protection"
  - "medical compliance"
  - "healthcare security"
  - "patient data privacy"
tags:
  - healthcare
  - compliance
  - HIPAA
  - privacy
  - security
  - regulations
---

# Healthcare Compliance

Expert healthcare regulatory compliance system designed for medical practices, healthcare organizations, health IT companies, and healthcare professionals navigating complex privacy, security, and operational regulations. This skill provides HIPAA compliance guidance, privacy and security assessments, breach response protocols, policy development, training frameworks, and regulatory requirement interpretation.

The Healthcare Compliance skill excels at translating complex regulations into actionable compliance programs, conducting risk assessments, developing policies and procedures, creating staff training materials, managing business associate agreements, and establishing incident response plans. It's valuable for compliance officers, practice administrators, healthcare IT teams, and providers ensuring regulatory adherence.

**Critical Legal Disclaimer:** This skill provides educational information and compliance frameworks based on federal regulations (primarily HIPAA). It does NOT constitute legal advice. Healthcare compliance is complex, high-stakes, and subject to interpretation. State laws may impose additional requirements. Always consult qualified healthcare attorneys and compliance professionals for legal guidance, especially regarding breach notifications, enforcement actions, and regulatory interpretations.

## Core Workflows

### Workflow 1: HIPAA Compliance Assessment & Implementation

**Purpose:** Evaluate current compliance posture and implement comprehensive HIPAA privacy and security programs.

**HIPAA Overview:**

The Health Insurance Portability and Accountability Act (HIPAA) has three main rules:

**1. Privacy Rule**
- Protects all "individually identifiable health information" (Protected Health Information - PHI)
- Establishes patient rights over their health information
- Sets boundaries on uses and disclosures
- Applies to: Covered entities (healthcare providers, health plans, clearinghouses) and business associates

**2. Security Rule**
- Establishes national standards for protecting electronic PHI (ePHI)
- Requires administrative, physical, and technical safeguards
- Flexible implementation based on size and complexity
- Risk assessment is foundational requirement

**3. Breach Notification Rule**
- Requires notification of breaches of unsecured PHI
- Notification to individuals, HHS, and media (if 500+ affected)
- Specific timelines and content requirements
- Penalties for non-compliance

**Compliance Assessment Framework:**

**Step 1: Determine Covered Entity Status**
- Are you a healthcare provider who transmits health information electronically?
- Are you a health plan?
- Are you a healthcare clearinghouse?
- Are you a business associate of a covered entity?
- **If YES to any:** HIPAA applies to you

**Step 2: Identify PHI and ePHI**

**What is PHI?**
- Any health information that can identify an individual
- Includes: Medical records, billing records, conversations about care, health insurance information
- 18 identifiers make information PHI:
  1. Names
  2. Addresses (more specific than state)
  3. Dates (except year) related to individual
  4. Phone numbers
  5. Fax numbers
  6. Email addresses
  7. Social Security numbers
  8. Medical record numbers
  9. Health plan beneficiary numbers
  10. Account numbers
  11. Certificate/license numbers
  12. Vehicle identifiers
  13. Device identifiers/serial numbers
  14. URLs
  15. IP addresses
  16. Biometric identifiers
  17. Ful
Vollständige Quelle auf GitHub lesen (öffnet externe Seite)
Kontext

Verwandte Arbeit