HIPAA Compliance for AI Agents

# HIPAA Compliance for AI Agents

Safety Notice

This listing is from the official public ClawHub registry. Review SKILL.md and referenced scripts before running.

Copy this and send it to your AI assistant to learn

Install skill "HIPAA Compliance for AI Agents" with this command: npx skills add 1kalin/afrexai-hipaa-compliance

HIPAA Compliance for AI Agents

Generate HIPAA compliance checklists, risk assessments, and audit frameworks for healthcare organizations deploying AI agents.

What This Skill Does

When activated, produce any of these deliverables based on user request:

1. Pre-Deployment Compliance Gate

  • BAA requirements checklist for AI vendors
  • PHI data flow mapping template
  • Minimum Necessary standard application guide
  • Risk assessment framework (45 CFR 164.308(a)(1))

2. Technical Safeguards (45 CFR 164.312)

Access Controls:

  • Unique service account IDs for AI agents
  • Emergency access procedures for system failures
  • 15-minute auto-logoff configuration
  • Role-based minimum necessary permissions

Audit Controls:

  • PHI access logging (timestamp, user, action, data)
  • 6-year retention compliance
  • Anomaly detection on access patterns
  • AI decision audit trails

Transmission Security:

  • TLS 1.3 enforcement
  • E2E encryption for patient comms
  • Certificate pinning for API connections
  • No PHI in URLs, query strings, or logs

3. AI-Specific Risk Matrix

RiskImpactMitigation
Prompt injection → PHI leakCriticalInput sanitization, output filtering, sandboxing
Model training on PHIHighBAA prohibition, single-tenant deployment
Hallucinated medical infoCriticalHuman-in-loop, confidence thresholds
Shadow AI with PHIHighApproved tool registry, DLP rules

4. Breach Response Timeline

  • 0-1 hrs: Contain (disable agent, preserve logs)
  • 1-24 hrs: Assess scope of PHI exposure
  • 24-48 hrs: Document root cause, affected individuals
  • Within 60 days: Notify HHS + individuals + media (if 500+)
  • 30-90 days: Remediate, patch, retrain

5. Compliance by Use Case

Rate each AI deployment:

  • Patient scheduling → Medium risk
  • Billing/coding → High risk
  • Clinical decision support → Critical risk
  • Patient communication → High risk
  • Medical records summarization → Critical risk

6. Penalty Reference

TierPer ViolationAnnual Cap
Unknowing$141 - $71,162$2,134,831
Reasonable cause$1,424 - $71,162$2,134,831
Willful neglect (corrected)$14,232 - $71,162$2,134,831
Willful neglect (not corrected)$71,162$2,134,831

Average healthcare breach cost: $10.93M (IBM/Ponemon 2025).

Output Format

  • Markdown checklist with status columns
  • Risk matrix with impact/likelihood scoring
  • Timeline tables for breach response
  • Department-specific compliance cards

Resources

Source Transparency

This detail page is rendered from real SKILL.md content. Trust labels are metadata-based hints, not a safety guarantee.

Related Skills

Related by shared tags or category signals.

Security

Compliance & Audit Readiness Engine

Guides startups and scale-ups through SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS compliance to achieve audit readiness without external consultants.

Registry SourceRecently Updated
7940Profile unavailable
Security

AuditClaw GRC

AI-native GRC (Governance, Risk, and Compliance) for OpenClaw. 97 actions across 13 frameworks including SOC 2, ISO 27001, HIPAA, GDPR, NIST CSF, PCI DSS, CI...

Registry SourceRecently Updated
6300Profile unavailable
Security

Compliance Audit Generator

Generates detailed compliance audits with risk-prioritized findings and remediation plans for frameworks like SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS.

Registry SourceRecently Updated
1.2K1Profile unavailable
Security

NotaryOS

Seal AI agent actions with Ed25519 cryptographic receipts. Verify what your agent did and prove what it chose not to do.

Registry SourceRecently Updated
2781Profile unavailable