1---2name: draft-response-to-regulatory-inquiry-letter3description: Regulatory inquiry responses involving health data sharing should be drafted by mapping each inquiry item to a corresponding response, preserving the distinction between the external response and any privileged internal analysis, and checking that representations align with the underlying factual record.4---56# Skill: Draft Response to California AG Formal Inquiry Letter on Health Data Sharing Practices78## 1. Subject-matter triage9- Confirm the inquiry is a formal regulatory request and identify the response deadline, production scope, and any stated preservation or certification requirements.10- Separate the work into two distinct deliverables at the outset: an external response and a privileged internal memo.11- Inventory the source set before drafting: inquiry letter, privacy notices, internal policies, vendor/data-sharing terms, technical or audit materials, incident or complaint history, and any privileged legal analysis.12- If the inquiry spans multiple business lines, products, data streams, time periods, or legal entities, enumerate them first and assign each to a response track before drafting.1314## 2. Failure modes the skill is correcting15- The response omits or only implicitly addresses one or more inquiry items, creating avoidable follow-up demands.16- The draft overstates compliance, understates known gaps, or makes factual representations that do not match the underlying record.17- The external response and internal memo are blended, causing privilege waiver risk or an overdefensive public position.18- The draft ignores technical or operational evidence that may contradict policy-level statements about data collection, sharing, notice, consent, or opt-out handling.19- Privileged materials are not segregated, and withheld materials are not tracked with a defensible privilege/protection description.20- The internal memo diagnoses problems but does not translate them into concrete remediation steps tied to responsible owners and timing.2122## 3. Legal frameworks / domain conventions that apply23- State consumer privacy enforcement authority: treat the inquiry as a formal regulatory record and draft every statement as if it may be read against the evidence later.24- Health-related data sharing rules: analyze whether disclosures, sales, sharing, processing, consent, notice, opt-out, purpose limitation, or vendor restrictions are implicated by the facts.25- Consumer rights workflows: assess whether access, deletion, correction, opt-out, and sensitive-data controls were implemented as represented.26- Preference signals and browser/device controls: verify whether any required global opt-out or similar signal handling is implemented and whether exceptions apply.27- Privilege and work product: segregate counsel-generated legal analysis and prepare withholding language and a privilege-log entry for any protected material.28- Regulatory response convention: answer in a formal, restrained tone; respond to the question asked; avoid volunteering unnecessary detail; acknowledge corrections or supplementation where warranted.29- Controlling authority must be named when a legal proposition is asserted, whether it is a statute, regulation, rule, or recognized doctrine.3031## 4. Analytical scaffolds32- Read the inquiry letter first and extract each question, request, and deadline into a response matrix.33- For each inquiry item, identify the factual predicate, the supporting documents, the risk if the record is incomplete, and the proposed response position.34- Test policy statements against operational evidence; if they diverge, resolve the discrepancy before finalizing any external statement.35- For each legal risk point, name the governing authority before stating the conclusion.36- Distinguish facts that can be affirmatively stated from points that should be qualified, reserved, or answered by reference to a document production.37- For any withheld material, determine whether the basis is privilege, work product, confidentiality, or another protection, and record that basis consistently.38- In the internal memo, identify the enforcement exposure, explain the factual and legal driver, and convert each issue into a concrete remediation plan.3940## 5. Vertical / structural / temporal relationships41- The response may need to describe past practices, current practices, and remediation underway; keep those time frames distinct.42- If changes were made after the inquiry date, identify them as post-inquiry remediation and avoid implying they were in place earlier.43- If the inquiry concerns one entity but the documents span affiliates, vendors, or service providers, trace the data flow vertically from collection to downstream disclosure and horizontally across recipients.44- Where multiple periods or products are involved, do not collapse them into one blended narrative; analyze each track separately and then reconcile them in the final drafting.45- If the company is responding while other regulatory or litigation matters are pending, calibrate the response to avoid inconsistent admissions across proceedings.4647## 6. Output structure conventions48- Produce two deliverables: an external response letter and a privileged internal advisory memo.49- The external response should be formatted as a formal business letter on firm letterhead, with numbered or otherwise clearly keyed responses that track the inquiry letter item by item.50- Keep the external tone factual, measured, and responsive; include privilege assertions only where needed and identify withheld materials in a separate privilege-log style reference.51- The internal memo should be candid, attorney-facing, and organized around risk, factual gaps, likely regulator concerns, and remediation priorities.52- End the internal memo with an explicit Recommended Actions section that assigns each action to a responsible role and a timing anchor tied to the inquiry response or remediation window.53- Use industry-conventional headings rather than mirroring any hidden checklist; do not rely on the same section names used in the prompt.54- Ensure the named deliverable filenames exactly match the task instructions.