1---2name: hipaa-compliance-program-gap-analysis3description: Gap analysis of a healthcare organization’s privacy and security compliance program, identifying deficiencies in administrative safeguards, breach notification procedures, and vendor oversight against applicable healthcare privacy and security requirements.4---56# Skill: Healthcare Data Privacy Compliance Program Gap Analysis78## 2. Failure modes the skill is correcting910- Treating a privacy-and-security gap analysis as a broad checklist rather than a document-by-document comparison against the governing requirements and the organization’s own policies11- Missing how one deficiency can cascade into others, especially where incident handling, vendor oversight, and prior audit findings overlap12- Conflating an incomplete process artifact with a legally sufficient determination, approval, or exception13- Overlooking governance weaknesses in compliance reporting lines, committee cadence, and independence from operational incentives14- Identifying gaps without tying each one to source citations, legal authority, downstream risk, and a concrete fix15- Collapsing multiple vendors, incidents, findings, or time periods into a single pass instead of analyzing each separately1617## 3. Legal frameworks / domain conventions that apply1819- HIPAA Privacy Rule: permitted uses and disclosures, minimum necessary, patient rights in limited circumstances, business associate oversight, and documentation expectations20- HIPAA Security Rule: administrative safeguards, workforce role designation, sanctions, access controls, risk analysis and risk management, and documentation for addressable implementation decisions21- Breach Notification Rule: discovery-based timing, notice thresholds, media notice where applicable, and the presumption of breach absent a documented risk assessment using the required factors22- De-identification and data-use concepts: distinguish de-identified data from a limited data set, and distinguish the agreement type required for each23- Compliance program guidance for healthcare entities: independent compliance function, appropriate reporting lines, board or committee oversight, and compensation structures that do not incentivize non-compliance24- Enforcement posture: evaluate inquiry response readiness, cooperation obligations, and exposure based on the organization’s documented posture and responsiveness25- Any legal conclusion in the memo should be anchored to the specific provision, regulation, or recognized authority supporting it2627## 4. Analytical scaffolds2829- Start by identifying the universe of materials in scope: policies, procedures, vendor trackers, incident logs, audit reports, governance documents, and inquiry correspondence; then analyze each category against the applicable framework30- Vendor oversight: for each vendor in the tracker, verify agreement existence, execution status, expiration, scope of services, and whether the vendor handles protected information requiring the correct agreement form31- Breach notification: for each incident, establish the discovery date, measure elapsed time to internal and external notice, assess whether notice thresholds are triggered, and confirm whether a documented risk assessment supports any non-reportable determination32- Open findings: for each unresolved audit issue, trace remediation status, supporting evidence, and any linkage to later incidents or inquiries33- Governance: review reporting structure, compensation, escalation path, and oversight cadence for the compliance function and compare them to the governing expectations34- Workforce controls: confirm that roles, sanctions, training, access authorization, and device-use policies are actually documented and operationalized35- Technology/privacy coverage: check whether policies address remote access, bring-your-own-device, tracking technologies, and other operational channels that can create compliance exposure36- Inquiry response: identify the scope of the request, deadlines, document categories sought, and coordination obligations across functions37- For each issue, state the governing authority, the document support, the practical consequence, and the recommended fix38- Assign a uniform severity label to every issue using a stated ordinal scale; reserve the highest severity for items with immediate regulatory, litigation, or operational exposure3940## 5. Vertical / structural / temporal relationships4142- Use a separate pass for each incident, each vendor, each unresolved finding, and each governance issue; do not blend them into a single representative example43- Where a prior audit finding overlaps with an incident or inquiry topic, treat the overlap as compounding risk because it may evidence prior knowledge and weak remediation44- Where a policy template predates current requirements, note the temporal mismatch and assess whether the template fails to capture newer obligations45- Treat discovery, notice, remediation, and oversight as a sequence: earlier failures can amplify later breach, enforcement, and governance consequences46- If only one item exists in a category, state that explicitly and explain why the analysis is limited to that item4748## 6. Output structure conventions4950- Draft the memorandum as an issue-based advisory memo in descending severity order, not as a generic summary51- Begin with a concise executive overview identifying the compliance posture, the most time-sensitive obligations, and the highest-risk gaps52- Define the severity scale once near the top and apply it consistently to every issue53- For each issue, include: a short title; document citation(s); controlling authority; severity; why the issue matters; related materials that interact with it; and a concrete remediation recommendation54- When the source set contains multiple vendors, incidents, or findings, present them as separate numbered issues or sub-issues rather than aggregating them55- Close with a prioritized Recommended Actions section that separates immediate, near-term, and longer-term remediation steps and assigns an owner or responsible role to each action56- If the memo references a deadline or milestone, tie the recommendation timing to that anchor; otherwise use a clearly stated urgency level linked to the compliance risk57- Use conventional memorandum formatting with headings and short analytical paragraphs; avoid bare conclusory bullet points without legal support