1---2name: hipaa-security-rule-policy-gap-analysis3description: HIPAA Security Rule gap analysis comparing each security policy against the applicable regulatory requirements, organized by safeguard category, with remediation recommendations aligned to an upcoming regulatory audit.4---56# Skill: HIPAA Security Rule Gap Analysis — Policy vs. Regulation78## 1. Subject-matter triage (only if applicable)910- Treat the assignment as a comparative compliance review of policies, procedures, logs, and supporting materials against the HIPAA Security Rule.11- First identify the universe of policy documents, systems, workforce groups, vendors, and incidents in scope; if more than one appears, enumerate them before analyzing gaps.12- Separate pre-audit items from longer-horizon remediation, because an audit notice creates an immediate priority window that controls sequencing.13- If the materials describe an incident, assess whether the incident triggers a breach-risk review and whether that analysis was documented.1415## 2. Failure modes the skill is correcting1617- Flattening the analysis into an unsorted issue list instead of grouping findings by safeguard category and applicable implementation specification.18- Stating that a policy is “generally compliant” without tying each gap to the controlling regulatory subsection and the omitted requirement.19- Treating training, access, vendor, or log issues as binary pass/fail without counting affected people, accounts, systems, or relationships.20- Failing to distinguish formal written designation from informal job performance where the rule expects a named role or documented procedure.21- Omitting the downstream consequence of each gap for audit readiness, regulatory exposure, incident response, or operational continuity.22- Conflating current-state weaknesses with future-state remediation, which obscures what must be fixed before the audit window closes.23- Ignoring that a gap may exist in multiple places at once, such as a policy omission plus an implementation failure.2425## 3. Legal frameworks / domain conventions that apply2627- Analyze against the HIPAA Security Rule by safeguard family and cited subsection, including administrative, physical, and technical requirements, plus documentation expectations.28- Cite the controlling regulation for each proposition by name and section; do not state a compliance conclusion without the rule that supports it.29- Confirm formal designation where the rule contemplates a responsible officer or defined security function.30- Treat workforce security, authorization, access management, incident procedures, contingency planning, evaluation, physical safeguards, and device/media control as distinct compliance lanes.31- Evaluate vendor relationships for business associate coverage wherever a vendor creates, receives, maintains, or transmits ePHI.32- Examine access controls for unique user identification, emergency access, automatic logoff, encryption/decryption mechanisms, and any legacy access path that bypasses strong authentication.33- Review audit controls for logging coverage, review capability, and retention practices sufficient for compliance and audit defense.34- Review workforce termination procedures for timely credential deactivation and removal of dormant or residual access.35- Review contingency planning for backup, recovery, emergency operations, testing, revision, and criticality analysis.36- Review physical safeguards for facility access, workstation use, workstation security, and device/media disposal or destruction.37- Treat personal-device access to ePHI as a policy issue unless governed by device-management or equivalent controls.38- If an incident is described, analyze whether a documented, multi-factor breach-risk assessment was completed and whether the result is defensible.3940## 4. Analytical scaffolds4142- Safeguard-by-safeguard pass: for each safeguard family, identify the governing requirement, compare the policy text and supporting materials, and then record the gap.43- Finding construction: each issue should state the omitted or deficient control, the applicable subsection, the affected population or asset set, and the practical consequence of the gap.44- Quantification: where the materials permit it, quantify affected employees, accounts, systems, vendors, devices, or incidents; if only one item is in scope, say so expressly.45- Cross-reference: link each issue to any related policy, register, incident record, system list, or supporting document that confirms or contradicts the stated control.46- Severity: assign every finding an ordinal severity level using one uniform scale defined once at the top of the report.47- Remediation logic: distinguish immediate audit-critical fixes from medium-term policy or tooling upgrades, and tie each recommendation to the role that should own it.48- Vendor analysis: build a register of all ePHI-touching vendors and test whether each has current, compliant agreement coverage.49- Access analysis: identify any systems, interfaces, or cohorts that permit ePHI access without required controls; do not collapse distinct systems into a single finding.50- Training analysis: identify the affected workforce groups and onboarding cohorts, and state the extent of non-completion when the source materials support it.51- Incident analysis: if a no-breach or non-reportable conclusion appears, verify the presence of a documented risk assessment that supports that position.5253## 5. Vertical / structural / temporal relationships (only if applicable)5455- The audit notification date controls priority: issues inside the audit scope should be surfaced ahead of background hardening work.56- If a breach-risk assessment is missing for a recent incident, that gap may affect both reporting posture and audit defensibility, so treat it as time-sensitive.57- Where a control depends on another control, identify the dependency explicitly, such as training relying on onboarding completion or deprovisioning relying on HR termination notice.58- If the materials show a chain from policy to procedure to implementation, test the chain end-to-end rather than evaluating the policy in isolation.5960## 6. Output structure conventions6162- Use a report format suited to a compliance deviation memorandum or gap analysis, not a contractual redline.63- Begin with a brief scope and method summary, then define the severity scale used in the report.64- Organize findings by safeguard category, with numbered findings under each category and a regulatory citation for each finding.65- For each finding include: issue summary, governing citation, affected scope, severity, evidence or document reference, consequence, and remediation recommendation.66- Keep remediation recommendations specific and operational, using imperative verbs and naming the responsible role or function.67- End with a prioritized remediation roadmap that separates pre-audit actions from longer-term remediation and reflects the audit timeline.68- If a deliverable file is requested, ensure the primary report is produced as the operative work product and that any secondary summary does not replace it.