1---2name: hls-compare-policies-hipaa-security-rule3description: Compares security and privacy policies against the HIPAA Security Rule on a policy-by-policy basis, organizing gaps by applicable safeguard category and tailoring remediation sequencing to external compliance deadlines.4---56# Skill: HIPAA Security Rule Gap Analysis — Policy vs. Regulation78## 1. Subject-matter triage9- Treat the task as a compliance-gap comparison, not a narrative policy review.10- Identify each policy, procedure, supporting schedule, inventory, register, or other source that bears on HIPAA Security Rule compliance.11- If the materials cover multiple entities, systems, locations, or programs, analyze each separately before aggregating.12- If the materials show a single in-scope program, say so and avoid implying broader coverage.1314## 2. Failure modes the skill is correcting15- Reviewers often stop at the policy text and miss mismatches between written controls, actual system coverage, and vendor/contract coverage.16- Required and addressable specifications are frequently blended together, leading to false negatives where an addressable safeguard is omitted without justification.17- Scope defects are commonly undercounted when the record contains multiple systems, users, vendors, or devices.18- Audit or reporting deadlines are often treated as background context rather than the anchor for remediation sequencing.19- Issue statements are often incomplete when they do not tie the gap to a specific provision, a measurable scope indicator, and a concrete consequence.2021## 3. Legal frameworks / domain conventions that apply22- Use the HIPAA Security Rule safeguard structure: Administrative, Physical, and Technical safeguards.23- Distinguish required specifications from addressable specifications; addressable items must be implemented or documented as reasonably and appropriately not implemented.24- Anchor each gap to the most specific rule provision available from the source materials, using the regulation’s part and section where possible.25- Commonly implicated provisions include security management, workforce security, information access management, security awareness and training, security incident procedures, contingency planning, physical access controls, workstation/device controls, access control, audit controls, integrity, person/entity authentication, and transmission security.26- Confirm whether security officer designation, risk analysis currency, access termination procedures, audit logging, contingency coverage, encryption scope, workstation/mobile controls, media disposal, and vendor access controls are actually supported by the materials.27- If the source set references an external compliance, audit, or notification milestone, treat that milestone as the controlling timing anchor for remediation sequencing.2829## 4. Analytical scaffolds30- Start by enumerating the in-scope policies, procedures, systems, vendors, and other distinct objects that can create separate gaps.31- For each policy or control family, test it against the applicable HIPAA safeguard category and then against the underlying required and addressable specifications.32- For every identified issue, close the analysis with:33 - the specific provision implicated,34 - a scope indicator drawn from the source materials where available,35 - the interaction with any related policy, system, inventory, register, or contract term,36 - the operational, regulatory, or litigation consequence if the gap remains open.37- Treat a missing justification for an addressable specification as a gap, even if the underlying control is not expressly mandated in absolute terms.38- When a vendor, system, or device population is implicated, identify the affected population from the record rather than using generalized language.39- When multiple gaps arise from one control family, separate them so the remediation action can be assigned cleanly.40- Do not infer facts not contained in the materials; where the record is silent, flag the silence as a gap in documentation or evidence.41- Use a severity judgment for every entry on a uniform ordinal scale defined once at the top of the report, and apply it consistently.42- Tie remediation sequencing to the external deadline or review milestone, then work backward from that date for priority ordering.43- End the report with direct recommendations that assign an action, a responsible role, and a timing anchor.4445## 5. Vertical / structural / temporal relationships46- Compare policy language against related support materials, including inventories, logs, attestations, contracts, and implementation evidence.47- Cross-check whether coverage in one document is undermined by exclusions, exceptions, or stale references in another.48- Separate current-state controls from historical artifacts; an outdated assessment or superseded procedure should be treated as different from a live control.49- Where a control depends on another document or operational practice, note the dependency and whether the dependency is satisfied in practice.50- If the record shows multiple time periods or versions, analyze the most recent operative version first and then note legacy conflicts that affect compliance.5152## 6. Output structure conventions53- Write the output as a gap analysis report suitable for a compliance audience.54- Open with a brief executive summary that states the overall posture, the severity scale used, and the distribution of gaps by severity.55- Organize the body by policy or control family, then by specific regulatory gap within each policy.56- For each gap, include:57 - policy or evidence reference,58 - HIPAA Security Rule provision,59 - concise gap description,60 - scope indicator if the record supports one,61 - severity,62 - consequence,63 - remediation action.64- Use precise regulatory citations where available rather than generic references to “HIPAA.”65- Keep the report analytical and action-oriented; do not repeat source text unless necessary to identify the provision or evidence.66- Close with a Recommended Actions section that uses imperative verbs, names the responsible role from the record where possible, and ties each action to a deadline or regulatory milestone.67- If the task asks for a document output, treat the report itself as the primary deliverable and ensure the final content is complete, self-contained, and ready to place into the requested file.