HIPAA Compliance for AI Agents
Generate HIPAA compliance checklists, risk assessments, and audit frameworks for healthcare organizations deploying AI agents.
What This Skill Does
When activated, produce any of these deliverables based on user request:
1. Pre-Deployment Compliance Gate
- BAA requirements checklist for AI vendors
- PHI data flow mapping template
- Minimum Necessary standard application guide
- Risk assessment framework (45 CFR 164.308(a)(1))
2. Technical Safeguards (45 CFR 164.312)
Access Controls:
- Unique service account IDs for AI agents
- Emergency access procedures for system failures
- 15-minute auto-logoff configuration
- Role-based minimum necessary permissions
Audit Controls:
- PHI access logging (timestamp, user, action, data)
- 6-year retention compliance
- Anomaly detection on access patterns
- AI decision audit trails
Transmission Security:
- TLS 1.3 enforcement
- E2E encryption for patient comms
- Certificate pinning for API connections
- No PHI in URLs, query strings, or logs
3. AI-Specific Risk Matrix
| Risk |
Impact |
Mitigation |
| Prompt injection → PHI leak |
Critical |
Input sanitization, output filtering, sandboxing |
| Model training on PHI |
High |
BAA prohibition, single-tenant deployment |
| Hallucinated medical info |
Critical |
Human-in-loop, confidence thresholds |
| Shadow AI with PHI |
High |
Approved tool registry, DLP rules |
4. Breach Response Timeline
- 0-1 hrs: Contain (disable agent, preserve logs)
- 1-24 hrs: Assess scope of PHI exposure
- 24-48 hrs: Document root cause, affected individuals
- Within 60 days: Notify HHS + individuals + media (if 500+)
- 30-90 days: Remediate, patch, retrain
5. Compliance by Use Case
Rate each AI deployment:
- Patient scheduling → Medium risk
- Billing/coding → High risk
- Clinical decision support → Critical risk
- Patient communication → High risk
- Medical records summarization → Critical risk
6. Penalty Reference
| Tier |
Per Violation |
Annual Cap |
| Unknowing |
$141 - $71,162 |
$2,134,831 |
| Reasonable cause |
$1,424 - $71,162 |
$2,134,831 |
| Willful neglect (corrected) |
$14,232 - $71,162 |
$2,134,831 |
| Willful neglect (not corrected) |
$71,162 |
$2,134,831 |
Average healthcare breach cost: $10.93M (IBM/Ponemon 2025).
Output Format
- Markdown checklist with status columns
- Risk matrix with impact/likelihood scoring
- Timeline tables for breach response
- Department-specific compliance cards
Resources
1---2name: hipaa-compliance-for-ai-agents3description: Generate HIPAA compliance checklists, risk assessments, and audit frameworks for healthcare organizations deploying AI agents.4---5
6# HIPAA Compliance for AI Agents
7
8Generate HIPAA compliance checklists, risk assessments, and audit frameworks for healthcare organizations deploying AI agents.
9
10## What This Skill Does
11
12When activated, produce any of these deliverables based on user request:
13
14### 1. Pre-Deployment Compliance Gate
15- BAA requirements checklist for AI vendors
16- PHI data flow mapping template
17- Minimum Necessary standard application guide
18- Risk assessment framework (45 CFR 164.308(a)(1))
19
20### 2. Technical Safeguards (45 CFR 164.312)
21**Access Controls:**
22- Unique service account IDs for AI agents
23- Emergency access procedures for system failures
24- 15-minute auto-logoff configuration
25- Role-based minimum necessary permissions
26
27**Audit Controls:**
28- PHI access logging (timestamp, user, action, data)
29- 6-year retention compliance
30- Anomaly detection on access patterns
31- AI decision audit trails
32
33**Transmission Security:**
34- TLS 1.3 enforcement
35- E2E encryption for patient comms
36- Certificate pinning for API connections
37- No PHI in URLs, query strings, or logs
38
39### 3. AI-Specific Risk Matrix
40
41| Risk | Impact | Mitigation |
42|------|--------|------------|
43| Prompt injection → PHI leak | Critical | Input sanitization, output filtering, sandboxing |
44| Model training on PHI | High | BAA prohibition, single-tenant deployment |
45| Hallucinated medical info | Critical | Human-in-loop, confidence thresholds |
46| Shadow AI with PHI | High | Approved tool registry, DLP rules |
47
48### 4. Breach Response Timeline
49- 0-1 hrs: Contain (disable agent, preserve logs)
50- 1-24 hrs: Assess scope of PHI exposure
51- 24-48 hrs: Document root cause, affected individuals
52- Within 60 days: Notify HHS + individuals + media (if 500+)
53- 30-90 days: Remediate, patch, retrain
54
55### 5. Compliance by Use Case
56Rate each AI deployment:
57- Patient scheduling → Medium risk
58- Billing/coding → High risk
59- Clinical decision support → Critical risk
60- Patient communication → High risk
61- Medical records summarization → Critical risk
62
63### 6. Penalty Reference
64| Tier | Per Violation | Annual Cap |
65|------|-------------|------------|
66| Unknowing | $141 - $71,162 | $2,134,831 |
67| Reasonable cause | $1,424 - $71,162 | $2,134,831 |
68| Willful neglect (corrected) | $14,232 - $71,162 | $2,134,831 |
69| Willful neglect (not corrected) | $71,162 | $2,134,831 |
70
71Average healthcare breach cost: $10.93M (IBM/Ponemon 2025).
72
73## Output Format
74- Markdown checklist with status columns
75- Risk matrix with impact/likelihood scoring
76- Timeline tables for breach response
77- Department-specific compliance cards
78
79## Resources
80- [Healthcare AI Context Pack — $47](https://afrexai-cto.github.io/context-packs/) — Full patient journey automation, revenue cycle, EHR integration patterns
81- [AI Revenue Leak Calculator](https://afrexai-cto.github.io/ai-revenue-calculator/) — Find where manual processes cost you money
82- [AI Agent Setup Wizard](https://afrexai-cto.github.io/agent-setup/) — Configure compliant AI agents in 5 minutes