Hipaa Privacy Minimum Necessary

Implements HIPAA Privacy Rule minimum necessary standard—45 CFR §164.502(b)—plus §164.514 de-identification, Limited Data Sets, and patient rights to access and amend records, with agent prompt minimization, role-based PHI exposure, and integration with the Presidio redaction pipeline. Trigger when designing LLM/agent PHI access policies, auditing disclosure practices, implementing patient rights workflows, or validating that agent prompts contain only minimum necessary ePHI. Do not use for Presidio entity tuning alone (use hipaa-phi-redaction-pipeline), Security Rule technical controls (use hipaa-technical-safeguards), or BAA legal review (use hipaa-baa-vendor-assessment).

vaquarkhan Updated

File contents

vaquarkhan/compliance-agent-skills/tree/main/skills/hipaa-privacy-minimum-necessary commit 309010ee1b

Frequently asked questions

npx skillmds@latest add vaquarkhan/hipaa-privacy-minimum-necessary