← all publishers

EliasAli0720

@eliasali0720 source repo

10 published skills

  1. Hipaa Code Review · eliasali0720 bundle
    Reviews code, diffs, and infrastructure-as-code for HIPAA violations — PHI in logs and URLs, non-BAA analytics and crash SDKs, missing encryption, weak access control and audit logging — and ships a runnable PHI scanner script. Use when asked to review code for HIPAA, scan for PHI, check a diff for PHI leaks, audit a healthcare codebase, or verify a health app's code before release.
    0
    installs
  2. Hipaa Fundamentals · eliasali0720 bundle
    Determines whether and how HIPAA applies to a product, company, or data flow, and explains the core rules with exact regulatory citations — PHI and the 18 identifiers, covered entities vs business associates, Privacy/Security/Breach Notification Rules, patient rights, and penalties. Use when someone asks "does HIPAA apply to us", "is this PHI", "are we a business associate", "do we need a BAA", or needs any HIPAA scoping, definitions, or regulatory overview.
    0
    installs
  3. Hipaa AI Compliance · eliasali0720 bundle
    Guides HIPAA-compliant deployment of AI on health data — using an LLM with PHI, AI agents in healthcare, HIPAA chatbots, medical AI, RAG over patient data, ambient scribes, and de-identifying data for AI training — covering BAA'd endpoint selection, zero data retention, redaction, agent scoping, and audit logging. Use when someone asks about a HIPAA chatbot, sending PHI to an LLM, or Claude/OpenAI/Azure OpenAI/Bedrock BAA availability.
    0
    installs
  4. Hipaa Risk Analysis · eliasali0720 bundle
    Conducts and reviews HIPAA Security Rule risk analyses under 45 CFR 164.308(a)(1)(ii)(A) using the NIST SP 800-66r2 methodology — ePHI asset inventory, data-flow mapping, threat and vulnerability identification, likelihood/impact rating, risk register, and risk management plan. Use when someone asks for a HIPAA risk analysis, risk assessment, security risk assessment (SRA), 164.308 compliance, OCR audit prep, or an asset inventory of ePHI systems.
    0
    installs
  5. Hipaa Baa Management · eliasali0720 bundle
    Determines business associate status, runs the full BAA lifecycle (vendor inventory, execution before PHI flows, subcontractor flow-down, annual review, termination), and reviews BAAs against the required elements of 45 CFR §164.504(e). Use when someone asks "do we need a BAA", "review this BAA", needs a vendor assessment for HIPAA, mentions a business associate agreement or a subcontractor agreement involving PHI, or wants to know whether a specific vendor signs a BAA.
    0
    installs
  6. Hipaa App Development · eliasali0720 bundle
    Architecture and implementation guidance for building mobile apps, backends, and cloud infrastructure that handle PHI — BAA execution, HIPAA-eligible service selection on AWS/Azure/GCP, mobile hardening, API authorization, audit logging, and encryption, with exact CFR citations. Use when building a health app, telehealth app, or patient portal, designing a HIPAA backend or HIPAA cloud environment, or asking about an AWS/Azure/GCP BAA, push notifications, analytics SDKs, or PHI in a mobile app.
    0
    installs
  7. Hipaa Breach Response · eliasali0720 bundle
    Runs the HIPAA breach response playbook end to end — discovery clock, containment, forensics, the 4-factor risk assessment under §164.402(2), the full notification decision tree with exact deadlines, and OCR investigation response. Use when someone reports a data breach, ransomware, or any security incident involving PHI, asks "do we have to report" or "is this a breach", needs a breach notification plan or 4-factor risk assessment, or is responding to an OCR investigation.
    0
    installs
  8. Hipaa Deidentification · eliasali0720 bundle
    Selects and executes the correct HIPAA de-identification path — Safe Harbor's 18 identifiers, Expert Determination, or a limited data set under a DUA — and flags residual re-identification risk in the LLM era. Use when someone asks to de-identify or anonymize patient data, mentions de-identification, Safe Harbor, Expert Determination, the 18 identifiers, or a limited data set, or wants test data from production, analytics exports, or AI training corpora built from PHI.
    0
    installs
  9. Hipaa Compliance Program · eliasali0720 bundle
    Builds and matures a HIPAA compliance program — the 12 required policies, Privacy Officer and Security Officer designation, workforce training, 6-year documentation retention, and OCR audit readiness — staged from day-1 startup to enterprise. Use when someone asks how to become HIPAA compliant, needs a HIPAA compliance program, HIPAA policies, a compliance checklist for a startup, privacy officer or security officer duties, HIPAA training requirements, or is preparing for an OCR audit.
    0
    installs
  10. Hipaa Website Compliance · eliasali0720 bundle
    Audits and remediates healthcare websites for HIPAA and state privacy-law exposure — tracking pixels and analytics (Meta pixel, Google Analytics on a health site), web forms, patient portals, cookie consent, HIPAA hosting, and NPP posting — with exact citations, tool-by-tool BAA verdicts, and prioritized fixes. Use when someone mentions a healthcare website, tracking pixel, Meta pixel, GA4 on a hospital or clinic site, patient portal, web form, cookie banner or consent, HIPAA hosting, or a website tracker audit.
    0
    installs