From openmed-skills
Verifies OpenMed de-identified output against all 18 HIPAA Safe Harbor identifier categories and reports residual re-identification risk. Use after de-identification to confirm coverage or before release to assess Safe Harbor achievability.
How this skill is triggered — by the user, by Claude, or both
Slash command
/openmed-skills:auditing-safe-harbor-checklistThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
The Safe Harbor method (45 CFR 164.514(b)(2)) de-identifies PHI by removing
The Safe Harbor method (45 CFR 164.514(b)(2)) de-identifies PHI by removing 18 specific identifier categories for the individual and their relatives, employers, and household members — and requires the covered entity to have no actual knowledge that the remainder could re-identify anyone. This skill turns that legal checklist into a concrete coverage check over OpenMed output: which of the 18 categories were detected and handled, and where the gaps are.
The full mapping table lives in
references/safe-harbor-identifiers.md —
all 18 categories, their OpenMed HIPAA class, the matching CANONICAL_LABELS,
and per-category cautions. Read it when you need the authoritative cross-walk.
Use it after a de-identification run to prove coverage, or before release to
decide whether Safe Harbor is even achievable for this text. If the user needs a
signed, retained record of the run, hand off to auditing-deidentification-runs.
import openmed
from openmed.core.labels import LABEL_TO_HIPAA, HIPAA_SAFE_HARBOR_CLASSES
note = (
"Patient John Doe (MRN 1234567), age 92, of Smalltown, seen 2024-03-02. "
"SSN 123-45-6789, phone 617-555-0142."
)
# 1) Detect identifiers (spans only; no rewrite).
detected = openmed.extract_pii(note)
# 2) Roll each detected span up to its HIPAA Safe Harbor class.
covered = set()
for ent in detected.entities:
canonical = openmed.normalize_label(ent.label) # -> CANONICAL_LABELS form
hipaa_class = LABEL_TO_HIPAA.get(canonical) # -> one of 18 classes
if hipaa_class:
covered.add(hipaa_class)
# 3) Report which of the 18 classes were touched and which weren't observed.
missing = sorted(HIPAA_SAFE_HARBOR_CLASSES - covered)
print("covered:", sorted(covered))
print("not observed in this note:", missing)
"Not observed" is not the same as "absent" — a category may simply not occur in this note, or may have been missed. That is exactly what the human review step (below) is for.
openmed.deidentify(note, policy="hipaa_safe_harbor"). This masks every
identifier class by default and runs the mandatory structured-ID safety sweep.LABEL_TO_HIPAA (as above).
Build a table of category → detected? → action taken.AGE) must be aggregated to "90+"; OpenMed flags but does
not auto-cap — see shifting-clinical-dates.PHONE label; biometrics and full-face photos
are out of scope for text — handle in the imaging/intake pipeline.audit=True and read residual_risk
(auditing-deidentification-runs). Non-zero projected leakage → review.openmed.extract_pii (spans) and openmed.deidentify
(rewrite) — see deidentifying-clinical-text.openmed.CANONICAL_LABELS, openmed.normalize_label, and
LABEL_TO_HIPAA / HIPAA_SAFE_HARBOR_CLASSES in openmed/core/labels.py.auditing-deidentification-runs
(audit=True → AuditReport.residual_risk).configuring-privacy-policies — if you must keep dates or
geography, Safe Harbor fails; use Expert Determination
(hipaa_expert_review_assist) or a Limited Data Set
(research_limited_dataset).strict_no_leak exists for high-stakes data.openmed/core/labels.py (LABEL_TO_HIPAA,
HIPAA_SAFE_HARBOR_CLASSES, CANONICAL_LABELS, normalize_label).npx claudepluginhub maziyarpanahi/openmed --plugin openmed-skillsDe-identifies PHI via HIPAA safe harbor (removes 18 identifiers) and expert determination methods. Assesses re-identification risks, limited datasets, and data agreements.
Runs a HIPAA Privacy and Security Rule checklist over a data pipeline and produces a gap report for pre-deployment compliance review on PHI.
Guides PHI data handling per HIPAA: 18 identifiers, Safe Harbor/Expert Determination de-identification, minimum necessary principle, RBAC access controls, audit logging, encryption at rest/transit, secure disposal.