From domain-healthcare
Guides PHI data handling per HIPAA: 18 identifiers, Safe Harbor/Expert Determination de-identification, minimum necessary principle, RBAC access controls, audit logging, encryption at rest/transit, secure disposal.
How this skill is triggered — by the user, by Claude, or both
Slash command
/domain-healthcare:phi-data-handlingThis skill is limited to the following tools:
The summary Claude sees in its skill listing — used to decide when to auto-load this skill
- Determining whether a dataset or field constitutes PHI
references/identifiers-deidentification.md — the 18 HIPAA identifiers, Safe Harbor removal checklist, Expert Determination method and documentation requirementsreferences/access-controls-audit-logging.md — minimum necessary principle, RBAC table by clinical role, break-glass implementation, required audit log fields, tamper-evident logging, high-risk access review cadencereferences/encryption-disposal.md — AES-256-GCM column encryption, TDE, key rotation with cloud KMS, mTLS for microservices, NIST SP 800-88 disposal methods, cryptographic erasure patternnpx claudepluginhub rnavarych/alpha-engineer --plugin domain-healthcareRuns a HIPAA Privacy and Security Rule checklist over a data pipeline and produces a gap report for pre-deployment compliance review on PHI.
Audits applications and infrastructure for HIPAA compliance: Security Rule safeguards, Privacy Rule, Breach Notification Rule, ePHI scoping, BAA chain, and minimum-necessary standard.
PHI/PII compliance patterns for healthcare apps covering data classification, row-level security, audit trails, encryption, and common leak vectors.