Use this as the HIPAA-specific entrypoint when a task is clearly about US healthcare compliance. This skill intentionally stays thin and canonical:
- `healthcare-phi-compliance` remains the primary implementation skill for PHI/PII handling, data classification, audit logging, encryption, and leak prevention.
- `healthcare-reviewer` remains the specialized reviewer when code, architecture, or product behavior needs a healthcare-aware second pass.
- `security-review` still applies for general auth, input-handling, secrets, API, and deployment hardening.
Key Features
HIPAA-specific decision gates and guardrails
PHI exposure prevention rules
Vendor and BAA evaluation steps
Privacy & Security
Data Collection
This tool follows industry-standard security practices and only collects data necessary for functionality.