
HIPAA Compliance Documentation Auditor
Generate audit-ready HIPAA compliance documentation with regulatory citations
What You Can Do
You can generate comprehensive, audit-ready HIPAA compliance documentation that synthesizes complex regulatory requirements with your organizational systems. The skill produces regulatory-compliant language, gap analyses, breach notification packages, and corrective action plans with traceable audit trails that satisfy OCR (HHS Office for Civil Rights) expectations—eliminating manual compilation of regulations and policies.
Features
Creates compliant PIAs for new IT systems, workflows, and third-party integrations with regulatory alignment
Generates incident summaries, notification letters, and regulatory reporting documents ready for OCR submission
Maps organizational policies against HIPAA/HITECH Act requirements and identifies compliance gaps with remediation steps
Includes specific CFR citations and regulatory references to support audit defense and board presentations
Documents remediation workflows with timelines, ownership assignments, and verification checkpoints
Reviews BAA language for compliance gaps and generates amendment recommendations
Creates compliance training records and attestations proving workforce education requirements are met
Produces comprehensive reports for internal committees, external auditors, and accreditation reviews with executive summaries
Example Output
Privacy Impact Assessment Output:
- System name, data flows, and PHI inventory
- Risk assessment matrix with probability/impact ratings
- Regulatory compliance checklist (45 CFR §§164.308-318)
- Recommended safeguard enhancements with implementation timeline
Breach Notification Package Output:
- Incident summary with timeline and affected individuals count
- Notification letter template (45 CFR §164.404 compliant)
- OCR reporting checklist and submission requirements
- Internal incident log with containment steps documented
Gap Analysis Report Output:
- Current state vs. required state comparison table
- Risk ratings (Critical/High/Medium/Low) with CFR citations
- Corrective action assignments with responsible parties and deadlines
- Before/after compliance metrics
What's Included
- SKILL.md instruction file: Full skill configuration with regulatory context and use case guidance
- Privacy Impact Assessment template: Structured PIA workflow covering system analysis, risk assessment, and control mapping
- Breach notification package template: Pre-formatted notification letters, incident logs, and OCR submission checklists
- Gap analysis framework: Systematic compliance audit checklist mapping 21 HIPAA Rule safeguard categories
- Corrective action plan template: Remediation tracking with ownership, timelines, and verification steps
Who It's For
- Health Information Managers — Responsible for HIPAA compliance and privacy operations across healthcare organizations
- Compliance Officers — Conduct internal audits, manage regulatory submissions, and oversee corrective actions
- Privacy Officers — Lead privacy assessments, manage breach responses, and document compliance evidence
- Chief Information Security Officers (CISOs) — Assess IT system risks and document safeguard implementations
- Audit and Accreditation Teams — Support external audits, OCR investigations, and accreditation reviews
Best For
- Routine HIPAA compliance assessments across departments or healthcare systems
- Privacy Impact Assessments for new IT systems, EHR implementations, or third-party integrations
- Breach response and incident documentation for regulatory reporting
- Business Associate Agreement review and compliance gap identification
- Corrective action planning following internal audits or OCR findings
- Workforce compliance training documentation and attestation records







