
Healthcare Records Compliance & Audit Assistant
Audit healthcare records for HIPAA compliance and regulatory requirements
What You Can Do
You can submit healthcare records, documentation, and policies to this skill for comprehensive compliance auditing. It identifies gaps against HIPAA Privacy and Security Rules, assesses breach risks, and generates detailed audit reports with remediation recommendations. You'll receive a compliance score, specific violation findings, and actionable steps to strengthen your healthcare organization's record management practices.
Features
Analyzes records against all Privacy Rule, Security Rule, and Breach Notification Rule requirements with specific section citations
Examines policies, access logs, consent forms, and retention procedures to identify missing or incomplete documentation
Evaluates your current record practices for vulnerability to unauthorized access, loss, or disclosure
Validates that access logs are complete, tamper-proof, and meet retention and accountability standards
Produces an overall compliance percentage with breakdowns by category (Privacy, Security, Breach Notification, Documentation)
Creates professional, detailed reports with findings, risk levels, and executive summaries for board presentation
Prioritizes violations by risk and provides step-by-step remediation steps with implementation timelines
Helps prepare documentation and evidence for OCR audits, state AG investigations, and healthcare facility inspections
Example Output
Audit Report Summary
Compliance Score: 72%
Key Findings:
✓ Privacy Rule Compliance: 85%
- Issue: Patient consent forms lack specific authorization for use in research (HIPAA § 164.508(c))
- Risk: Medium — potential legal liability
- Remediation: Add research-use checkbox to consent template within 30 days
✓ Security Rule Compliance: 68%
- Issue: Access logs lack documented review procedures (HIPAA § 164.312(b))
- Risk: High — no audit mechanism in place
- Remediation: Implement monthly log review schedule with documented sign-off
✓ Breach Notification Rule: 82%
- Issue: Breach investigation procedures do not specify forensic steps
- Risk: Medium — incomplete incident response plan
- Remediation: Add forensic imaging and chain-of-custody procedures to breach response policy
Next Steps (90-day plan): Update 3 policies, implement access log review, train 15 staff on HIPAA compliance procedures
What's Included
- HIPAA Compliance Audit Framework: Reference implementation covering Privacy Rule, Security Rule, and Breach Notification Rule with regulation section mapping
- Documentation Templates: Audit checklists, compliance scorecards, policy review templates, and breach response verification forms
- Risk Assessment Methodology: Structured approach to identify, categorize, and prioritize compliance gaps by regulatory risk
- Remediation Tracking Tool: Template for documenting and monitoring fixes with implementation dates and evidence collection
- Audit Report Generator: Formats findings into professional reports suitable for board presentation, legal review, and OCR submission
Who It's For
- Chief Compliance Officers
- Privacy & Security Officers
- Healthcare Practice Managers
- Hospital Audit Departments
- Healthcare Legal Counsel
Best For
- Annual HIPAA compliance audits
- Breach investigation & documentation
- OCR audit preparation
- Healthcare facility certification reviews
- Policy gap analysis & remediation planning







