
Healthcare Data Governance Framework Builder
Build HIPAA-aligned healthcare data governance frameworks with compliance mapping
What You Can Do
You can design complete data governance frameworks that establish clear ownership, access controls, data quality standards, and breach protocols across EHR systems, data warehouses, and integration platforms. The skill maps regulatory requirements to organizational policies, defines data stewardship roles with accountability matrices, and creates audit procedures and metrics for ongoing compliance monitoring—all in formats ready for board presentation or regulatory review.
Features
Align HIPAA, HITECH, state privacy laws, and 21st Century Cures Act requirements to organizational policies
Create accountability matrices that define ownership, responsibilities, and escalation paths across departments
Develop risk-based classification systems that categorize data by sensitivity and regulatory requirements
Establish protocols for compliance monitoring, breach response, and documentation ready for CMS, OCR, or state attorney general reviews
Generate governance policies in formats suitable for board presentations, staff training, and regulatory submissions
Define procedures for patient access requests, amendments, disclosures, and breach notifications
Create data quality standards specific to EHR, cancer registry, claims, or other healthcare systems
Structure governance documentation to align with accreditation standards and regulatory expectations
Example Output
Example 1: HIPAA Compliance Mapping Document
- Regulation: 45 CFR §164.308(a)(1) — Risk Analysis
- Policy Requirement: Annual risk assessment covering all systems handling PHI
- Responsible Role: Chief Privacy Officer + IT Director
- Evidence: Risk assessment template, vendor attestations, audit logs
Example 2: Data Stewardship Accountability Matrix
| Department | Data Steward | Responsibilities | Escalation |
|---|---|---|---|
| Cardiology | Dr. Smith | EHR data quality, access approvals, audit compliance | Chief Medical Officer |
| Claims | Jane Doe | Claims data completeness, error tracking, breach protocols | Compliance Director |
Example 3: Data Classification Schema
- Level 1 (Public): Non-identifiable, published data
- Level 2 (Internal): De-identified research data, operational metrics
- Level 3 (Confidential): PHI with routine access controls, encryption required
- Level 4 (Restricted): Highly sensitive data (genetic info, behavioral health), role-based access
What's Included
- SKILL.md instruction file: Complete framework-building methodology and compliance principles
- HIPAA Compliance Mapping Template: Checklist linking regulatory requirements to organizational policies
- Data Stewardship Accountability Matrix: Role definition and responsibility assignment template
- Data Classification Schema Worksheet: Risk-based categorization framework for healthcare datasets
- Audit Procedures Checklist: Protocols for ongoing monitoring, documentation, and breach response
- Policy Documentation Outline: Structure for board-ready governance policies and staff training materials
Who It's For
- Health Information Managers — Design and oversee governance frameworks for compliance and operational efficiency
- Compliance Officers — Prepare for regulatory audits and map new requirements to existing policies
- Chief Privacy Officers — Establish privacy governance and breach protocols across enterprise systems
- Healthcare IT Leaders — Define data access controls and stewardship roles for EHR and data warehouse systems
- Clinical Department Heads — Understand data governance expectations and accountability in their specialty areas
Best For
- Building governance frameworks from scratch or overhauling existing ones
- Preparing for regulatory audits (CMS, OCR HIPAA audits, state attorney general reviews)
- Mapping new state privacy laws or federal regulations to organizational policies
- Creating data stewardship accountability matrices across clinical and administrative departments
- Developing data quality standards for specific systems (EHR, cancer registry, claims)
- Establishing data access request, amendment, and breach response protocols
- Training staff on data handling expectations and governance compliance







