
HIPAA Compliance Audit Assistant
Audit healthcare operations for HIPAA compliance gaps with evidence-based findings
What You Can Do
You can conduct comprehensive HIPAA compliance audits across your healthcare operations by analyzing workflows, documentation patterns, access logs, and Business Associate Agreements against the 18 primary violation categories. Claude identifies compliance gaps, quantifies risk exposure, and generates evidence-based corrective action plans tailored to your specific departmental or organizational context.
Features
Maps healthcare processes against Privacy and Security Rule requirements to identify unauthorized access and improper disclosure vulnerabilities
Evaluates policies, training records, and risk assessments for sufficiency and identifies missing or inadequate compliance documentation
Analyzes user behavior and access logs to detect unauthorized access patterns and segregation of duties violations
Reviews vendor agreements and third-party access controls to identify BAA compliance gaps
Identifies systemic compliance weaknesses from breach incident trends and near-miss events
Develops prioritized remediation strategies with specific implementation steps and accountability measures
Ranks findings by regulatory impact and breach probability to focus remediation efforts on highest-risk areas
Example Output
Example 1: Workflow Analysis Finding
Input: Your radiology department's image sharing process
Output:
- Gap Identified: Images transmitted via unsecured email to referring physicians (Security Rule §164.312(a)(2)(i) violation)
- Risk Level: High — PHI transmitted without encryption in transit
- Evidence: Documented in 5 workflow interviews; email logs show 847 image transmissions in past 60 days
- Remediation: Implement secure portal with audit logging; train staff on proper transmission protocol within 30 days
Example 2: Documentation Assessment
Input: Your annual risk assessment from 2021
Output:
- Gap Identified: Risk assessment 3+ years outdated; new telehealth workflows and cloud storage systems not evaluated (Security Rule §164.308(a)(1)(ii)(A) violation)
- Evidence: HIPAA Omnibus Rule updates in 2023 require assessment of emerging technology risks
- Remediation: Conduct updated risk assessment covering telehealth, EHR upgrades, and vendor integrations by Q2; allocate 80 hours IT + compliance staff
Example 3: Access Pattern Finding
Input: 90-day access logs for billing department
Output:
- Gap Identified: 12 employees accessing patient records outside assigned patient populations; 1 employee accessed records for 847 unique patients (Privacy Rule §164.502(b) violation)
- Risk Level: Critical — potential data mining or theft
- Evidence: Access patterns inconsistent with job function; no documented business justification
- Remediation: Immediate access suspension and investigation; implement role-based access controls and monthly audit procedures
What's Included
- SKILL.md: Complete HIPAA audit methodology and 18-category violation framework
- Audit Checklist Template: Department-specific compliance assessment matrix covering Privacy Rule, Security Rule, and Breach Notification requirements
- Workflow Analysis Framework: Structured interview and documentation review guide for identifying process-level compliance gaps
- Remediation Action Plan Template: Evidence-based corrective action format with priority ranking, owner assignment, and compliance deadlines
- Business Associate Agreement Review Guide: BAA compliance assessment criteria and vendor risk evaluation matrix
Who It's For
- HIPAA Compliance Officers — conducting annual audits and responding to triggered compliance investigations
- Healthcare Risk Managers — identifying systemic vulnerabilities across departments and operations
- Quality Assurance Directors — integrating compliance assessments into organizational quality improvement processes
- Privacy Officers — analyzing privacy incident patterns and developing corrective action strategies
- Healthcare Legal/Compliance Teams — preparing compliance documentation for regulatory review or breach response
Best For
- Annual or triggered departmental HIPAA compliance audits
- Workflow vulnerability assessments for unauthorized access or improper disclosure risks
- Documentation sufficiency reviews (policies, training records, risk assessments)
- Business Associate and vendor compliance evaluations
- Incident pattern analysis and corrective action planning following breaches or near-miss events







