SkillsLib.ai

HIPAA Compliance Audit Assistant

Audit healthcare operations for HIPAA compliance gaps with evidence-based findings

4.1(31 reviews)
100+ downloads
Updated Oct 2026
Verified SafeSecurity VerifiedThis skill was analyzed by our AI security scanner for harmful content including data exfiltration, system manipulation, credential theft, and prompt injection. No threats were detected.

What You Can Do

You can conduct comprehensive HIPAA compliance audits across your healthcare operations by analyzing workflows, documentation patterns, access logs, and Business Associate Agreements against the 18 primary violation categories. Claude identifies compliance gaps, quantifies risk exposure, and generates evidence-based corrective action plans tailored to your specific departmental or organizational context.

Features

Workflow Analysis

Maps healthcare processes against Privacy and Security Rule requirements to identify unauthorized access and improper disclosure vulnerabilities

Documentation Review

Evaluates policies, training records, and risk assessments for sufficiency and identifies missing or inadequate compliance documentation

Access Pattern Assessment

Analyzes user behavior and access logs to detect unauthorized access patterns and segregation of duties violations

Business Associate Evaluation

Reviews vendor agreements and third-party access controls to identify BAA compliance gaps

Incident Pattern Analysis

Identifies systemic compliance weaknesses from breach incident trends and near-miss events

Corrective Action Planning

Develops prioritized remediation strategies with specific implementation steps and accountability measures

Risk Prioritization

Ranks findings by regulatory impact and breach probability to focus remediation efforts on highest-risk areas

Example Output

Example 1: Workflow Analysis Finding

Input: Your radiology department's image sharing process

Output:

  • Gap Identified: Images transmitted via unsecured email to referring physicians (Security Rule §164.312(a)(2)(i) violation)
  • Risk Level: High — PHI transmitted without encryption in transit
  • Evidence: Documented in 5 workflow interviews; email logs show 847 image transmissions in past 60 days
  • Remediation: Implement secure portal with audit logging; train staff on proper transmission protocol within 30 days

Example 2: Documentation Assessment

Input: Your annual risk assessment from 2021

Output:

  • Gap Identified: Risk assessment 3+ years outdated; new telehealth workflows and cloud storage systems not evaluated (Security Rule §164.308(a)(1)(ii)(A) violation)
  • Evidence: HIPAA Omnibus Rule updates in 2023 require assessment of emerging technology risks
  • Remediation: Conduct updated risk assessment covering telehealth, EHR upgrades, and vendor integrations by Q2; allocate 80 hours IT + compliance staff

Example 3: Access Pattern Finding

Input: 90-day access logs for billing department

Output:

  • Gap Identified: 12 employees accessing patient records outside assigned patient populations; 1 employee accessed records for 847 unique patients (Privacy Rule §164.502(b) violation)
  • Risk Level: Critical — potential data mining or theft
  • Evidence: Access patterns inconsistent with job function; no documented business justification
  • Remediation: Immediate access suspension and investigation; implement role-based access controls and monthly audit procedures

What's Included

  • SKILL.md: Complete HIPAA audit methodology and 18-category violation framework
  • Audit Checklist Template: Department-specific compliance assessment matrix covering Privacy Rule, Security Rule, and Breach Notification requirements
  • Workflow Analysis Framework: Structured interview and documentation review guide for identifying process-level compliance gaps
  • Remediation Action Plan Template: Evidence-based corrective action format with priority ranking, owner assignment, and compliance deadlines
  • Business Associate Agreement Review Guide: BAA compliance assessment criteria and vendor risk evaluation matrix

Who It's For

  • HIPAA Compliance Officers — conducting annual audits and responding to triggered compliance investigations
  • Healthcare Risk Managers — identifying systemic vulnerabilities across departments and operations
  • Quality Assurance Directors — integrating compliance assessments into organizational quality improvement processes
  • Privacy Officers — analyzing privacy incident patterns and developing corrective action strategies
  • Healthcare Legal/Compliance Teams — preparing compliance documentation for regulatory review or breach response

Best For

  • Annual or triggered departmental HIPAA compliance audits
  • Workflow vulnerability assessments for unauthorized access or improper disclosure risks
  • Documentation sufficiency reviews (policies, training records, risk assessments)
  • Business Associate and vendor compliance evaluations
  • Incident pattern analysis and corrective action planning following breaches or near-miss events

You might also like

Political Risk Assessment for Health Diplomacy
$45
Political4.1(31)
Political Risk Assessment for Health Diplomacy

You can systematically evaluate how political instability, leadership transitions, factional conflicts, and policy shifts affect your health security objectives and medical diplomacy initiatives. The skill identifies specific political vulnerabilities in healthcare infrastructure, pharmaceutical supply chains, aid acceptance, bilateral agreements, and cross-border health cooperation—enabling you to assess feasibility before committing resources and develop contingency protocols for high-risk environments.

Deal Scorecard
$40
Deal Scorecard

You can systematically assess any sales opportunity across four critical dimensions—fit, budget, timeline, and authority—to determine deal viability and prioritize your pipeline. The skill generates a composite health score (0-100), surfaces risk flags, identifies gaps, and produces a prioritized action plan so you can focus on high-probability opportunities and know exactly what to do next.

Pre-Authorization Medical Necessity Analyzer
$30
Pre-Authorization Medical Necessity Analyzer

You can rapidly evaluate pre-authorization requests by extracting clinical information from provider submissions, mapping findings against medical necessity standards, identifying documentation gaps, and generating clear authorization decisions with detailed rationale. This creates an audit trail that withstands peer review and appeals while supporting provider education through transparent decision logic.

Grant Compliance Report Generator
$30
Reporting4.0(31)
Grant Compliance Report Generator

You can transform scattered financial data, program metrics, and budget spreadsheets into comprehensive, compliance-ready grant reports tailored to specific funder requirements. Claude reconciles budgeted versus actual spending, extracts outcomes data, flags variances, and generates audit-trail documentation—reducing manual synthesis work from days to hours while ensuring accuracy and funder alignment.

Patient Satisfaction Insight Analyzer
$35
Patient Satisfaction Insight Analyzer

You can process large volumes of patient feedback—surveys, reviews, complaints, and compliments—to identify recurring themes and emotional patterns that drive satisfaction. Claude reveals which service touchpoints matter most to your patient population, highlights systemic gaps, and generates prioritized improvement initiatives with clear implementation pathways. This transforms reactive complaint handling into proactive satisfaction architecture grounded in data.

Trade Agreement Healthcare Economic Analyzer
$45
Economic3.4(34)
Trade Agreement Healthcare Economic Analyzer

You can rapidly assess the healthcare economic implications of trade agreements by analyzing tariff classifications on pharmaceuticals and medical devices, evaluating intellectual property provisions affecting drug market entry, reviewing GATS commitments on healthcare service trade, and identifying competitive advantages or disadvantages across your portfolio countries. This skill helps you quantify market access gains and pricing pressures while flagging regulatory harmonization commitments that affect healthcare delivery.

State Grant Compliance Navigator
$45
State4.0(34)
State Grant Compliance Navigator

You can systematically decode state-specific grant requirements across Medicaid, workforce development, rural health, and behavioral health programs. The skill helps you identify compliance gaps in your current processes, build state-compliant budget narratives and work plans, and create audit-ready documentation frameworks tailored to your state's unique administrative standards and reporting frequencies.

Credentialing Verification Orchestrator
$35
Credentialing Verification Orchestrator

You can systematize the entire primary source verification lifecycle—from initial data collection through final documentation—for healthcare providers. This skill manages verification requests across multiple credential categories (licenses, education, DEA, employment history), tracks source coordination timelines, resolves discrepancies between sources, and produces compliance-ready verification reports that satisfy Joint Commission, CMS, and plan network audits.

$40.00