Healthcare PHI Compliance Patterns
Protect patient data with Muse: PHI classification, row-level security, tamper-proof audit trails, and the common leak vectors like logs, URLs and browser storage.
- What
- Protect patient data with Muse: PHI classification, row-level security, tamper-proof audit trails, and the common leak vectors like logs, URLs and browser storage.
- Cost
- Free
- Needs
- Use "Healthcare PHI Compliance Patterns" with your Muse.
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor: compliance patterns for protecting patient and clinician data in healthcare applications, contributed by Dr. Keyur Patel (Health1 Super Speciality Hospitals). Protection works on three layers: classification (what is sensitive), access control (who can see it), and audit (who did see it). PHI is defined as any data that can identify a patient and relates to their health, from names and national IDs to diagnoses, medications and claim details. Access control uses row-level security with facility-scoped policies and insert-only, tamper-proof audit logs. Schema tagging marks PHI and PII columns at the database level. The most practical part is the catalog of common leak vectors: patient data in error messages thrown to the client, full patient objects in console output, identifying data in URL parameters, PHI in browser localStorage, service_role keys in client-side code, and full patient records in logs and error tracking. Each comes with the safe alternative, like opaque UUIDs instead of medical record numbers and generic errors with server-side logging. A deployment checklist closes the skill: no PHI in errors, logs, URLs or browser storage, RLS enabled on all PHI tables, audit trails on, cross-facility isolation verified. By @affaan-m, listed here with credit to its creator and contributor. From the affaan-m/ECC repository (MIT). Honest caveats: patterns do not make an app HIPAA or GDPR compliant by themselves, a real compliance review is required; never put real patient data in a chat while using it; this is development guidance, not legal advice. Skill Harbor never reviews the code, review it yourself before use.
Version:
Install
Copy the install package below, then paste it into MuseThe install prompt below already includes the vetting steps: your agent follows the community checklist before installing anything with executable code. Want more?
Use "Healthcare PHI Compliance Patterns" with your Muse. Prerequisites: none to install. Pure guidance; a healthcare app project helps. 1. Open the skill: https://github.com/affaan-m/ECC/blob/main/skills/healthcare-phi-compliance/SKILL.md and copy the full SKILL.md text. 2. Paste it into a chat with Muse and add: "Audit this code for PHI leak vectors: [paste code, with real patient data replaced by synthetic fixtures]." 3. Ask follow-ups like "which of these log lines could leak patient data?" or "design the RLS policy for this multi-facility schema." Tip: never use real patient data in the chat; use synthetic fixtures. Safety: a skill is plain-text instructions; it runs nothing by itself. This is development guidance, not legal advice. A real compliance review is required.
Saved to your recent installs. Find it anytime on /connect.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.