HIPAA Compliance
HIPAA entrypoint for Muse on US healthcare work: PHI decision gates, minimum necessary access, BAA checks, and guardrails that keep PHI out of logs, prompts, and URLs.
- What
- HIPAA entrypoint for Muse on US healthcare work: PHI decision gates, minimum necessary access, BAA checks, and guardrails that keep PHI out of logs, prompts, and URLs.
- Cost
- Free
- Needs
- Use "HIPAA Compliance" with your Muse.
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor: the HIPAA-specific entrypoint for Muse when a task is explicitly about US healthcare compliance. It stays intentionally thin and canonical, routing the concrete implementation work to companion skills (PHI handling rules, healthcare code review, general security review) while applying HIPAA-specific decision gates: is this data PHI, is this actor a covered entity or business associate, does the vendor need a BAA before touching the data, is access limited to the minimum necessary, and are read/write/export events auditable. The guardrails are blunt: never place PHI in logs, analytics events, crash reports, prompts, or client-visible error strings; never expose PHI in URLs, browser storage, screenshots, or example payloads; treat third-party SaaS, observability, support tooling and LLM providers as blocked-by-default until BAA status is clear; prefer opaque internal IDs over names, phone numbers or addresses. Includes worked examples (AI visit summaries for a clinician dashboard, support transcripts into analytics) showing how the gates apply in practice. By @affaan-m, listed here with credit to its creator. From the affaan-m/ECC repository (MIT). Honest caveats: this is guidance, not legal advice; following a checklist does not make you HIPAA compliant, a real compliance review still belongs to your compliance officer and counsel. Skill Harbor never reviews the code, review it yourself before use.
Version:
Install
Copy the install package below, then paste it into MuseThe install prompt below already includes the vetting steps: your agent follows the community checklist before installing anything with executable code. Want more?
Use "HIPAA Compliance" with your Muse. Prerequisites: none to install. Pure guidance; a US healthcare project helps. 1. Open the skill: https://github.com/affaan-m/ECC/blob/main/skills/hipaa-compliance/SKILL.md and copy the full SKILL.md text. 2. Paste it into a chat with Muse and add: "Review this design for HIPAA exposure: [paste the design, data flow, or code]." 3. Ask it to run the decision gates: is this PHI, who are the actors, which vendors need a BAA, and where could PHI leak into logs, prompts, or URLs. Tip: paste your logging and analytics plan and ask "show me every place PHI could leak." Safety: a skill is plain-text instructions; it runs nothing by itself. Never paste real PHI into any chat while testing.
Saved to your recent installs. Find it anytime on /connect.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.