hipaa-compliance-auditor

hipaa-compliance-auditor is a skill for Claude Code, Codex from aipoch/medical-research-skills. It costs 58 tokens per session (2,689 once invoked), scanned A, original, MIT.

A healthcare text scanner that detects and removes personally identifiable information and protected health information. It covers the 18 identifier categories defined by HIPAA, the US health-data privacy law.

In plain words
What is it for?
Use it to scan healthcare text, identify sensitive details, create de-identified versions, and produce audit logs.
Why use it?
It helps reduce privacy risks when preparing clinical text for analysis or sharing while keeping the document structure intact.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one.

Good fit Use it to scan healthcare text, identify sensitive details, create de-identified versions, and produce audit logs.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/aipoch/medical-research-skills/hipaa-compliance-auditor
About the project

Medical Research Agent Skills is a library of agent instructions for medical and biomedical research, covering evidence analysis, study protocol design, data analysis, and academic writing. Researchers use it to guide compatible coding agents through common scientific workflows. The catalogue contains many of the library's skills and commands.

aipoch/medical-research-skills · 1,860 stars · on GitHub · aipoch.com

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add aipoch/medical-research-skills --skill hipaa-compliance-auditor
Clone the repo
git clone --depth 1 https://github.com/aipoch/medical-research-skills

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for hipaa-compliance-auditor

README.md
[![agentmods](https://agentmods.dev/badge/skills/aipoch/medical-research-skills/hipaa-compliance-auditor/github.svg)](https://agentmods.dev/skills/aipoch/medical-research-skills/hipaa-compliance-auditor)
Your own site
<a href="https://agentmods.dev/skills/aipoch/medical-research-skills/hipaa-compliance-auditor"><img src="https://agentmods.dev/badge/skills/aipoch/medical-research-skills/hipaa-compliance-auditor/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for hipaa-compliance-auditor

Your own site · 80×15
<a href="https://agentmods.dev/skills/aipoch/medical-research-skills/hipaa-compliance-auditor"><img src="https://agentmods.dev/badge/skills/aipoch/medical-research-skills/hipaa-compliance-auditor.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 58 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,689 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe. Third-party audits
  • NVIDIA SkillSpector pass 7 Sept 2026
How audits are shown
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00058 $0.02689
Opus 5 $0.00029 $0.01345
Sonnet 5 $0.00012 $0.00538
Haiku 4.5 $0.00006 $0.00269

Measured 9d ago against content hash 243ce6e64bb3, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

hipaa-compliance-auditor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.

The scan reads SKILL.md. This mod also ships 1 executable file (scripts/main.py), listed below but not scanned — reading those needs a real analyzer, not pattern matching.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

scientific-skills/Academic Writing/hipaa-compliance-auditor/SKILL.md · 312 lines

How it starts

The opening of the file, as written. The whole thing — 312 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Source: https://github.com/aipoch/medical-research-skills

HIPAA Compliance Auditor

A clinical-grade PII/PHI detection and de-identification tool for healthcare text data.

Quick Check

Use this command to verify that the packaged script entry point can be parsed before deeper execution.

python -m py_compile scripts/main.py

Audit-Ready Commands

Use these concrete commands for validation. They are intentionally self-contained and avoid placeholder paths.

python -m py_compile scripts/main.py
python scripts/main.py --help
python scripts/main.py --text "Audit validation sample with explicit methods, findings, and conclusion."

When to Use

  • Use this skill when the task needs A clinical-grade PII/PHI detection and de-identification tool for healthcare text data.
  • Use this skill for academic writing tasks that require explicit assumptions, bounded scope, and a reproducible output format.
  • Use this skill when you need a documented fallback path for missing inputs, execution errors, or partial evidence.

When NOT to Use

  • Do NOT use for DICOM image de-identification (use dicom-anonymizer skill)
  • Do NOT use for general data anonymization of structured databases (use dedicated tools)
  • Do NOT use as a legal compliance certification — this tool assists but does NOT replace human HIPAA review

Workflow

Step 1: Provide Input Text

Provide clinical text in one of two ways:

  • File input: python scripts/main.py --input patient_text.txt --output deidentified.txt
  • Direct text: python scripts/main.py --text "Patient John Doe, SSN 123-45-6789..." --audit-log audit.json

If neither input provided: Request the text or file path from the user. Do not proceed without input.

Step 2: Configure Detection Parameters

  • --confidence 0.7 (default): Minimum confidence threshold (0.0-1.0). Lower = more detections but more false positives.
  • --preserve-structure true (default): Maintain document formatting after redaction
  • --custom-patterns <path>: Optional custom regex patterns JSON for institution-specific identifiers

Read the full file on GitHub · 312 lines

Files

What ships with it

6 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 9d ago First seen · 312 lines · 58 tokens per session scan A 243ce6e64bb3

Subscribe to this mod's changes

hipaa-compliance-auditor is a skill published in the GitHub repository aipoch/medical-research-skills (1,860 stars, last pushed 1mo ago), licensed MIT. It adds 58 tokens to every session and 2,689 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.

Related

Other skills, from other repositories

network-regulatory

Network and regulatory analysis including co-expression networks, GRN inference, PPI analysis, and TF activity scoring.

inflexa-ai/inflexa · 25 tokens

analytical-method-validation

Plan, execute, and document validation, verification, and transfer of analytical procedures under the governing framework - ICH Q2(R2) and Q14, USP / / , ICH M10 bioanalytical, CLSI EP, or ISO/IEC 17025. Use for HPLC, LC-MS/MS, GC, CE, ICP-MS, dissolution, qNMR, qPCR, NIR, and ligand binding or cell-based assays…

K-Dense-AI/scientific-agent-skills · 281 tokens

scanpy

Standard single-cell RNA-seq analysis pipeline. Use for QC, normalization, dimensionality reduction (PCA/UMAP/t-SNE), clustering, differential expression, and visualization. Best for exploratory scRNA-seq analysis with established workflows. For deep learning models use scvi-tools; for data format questions use…

synthetic-sciences/openscience · 68 tokens

patsnap-ip-searching

Patsnap Patent Research MCP for AI agents. Performs novelty searches, invention freedom-to-operate reviews, and design-patent FTO reviews from technical text, claims, disclosures, or product images. Use for defined novelty and infringement-risk research workflows, including asynchronous task retrieval; do not use it…

patsnap/mcp · 74 tokens

patsnap-patent-analysis

Patsnap Patent Analysis MCP for AI agents. Aggregates and mines a patent search result into trends, distributions, rankings, cross-tabs, keyword clouds, and innovation sunbursts. Use after a patent-search tool has returned a reusable search expression; this service analyzes rather than discovers patents.

patsnap/mcp · 66 tokens

patsnap-deep-patent-mining

Patsnap Deep Patent Mining MCP for AI agents. Designed for deeper mining of technical content from patent text and classification data. It supports analysis of technology topics, the three technical elements of problem-solution-effect, strategic emerging industries, materials, application areas, and classification…

patsnap/mcp · 91 tokens