Skill

Audit HIPAA Compliance and Identify Risks

A skill auditing HIPAA Privacy and Security Rule compliance with a risk matrix, audit SQL queries, and breach classification.

Works with githubmysql

76
Spark score
out of 100
Updated 8 months ago
Version 1.0.0
Models

Add to Favorites

Why it matters

Ensure your healthcare organization adheres to HIPAA regulations by conducting comprehensive compliance audits. Identify vulnerabilities and receive actionable remediation strategies to protect sensitive patient data.

Outcomes

What it gets done

01

Assess compliance with Privacy and Security Rule requirements.

02

Perform technical security evaluations, including network and access control audits.

03

Review documentation and audit trails for completeness and adherence to standards.

04

Generate prioritized remediation plans based on risk assessment.

Install

Add it to your toolbox

Run in your project directory:

curl -fsSL https://spark.entire.vc/get/vb-hipaa-compliance-audit | bash

Overview

HIPAA Compliance Auditor

This skill audits HIPAA Privacy and Security Rule compliance against specific CFR citations, runs technical access-control audit queries, scores findings on a weighted risk methodology, and classifies breach incidents by scope. Use it when a healthcare organization needs a structured compliance audit against specific CFR citations rather than a general security review.

What it does

This skill audits HIPAA compliance - Privacy and Security Rule requirements, implementation standards, and audit methodologies for healthcare organizations, conducting thorough assessments, identifying vulnerabilities, and developing remediation strategies. Privacy Rule coverage includes PHI identification and classification, the minimum-necessary standard, individual rights (access, amendment, accounting of disclosures), Business Associate Agreement requirements, Notice of Privacy Practices adequacy, and breach notification timing (60 days to both individuals and HHS). Security Rule technical safeguards cover access control, audit logging, integrity controls for PHI in transit and at rest, authentication systems, and transmission security.

When to use - and when NOT to

Use it when a healthcare organization needs a structured compliance audit against specific CFR citations rather than a general security review. The audit checklist maps directly to regulation sections: Administrative Safeguards (45 CFR 164.308 - security officer designation, workforce training, incident procedures, contingency planning), Physical Safeguards (45 CFR 164.310 - facility access, workstation restrictions, device/media controls), and Technical Safeguards (45 CFR 164.312 - access control, audit logs, integrity, authentication, transmission security).

Inputs and outputs

Risk is scored on a four-level matrix (Critical/High/Medium/Low) mapped to remediation windows from immediate (0-30 days) to monitor-and-review (90+ days). Technical assessment includes sample network security commands (nmap port scanning, openssl s_client cipher verification, mysql SHOW GRANTS access audits) and SQL queries that flag users with PHI access more than double their department's average and check audit-trail completeness over a 6-month window. Audit trail requirements are specified precisely: mandatory fields (user ID, timestamp, action, patient identifier, source IP, application), a 6-year retention period, quarterly review frequency, and specific monitoring alerts (after-hours access, bulk data export, failed authentication, privileged account usage). Common high-risk findings named directly: stale access after role changes, missing audit logs, single-factor authentication for PHI access, outdated BAAs, and incomplete annual risk assessments - each scorable through a weighted risk-score function combining administrative/physical/technical impact with PHI-exposure, patient-volume, and breach-likelihood multipliers. Breach incidents are classified Low through Critical by scope and evidence, feeding a post-audit report structure: executive summary, detailed findings with regulatory references, a prioritized remediation plan, cost analysis, and a re-audit follow-up schedule.

Who it's for

Healthcare compliance officers and security auditors who need a HIPAA audit grounded in specific CFR citations, with a quantified risk-scoring methodology and concrete technical assessment queries - not a generic security checklist relabeled for healthcare. Ongoing compliance is tracked through five specific metrics: the percentage of workforce completing annual HIPAA training, average time to patch a security vulnerability, access-control violations per quarter, how often business-associate compliance gets reassessed, and incident response time from detection to containment.

FAQ

Common questions

Discussion

Questions & comments ยท 0

Sign In Sign in to leave a comment.