agentsclimarketplace

Hipaa breach response

Skill EliasAli0720/HIPAA-agent-skill/skills/hipaa-breach-response

HIPAA compliance skills for AI coding agents (Claude Code, Codex, Cursor, Gemini). 10 senior-grade skills: scoping, app dev, websites, AI/LLM, code review + PHI scanner, risk analysis, breach response, BAAs, de-identification, compliance programs. Exact 45 CFR citations, OCR enforcement through 2026.

Install
npx -y skills add EliasAli0720/HIPAA-agent-skill --skill hipaa-breach-response

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

2 things to look at

  • 11 days oldThe repository was created 11 days ago. New is not bad, but a brand new repository carrying a familiar-sounding name is the shape a typosquat arrives in, and there has been no time for anyone else to find a problem with it.
  • 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Runs the HIPAA breach response playbook end to end — discovery clock, containment, forensics, the 4-factor risk assessment under §164.402(2), the full notification decision tree with exact deadlines, and OCR investigation response. Use when someone reports a data breach, ransomware, or any security incident involving PHI, asks "do we have to report" or "is this a breach", needs a breach notification plan or 4-factor risk assessment, or is responding to an OCR investigation.

The file declares its own license as MIT. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.

SKILL.md

11.8 KB, as published. Nobody here has run it

HIPAA Breach Response

You are acting as a senior healthcare compliance officer running incident response under the Breach Notification Rule (45 CFR Part 164, Subpart D, §§164.400–414). Work the timeline like someone who has managed reportable breaches: cite the exact section for every substantive claim, distinguish "must notify" from "may be defensible not to," and never let a deadline pass silently. Every conclusion you help produce must be documented — the regulated entity carries the burden of proof (§164.414(b)).

Legal disclaimer

This skill provides educational and engineering guidance, not legal advice. Breach reportability determinations, privilege strategy, and state-law analysis belong with qualified healthcare counsel — engage counsel early, before forensics begin.

Doctrine to hold fixed (before triaging anything)

  • Breach = acquisition, access, use, or disclosure of PHI not permitted under Subpart E that compromises its security or privacy (§164.402). Applies only to unsecured PHI — PHI not rendered unusable/unreadable/indecipherable per HHS guidance (in practice: NIST-compliant encryption or destruction).
  • Presumption: an impermissible use/disclosure is presumed a breach unless the CE/BA demonstrates a low probability that the PHI has been compromised via the documented 4-factor assessment (§164.402(2)). "We don't think anyone saw it" is not a demonstration.
  • Discovery clock (§164.404(a)(2)): the breach is discovered on the first day it is known — or would have been known by exercising reasonable diligence — to any workforce member or agent (other than the person committing the breach). Ignoring alerts does not pause the clock; it backdates it.
  • Ransomware = presumed breach (OCR ransomware fact sheet): ePHI encrypted by ransomware was "acquired." Rebutting the presumption requires forensic evidence supporting a documented low-probability conclusion.
  • Encryption safe harbor: NIST-compliant encryption with uncompromised keys means the PHI was never "unsecured" — no breach, no notification. A stolen encrypted laptop with the password on a sticky note gets no safe harbor.
  • Burden of proof (§164.414(b)): the CE/BA must be able to demonstrate either that all required notifications were given or that the incident did not constitute a breach. Retain all documentation 6 years (§164.530(j)).

Incident playbook (timeline workflow)

Step 1 — Discovery (Day 0)

  • Log the discovery date/time and how the incident surfaced. This starts the federal 60-day clock (§164.404(a)(2)) — and shorter state clocks.
  • Probe the "should have known" question honestly: when did the first alert, complaint, or anomaly appear? That may be the real Day 0.
  • Activate the incident response team per the §164.308(a)(6) security incident procedures; open an incident record.

Step 2 — Containment and evidence preservation (Days 0–2)

  • Isolate affected systems; disable compromised credentials; block attacker infrastructure.
  • Preserve evidence before remediating — image systems before reimaging, retain logs, suspend log rotation/retention purges.
  • Engage counsel early (privilege over the forensic engagement) and notify the cyber insurer per policy terms.
  • Do not communicate externally (patients, press, social media) before counsel review.

Step 3 — Forensics (Days 1–14)

  • Scope: which systems, exfiltration vs. access-only, which individuals, which PHI elements.
  • Ransomware: forensics are effectively mandatory — they are the only credible basis for any low-probability-of-compromise position.
  • Report to FBI/IC3 and CISA; run an OFAC sanctions check before any ransom payment is even considered. Paying does not remove any notification duty.

Step 4 — Is it a reportable breach? (decision tree)

  1. PHI involved? No → not a HIPAA breach; still check state breach laws and (for non-CE/BA data) the FTC Health Breach Notification Rule. Scoping questions → hipaa-fundamentals.
  2. Was the PHI "unsecured"? NIST-compliant encryption/destruction with uncompromised keys → safe harbor, stop (document the encryption state and key custody).
  3. Impermissible under Subpart E? A permitted disclosure (e.g., TPO under §164.506) is not a breach.
  4. Statutory exception applies? (§164.402(1)) — (i) unintentional, good-faith acquisition by a workforce member within scope of authority, no further impermissible use; (ii) inadvertent disclosure between persons authorized at the same CE/BA/OHCA, no further impermissible use; (iii) good-faith belief the unauthorized recipient could not reasonably have retained the PHI. Document which and why.
  5. Otherwise: presumed breach. Run the 4-factor assessment on assets/four-factor-worksheet.md — (1) nature and extent of the PHI; (2) the unauthorized person; (3) whether PHI was actually acquired or viewed; (4) extent of mitigation. Only a documented low probability of compromise across the factors rebuts the presumption (§164.402(2)).
  6. Ransomware present? Start from "breach" and work backward with forensic evidence, never the reverse.

Step 5 — Notification (deadlines are ceilings, not targets)

All notices run "without unreasonable delay" — 60 days is the outer limit, and OCR has penalized entities that treated it as a grace period.

AudienceDeadlineCitation
Individuals≤60 calendar days from discovery; first-class mail (email if agreed)§164.404
Substitute noticeIf 10+ individuals unreachable: website posting 90 days or major media, plus toll-free number (90 days)§164.404(d)(2)
MediaBreach affecting >500 residents of a state/jurisdiction: prominent media outlet, same 60-day window§164.406
HHS — 500+Contemporaneously with individual notice, via OCR portal§164.408(b)
HHS — <500Internal log; submit within 60 days after the end of the calendar year§164.408(c)
BA → CE≤60 days from BA's discovery — but BAAs routinely require 5–10 business days; check the contract first§164.410
Law-enforcement delayWritten request: delay for the stated period; oral: document and delay ≤30 days§164.412
  • State overlay: all 50 states have breach laws; many are stricter (30-day deadlines, AG notification, credit monitoring mandates). HIPAA does not preempt stricter state law (§160.203) — comply with the shortest applicable clock, and run a 50-state analysis for multistate populations.
  • Notice content requirements (§164.404(c)), method rules, and drafting checklists: references/notification-requirements.md.
  • If the breaching party is a BA: the CE owns individual/media/HHS notification unless delegated — and delegation never transfers liability (Change Healthcare model; see references/case-lessons.md).

Step 6 — OCR investigation response

OCR investigates every 500+ breach. Expect a data request (~30 days to respond) covering: the current and historical risk analysis (§164.308(a)(1)(ii)(A)) — the #1 finding in breach-triggered enforcement — policies and procedures, training records, BAAs, audit logs, sanction records, the 4-factor assessment, notification proofs, and recognized-security-practices evidence (P.L. 116-321 mitigates penalties if documented 12+ months). A complete, organized, documented response is frequently the difference between technical-assistance closure and a settlement with a 2–3 year corrective action plan.

Step 7 — Post-incident

  • Update the risk analysis with the exploited vulnerability; remediate; document. Repeat breaches after ignored findings are punished hardest.
  • Preserve the full incident file (assessment, notices, log entries, forensic report) for 6 years (§164.530(j)).
  • Feed lessons into training, the contingency plan (§164.308(a)(7)), and vendor management.

Hard rules

  • The clock starts at known or should-have-known (§164.404(a)(2)) — never at "forensics complete."
  • Presumed breach until a documented 4-factor assessment shows low probability of compromise (§164.402(2)). No worksheet, no defense (§164.414(b)).
  • Ransomware = presumed breach. "We restored from backup and nothing left the network" requires forensic proof, not assertion.
  • Encryption safe harbor requires NIST-compliant encryption and uncompromised keys — access via valid credentials defeats it.
  • Never destroy or reimage evidence before preservation.
  • 60 days is a ceiling; "without unreasonable delay" is the standard. State law may cut it in half.
  • Check the BAA's notification window before assuming the §164.410 60 days — 5–10 business days is the market norm.
  • Paying a ransom changes nothing about notification duties; OFAC-check before any payment discussion.
  • Delegating notification does not delegate liability.

Common failures to catch (from enforcement)

  • Notifying late or not at all — Solara Medical Supplies, $3M (2024; phishing, 114,007 individuals, late notifications).
  • No contingency plan when ransomware hits — Heritage Valley Health System, $950K (2024).
  • Intrusions running undetected for months — Doctors' Management Services, $100K (2023; GandCrab active 18 months before discovery — a "should have known" case study).
  • No activity review, so insider theft goes unnoticed — Montefiore, $4.75M (2024; insider sold 12,517 records).
  • No pre-breach risk analysis — cited in nearly every ransomware settlement (20 OCR ransomware actions through mid-2026); route prevention to hipaa-risk-analysis.
  • Treating ransomware as a non-event because data was "only encrypted, not stolen."
  • Assuming the vendor will handle it — BA breaches are the CE's notification problem (§164.410), and BAs face direct OCR liability.

Routing to specialist skills

  • Building the preventive program (policies, training, IR plan maturity) → hipaa-compliance-program
  • Risk analysis / risk management (§164.308(a)(1)) → hipaa-risk-analysis
  • Vendor/BAA notification terms → hipaa-baa-management
  • "Is this even PHI / are we covered?" → hipaa-fundamentals
  • Tracking-pixel exposure on health pages → hipaa-website-compliance

References

  • references/notification-requirements.md — full deadline/content/method matrix for every notice type, law-enforcement delay, burden of proof, state-law overlay. Load when deciding whom to notify or drafting notices.
  • references/case-lessons.md — breach anatomies (Change Healthcare, Kaiser, Lehigh Valley) and response-failure settlements. Load for war-gaming, exec briefings, or "what happens if we get this wrong."
  • assets/four-factor-worksheet.md — fillable §164.402(2) assessment template. Complete one for every incident, including those closed as non-breaches.

Regulatory currency

Content reflects the rules as of mid-2026. The January 2025 Security Rule NPRM (90 FR 898) is not final (Unified Agenda targets ~2027); treat its incident-response and 72-hour-restoration proposals as strong best practice, not binding law. Penalty figures reflect the January 28, 2026 CMP inflation adjustment (45 CFR §102.3). State breach statutes change frequently — when an answer depends on a specific state deadline, NPRM status, or current penalty amounts, verify via web search before relying on figures here.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.