agentsclimarketplace

BAAReview

Skill joseruiz1571/healthcare-privacy-grc-toolkit/skills/BAAReview

Healthcare privacy GRC toolkit — AI acceptable use, vendor risk, HIPAA risk assessment, BAA, breach response

Install
npx -y skills add joseruiz1571/healthcare-privacy-grc-toolkit --skill BAAReview

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 1 stars1 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Review and negotiate Business Associate Agreements (BAAs) for AI and healthcare technology vendors. USE WHEN review BAA, evaluate business associate agreement, negotiate BAA, check BAA for AI vendor, does this BAA cover HIPAA requirements, BAA redlines, what should be in a BAA, BAA gap analysis, sign BAA, business associate contract review, 164.504 compliance, OR user pastes a BAA or vendor agreement text for analysis.

SKILL.md

2.4 KB, as published. Nobody here has run it

BAAReview

Review vendor-provided Business Associate Agreements against HIPAA statutory requirements and AI-specific negotiation standards. Given a BAA document or vendor name, Claude identifies missing provisions, flags hard stops, produces a gap analysis, and recommends specific redlines — not a blank checklist.

Workflow Routing

WorkflowTriggerFile
Review"review BAA", "evaluate BAA", "check this agreement", "should we sign this BAA"Workflows/Review.md

Quick Reference

  • 5 review sections: Mandatory HIPAA elements, Breach notification, AI-specific provisions, Security safeguards, Termination rights
  • Hard stops: 4 conditions that block signing as-is
  • 10 AI-specific provisions that standard templates omit
  • Breach notification target: ≤30 days (statutory max is 60; push for shorter)
  • Output: Completed gap analysis + hard-stop flags + specific redline recommendations

Full checklist criteria: Checklist.md

Examples

Example 1: Review a pasted BAA

User: "Here's the BAA our AI vendor sent us, can you review it?"
-> Invokes Review workflow
-> Maps each provision against the 5-section checklist
-> Identifies gaps, missing AI-specific clauses, and hard stops
-> Produces list of specific redlines to request

Example 2: Assess a vendor's BAA posture

User: "Does Microsoft offer a compliant BAA for Azure OpenAI?"
-> Invokes Review workflow
-> Reviews known BAA terms from public knowledge
-> Identifies AI-specific provisions present and absent
-> Recommends what to verify or negotiate

Example 3: Pre-negotiation preparation

User: "We're about to negotiate a BAA with a new AI scribe vendor — what do we need?"
-> Invokes Review workflow
-> Produces a checklist of must-have and should-have provisions
-> Highlights AI-specific items to negotiate proactively
-> Notes which provisions vendors commonly resist and why

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.