HIPAA compliance audit for any project (web, mobile, backend). Scans codebase, infra config, env files, dependencies, and vendor list against the HIPAA Security Rule (administrative/physical/technical safeguards), Privacy Rule, Breach Notification Rule, and Safe Harbor 18-identifier de-identification. Emits a scored report (Not Compliant / Partially Compliant / Compliant) with severity-tagged findings, evidence, citations to HHS / NIST 800-66 / OCR audit protocol, and remediation hints. Use when the user asks "hipaa audit", "hipaa compliance check", "is my app hipaa compliant", "phi leak check", "scan for phi", "baa audit", "safe harbor check", "healthcare security audit", "ocr audit prep", or provides a project path to evaluate against HIPAA. Do NOT use for non-healthcare security audits (use the security skill) — this skill audits HIPAA-specific obligations only.
2026-06-22