skills/legal/hipaa-baa/SKILL.md
Drafts HIPAA/HITECH-compliant Business Associate Agreements governing PHI/ePHI handling between covered entities and business associates. Covers Privacy Rule and Security Rule obligations, breach notification, subcontractor flow-downs, individual-rights support, and state-law overlays. Use when drafting or updating a BAA, negotiating vendor PHI access, or attaching HIPAA terms to a services agreement. Trigger keywords: BAA, business associate agreement, HIPAA contract, PHI vendor agreement, HITECH breach notice.
npx skillsauth add casemark/skills hipaa-baaInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Produces a HIPAA/HITECH-compliant BAA tailored to services, PHI flow, and risk profile.
Draft sections in this order, filling placeholders from matter facts:
Include all applicable terms with statutory citations:
| Term | Source | |---|---| | Protected Health Information (PHI) | 45 CFR 160.103 [VERIFY] | | Electronic PHI (ePHI) | 45 CFR 160.103 [VERIFY] | | Breach | 45 CFR 164.402 [VERIFY] | | Security Incident | 45 CFR 164.304 [VERIFY] | | Unsecured PHI | HHS Guidance / NIST [VERIFY] | | Designated Record Set | 45 CFR 164.501 [VERIFY] | | Required by Law, Individual, Secretary, Subcontractor, Use, Disclosure | HIPAA definitions [VERIFY] |
| Topic | Drafting Requirement | |---|---| | Core permitted uses | Tie each to a service obligation; include data aggregation if applicable | | Management/admin uses | Allow only if required by law or with recipient assurances | | Required by law | Permit with notice to covered entity where allowed | | Minimum necessary | Require policies; define exceptions (treatment, disclosures to CE) | | Prohibited uses | No sale of PHI; no marketing without authorization; no psychotherapy notes unless authorized |
| Element | Requirement | |---|---| | Deadline | "Without unreasonable delay," capped in days (e.g., 10 business days) | | Discovery standard | Knowledge or would-have-known with reasonable diligence | | Content | Dates, description, PHI types, affected count, mitigation steps, contact info | | Supplemental updates | Required as new facts emerge | | Incident logs | Maintain and provide periodic summaries of non-breach incidents |
| Right | BA Obligation | |---|---| | Access | Provide Designated Record Set data within X days per 45 CFR 164.524 [VERIFY] | | Amendment | Implement amendments within X days; flow-down to subcontractors | | Accounting | Maintain disclosure logs per 45 CFR 164.528 [VERIFY] | | Restrictions / confidential comms | Implement covered entity instructions |
[VERIFY].Key changes from the original:
###: Definitions, Required Clauses, Permitted Uses, etc. are now nested under Output Structure for clear hierarchy[VERIFY] flagsdevelopment
name: automated-contract-summary language: en description: Generates structured executive summaries of contracts using ML — captures key terms, party obligations, risk allocations, and compliance requirements in a standardized format. Optimized for high-volume review where speed and consistency matter. tags: - summarization - agreement - corporate --- # Automated Contract Summarization Produces standardized executive summaries of contracts using machine learning, capturing essential term
tools
Extracts regulatory obligations from dense regulations across jurisdictions. Breaks down multi-level regulations into clear article-level obligations, classifies applicability to a business, and prioritizes by risk level. Use when translating regulations into actionable compliance requirements.
development
Continuously monitors regulatory landscapes for changes relevant to a specific business. Ingests global regulatory updates, filters by relevance, summarizes impact, and produces an actionable change advisory. Use when tracking regulatory developments affecting a particular product or market.
testing
Compares an organization's existing compliance controls, policies, and procedures against extracted regulatory obligations to identify coverage gaps. Produces a remediation plan with prioritized actions. Use when assessing compliance maturity or preparing for regulatory audits.