skills/legal/hipaa-release-authorization/SKILL.md
Drafts HIPAA-compliant PHI release authorizations for estate-planning workflows under 45 CFR §164.508. Use when drafting release forms, healthcare POA support documents, or record-access instruments. Triggers: HIPAA release, PHI authorization, healthcare agent access, advance directive support, medical record release.
npx skillsauth add casemark/skills hipaa-release-authorizationInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Generates a 45 CFR §164.508-compliant authorization permitting designated recipients to access a patient's protected health information (PHI) from covered entities, typically in an estate-planning context.
Gather before drafting:
Every authorization must include these elements per §164.508:
| Section | Key requirement | |---|---| | Patient identification | Name, DOB, contact | | Authorization statement | Voluntary, specific written consent | | Authorized recipients | Agent names, roles, relationships — no ambiguity | | Disclosing entities | Covered entities / record holders | | PHI scope | Explicit categories; do not mix "all records" with narrow limits | | Purpose | Specific estate-planning healthcare decision-making purpose | | Expiration | Explicit end date, event, or condition | | Required notices | Re-disclosure warning, treatment non-conditioning, right to refuse | | Revocation | How and where written revocation is sent; prospective-only effect | | Execution block | Patient signature first, then representative if applicable | | Witness/notary | Only where state law requires [VERIFY] |
development
name: automated-contract-summary language: en description: Generates structured executive summaries of contracts using ML — captures key terms, party obligations, risk allocations, and compliance requirements in a standardized format. Optimized for high-volume review where speed and consistency matter. tags: - summarization - agreement - corporate --- # Automated Contract Summarization Produces standardized executive summaries of contracts using machine learning, capturing essential term
tools
Extracts regulatory obligations from dense regulations across jurisdictions. Breaks down multi-level regulations into clear article-level obligations, classifies applicability to a business, and prioritizes by risk level. Use when translating regulations into actionable compliance requirements.
development
Continuously monitors regulatory landscapes for changes relevant to a specific business. Ingests global regulatory updates, filters by relevance, summarizes impact, and produces an actionable change advisory. Use when tracking regulatory developments affecting a particular product or market.
testing
Compares an organization's existing compliance controls, policies, and procedures against extracted regulatory obligations to identify coverage gaps. Produces a remediation plan with prioritized actions. Use when assessing compliance maturity or preparing for regulatory audits.