skills/phi-readiness-review/SKILL.md
Assess the current PHI Readiness Stage (PRS) of a workload, repository, system, or environment; determine HIPAA applicability and role; identify evidence gaps; and recommend the next actions using the PRS framework, official HHS/OCR and NIST sources, and conservative evidence caps.
npx skillsauth add nickzren/phi-readiness-stages phi-readiness-reviewInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this skill when the task is to assess a system's PRS stage, check PHI-readiness gaps, audit evidence for PHI use, or recommend the next steps to advance a workload safely.
Always read these first:
framework/assessment-rules.mdframework/assessment-evidence-handling.mdframework/applicability-role-matrix.mdframework/stage-rubric.mdframework/evidence-levels.mdframework/evidence-freshness.mdframework/minimum-artifact-matrix.mdframework/regulatory-boundaries.mdframework/output-contract.mdThen read only the references needed for the task:
skills/phi-readiness-review/references/triage.md for HIPAA applicability and roleskills/phi-readiness-review/references/checklist.md for the full review sequenceskills/phi-readiness-review/references/report-template.md for the output layoutskills/phi-readiness-review/references/action-priority.md for ordering recommendationsskills/phi-readiness-review/references/health-app-and-api-scenarios.md for consumer health apps, provider-connected apps, patient-directed API access, customer-hosted products, or unintended PHI ingressskills/phi-readiness-review/references/mobile-wearable-communications.md for push notifications, outbound communications, local device storage, lock-screen exposure, wearables, or companion-device risksmappings/hipaa-security-rule-crosswalk.md when rule-level traceability, required-versus-addressable analysis, or PRS policy labeling is neededexamples/README.md and the example assessments for calibration against common archetypescontrols/index.md and specific control files for domain-level questionscontrols/shared-responsibility.md for cloud, SaaS, customer-hosted, or inherited-control reviewscontrols/physical-safeguards.md when facilities, devices, workstations, media handling, or retained physical responsibilities are in scopereferences/source-registry.md before making claims about current HIPAA rulesskills/phi-readiness-review/references/health-app-and-api-scenarios.md.skills/phi-readiness-review/references/mobile-wearable-communications.md.framework/assessment-evidence-handling.md before requesting, copying, or quoting any evidence.framework/evidence-levels.md.framework/evidence-freshness.md.framework/minimum-artifact-matrix.md.references/source-registry.md.framework/stage-rubric.md.mappings/hipaa-security-rule-crosswalk.md when the assessment needs rule-level traceability, required-versus-addressable reasoning, or a PRS policy note.controls/shared-responsibility.md whenever controls are inherited or the deployment model changes the role analysis.controls/physical-safeguards.md whenever physical controls are direct, partially inherited, or unclear.examples/.framework/regulatory-boundaries.md.framework/output-contract.md.HIPAA compliant, HIPAA certified, or HIPAA secure as status labels.testing
Assess the current PHI Readiness Stage (PRS) of a workload, repository, system, or environment; determine HIPAA applicability and role; identify evidence gaps; and recommend next actions using official HHS/OCR and NIST sources with conservative evidence caps.
development
Maintainer-only workflow for handling GitHub Secret Scanning alerts on OpenClaw. Use when Codex needs to triage, redact, clean up, and resolve secret leakage found in issue comments, issue bodies, PR comments, or other GitHub content.
development
Maintainer workflow for OpenClaw releases, prereleases, changelog release notes, and publish validation. Use when Codex needs to prepare or verify stable or beta release steps, align version naming, assemble release notes, check release auth requirements, or validate publish-time commands and artifacts.
development
Run, watch, debug, and extend OpenClaw QA testing with qa-lab and qa-channel. Use when Codex needs to execute the repo-backed QA suite, inspect live QA artifacts, debug failing scenarios, add new QA scenarios, or explain the OpenClaw QA workflow. Prefer the live OpenAI lane with regular openai/gpt-5.4 in fast mode; do not use gpt-5.4-pro or gpt-5.4-mini unless the user explicitly overrides that policy.