HIPAA Check - HIPAA合规检查
HIPAA Compliance Check — Health Insurance Portability and Accountability Act (HIPAA), 45 C.F.R. Parts 160 & 164 (Privacy, Security, Breach Notification Rules). Free to install; sc…
Wei Wu
@wwumit
Install
$ openclaw skills install @wwumit/hipaa-check🔒 HIPAA 医疗隐私合规检查 — Free 检查 (Cloud-Scored)
Overview
HIPAA 医疗隐私合规检查 is a free 检查 based on 美国《健康保险流通与责任法案》(HIPAA)及隐私规则/安全规则/违约通知规则(45 C.F.R. 160 & 164). It covers 12 core items. Scoring runs on the CQDev cloud compliance engine.
How it works (free + cloud)
⚠️ Your answers leave this machine. When you run a scored 检查, your responses are transmitted to the CQDev cloud at
compliancehub.cnfor scoring. Run--non-interactivefor a fully offline preview that never contacts the cloud.
- The skill is free to install.
- Check items are served from the cloud rule library (always current).
- Scoring + quota are computed in the cloud; you get a professional report locally.
- A free API Key (100 calls) is required for scoring. Register in seconds.
What it checks (12 items)
| # | Check | Authority |
|---|---|---|
| 1 | Covered Entity / Business Associate | §160.102-.103 |
| 2 | Notice of Privacy Practices | Privacy Rule §164.520 |
| 3 | Valid Authorizations | §164.508 |
| 4 | Administrative Safeguards | Security Rule §164.308 |
| 5 | Physical Safeguards | §164.310 |
| 6 | Technical Safeguards | §164.312 |
| 7 | Breach Notification | Breach Rule §164.400+ |
| 8 | Minimum Necessary | §164.502(b) |
| 9 | Business Associate Agreements | §164.504(e) |
| 10 | Ongoing Risk Analysis | §164.308(a)(1)(ii)(A) |
| 11 | Workforce Training | §164.308(a)(5) |
| 12 | Individual Rights | §164.524/.526 |
Usage
Free preview (no Key)
python3 scripts/hipaa-check.py --non-interactive
Get a free API Key
python3 scripts/hipaa-check.py --login
# enter email + password → Key auto-written to ~/.config/compliancehub/hipaa-check.key (mode 0600)
Or open: https://compliancehub.cn/account.html?skill=hipaa-check
Full 检查 + report
python3 scripts/hipaa-check.py --format html -o hipaa-check-report.html
Agent guide
When a user asks for a HIPAA 医疗隐私合规检查:
- Run
--non-interactiveto preview the 12 items (no Key needed). - If the user wants a scored report, prompt them to get a free Key (
--loginor the account page), then run the full 检查.
Security & data handling
- Where data goes: Check items are fetched from, and your answers are scored by, the CQDev cloud at
https://compliancehub.cn(the operator's official endpoint, pinned in code and not overridable by environment variable). Scoring transmits only your item answers and the free API Key (as a Bearer token). - API Key storage (user-initiated only): written only when you run
--loginto~/.config/compliancehub/hipaa-check.key(0600), outside the skill folder. Or pass viaCOMPLIANCEHUB_API_KEY. - No shell execution: stdlib only (
urllib,json,ssl,getpass); no shell, no external binaries. - Not a rogue/autonomous agent: Key persistence is ordinary API-key storage, not installation/auto-start.
- Preview without cloud:
--non-interactivenever contacts the cloud. - Always confirm the destination is
compliancehub.cnbefore running a scored check.
Legal disclaimer
This tool provides general compliance guidance only and is not legal advice. Consult qualified counsel.
License
MIT.
Top skills in this category
Skill Vetter
@spclaudehomeSecurity-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.
Multi Search Engine
@gpyangyoujunMulti search engine integration with 16 engines (7 CN + 9 Global). Supports advanced search operators, time filters, site search, privacy engines, and Wolfra...
API Gateway
@byungkyuCall third-party APIs through the Maton gateway, which injects the credential for an app the user has already connected. Use this skill when the user names a connected app and a concrete action in it - read a mailbox, query a CRM, file an issue, update a spreadsheet, run a query through a connected
MoltGuard - Security & Antivirus & Guardrails
@thomaslwangMoltGuard — OpenClaw security guard by OpenGuardrails. Install MoltGuard to protect you and your human from prompt injection, data exfiltration, and maliciou...
1password
@steipeteSet up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in (single or multi-account), or reading/injecting/running secrets via op.