Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
affaan-m avatar

Healthcare Phi Compliance

  • 1.4k installs
  • 238k repo stars
  • Updated August 5, 2026
  • affaan-m/ecc

This is a copy of healthcare-phi-compliance by affaan-m - installs and ranking accrue to the original listing.

healthcare-phi-compliance is a security agent skill that applies PHI and PII protection patterns for HIPAA, DISHA, and GDPR healthcare applications for developers building features that touch patient records.

About

healthcare-phi-compliance is an affaan-m/ecc skill (version 1.0.0) contributed from healthcare practice, providing patterns to protect patient, clinician, and financial data in clinical systems. It guides access control, authentication, database schema design, API response filtering, audit trails, and logging when building features that touch patient records. The skill spans HIPAA (US), DISHA (India), and GDPR (EU) requirements alongside general healthcare data protection. Developers invoke it when designing EHR integrations, patient portals, or clinician dashboards where PHI leakage, weak authorization, or non-compliant logs create regulatory risk. Outputs include concrete schema, API, and logging patterns rather than generic security checklists.

  • Covers data classification, access control, audit trails, encryption, and common leak vectors
  • Applicable to HIPAA (US), DISHA (India), GDPR (EU), and general healthcare data protection
  • Three-layer model: classification (what is sensitive), access control (who can see it), and audit (who did see it)
  • Includes patterns for Row-Level Security in multi-tenant healthcare systems
  • Provides review checklists for data exposure vulnerabilities in clinical APIs and schemas

Healthcare Phi Compliance by the numbers

  • 1,362 all-time installs (skills.sh)
  • +86 installs in the week ending Aug 4, 2026 (Skillselion tracking)
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
npx skills add https://github.com/affaan-m/ecc --skill healthcare-phi-compliance

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs1.4k
repo stars238k
Last updatedAugust 5, 2026
Repositoryaffaan-m/ecc

How do you protect PHI in healthcare app APIs?

Apply consistent PHI/PII protection patterns when building any healthcare feature that touches patient records.

Who is it for?

Backend developers building EHR, patient portal, or clinical APIs who must implement HIPAA-aligned PHI protection in schemas, auth, and audit logs.

Skip if: Non-healthcare applications with no patient data, or teams needing only generic OWASP checks without regulatory PHI requirements.

When should I use this skill?

User builds patient records features, clinical authentication, healthcare APIs, audit trails, or mentions HIPAA, PHI, PII, DISHA, or GDPR for health data.

What you get

PHI-safe database schemas, filtered API responses, access control rules, audit trail configs, and compliant logging patterns.

  • PHI-safe schema patterns
  • API response filters
  • Audit trail configuration

By the numbers

  • Published as healthcare-phi-compliance skill version 1.0.0

Files

SKILL.mdMarkdownGitHub ↗

Healthcare PHI/PII Compliance Patterns

Patterns for protecting patient data, clinician data, and financial data in healthcare applications. Applicable to HIPAA (US), DISHA (India), GDPR (EU), and general healthcare data protection.

When to Use

  • Building any feature that touches patient records
  • Implementing access control or authentication for clinical systems
  • Designing database schemas for healthcare data
  • Building APIs that return patient or clinician data
  • Implementing audit trails or logging
  • Reviewing code for data exposure vulnerabilities
  • Setting up Row-Level Security (RLS) for multi-tenant healthcare systems

How It Works

Healthcare data protection operates on three layers: classification (what is sensitive), access control (who can see it), and audit (who did see it).

Data Classification

PHI (Protected Health Information) — any data that can identify a patient AND relates to their health: patient name, date of birth, address, phone, email, national ID numbers (SSN, Aadhaar, NHS number), medical record numbers, diagnoses, medications, lab results, imaging, insurance policy and claim details, appointment and admission records, or any combination of the above.

PII (Non-patient-sensitive data) in healthcare systems: clinician/staff personal details, doctor fee structures and payout amounts, employee salary and bank details, vendor payment information.

Access Control: Row-Level Security

ALTER TABLE patients ENABLE ROW LEVEL SECURITY;

-- Scope access by facility
CREATE POLICY "staff_read_own_facility"
  ON patients FOR SELECT TO authenticated
  USING (facility_id IN (
    SELECT facility_id FROM staff_assignments
    WHERE user_id = auth.uid() AND role IN ('doctor','nurse','lab_tech','admin')
  ));

-- Audit log: insert-only (tamper-proof)
CREATE POLICY "audit_insert_only" ON audit_log FOR INSERT
  TO authenticated WITH CHECK (user_id = auth.uid());
CREATE POLICY "audit_no_modify" ON audit_log FOR UPDATE USING (false);
CREATE POLICY "audit_no_delete" ON audit_log FOR DELETE USING (false);

Audit Trail

Every PHI access or modification must be logged:

interface AuditEntry {
  timestamp: string;
  user_id: string;
  patient_id: string;
  action: 'create' | 'read' | 'update' | 'delete' | 'print' | 'export';
  resource_type: string;
  resource_id: string;
  changes?: { before: object; after: object };
  ip_address: string;
  session_id: string;
}

Common Leak Vectors

Error messages: Never include patient-identifying data in error messages thrown to the client. Log details server-side only.

Console output: Never log full patient objects. Use opaque internal record IDs (UUIDs) — not medical record numbers, national IDs, or names.

URL parameters: Never put patient-identifying data in query strings or path segments that could appear in logs or browser history. Use opaque UUIDs only.

Browser storage: Never store PHI in localStorage or sessionStorage. Keep PHI in memory only, fetch on demand.

Service role keys: Never use the service_role key in client-side code. Always use the anon/publishable key and let RLS enforce access.

Logs and monitoring: Never log full patient records. Use opaque record IDs only (not medical record numbers). Sanitize stack traces before sending to error tracking services.

Database Schema Tagging

Mark PHI/PII columns at the schema level:

COMMENT ON COLUMN patients.name IS 'PHI: patient_name';
COMMENT ON COLUMN patients.dob IS 'PHI: date_of_birth';
COMMENT ON COLUMN patients.aadhaar IS 'PHI: national_id';
COMMENT ON COLUMN doctor_payouts.amount IS 'PII: financial';

Deployment Checklist

Before every deployment:

  • No PHI in error messages or stack traces
  • No PHI in console.log/console.error
  • No PHI in URL parameters
  • No PHI in browser storage
  • No service_role key in client code
  • RLS enabled on all PHI/PII tables
  • Audit trail for all data modifications
  • Session timeout configured
  • API authentication on all PHI endpoints
  • Cross-facility data isolation verified

Examples

Example 1: Safe vs Unsafe Error Handling

// BAD — leaks PHI in error
throw new Error(`Patient ${patient.name} not found in ${patient.facility}`);

// GOOD — generic error, details logged server-side with opaque IDs only
logger.error('Patient lookup failed', { recordId: patient.id, facilityId });
throw new Error('Record not found');

Example 2: RLS Policy for Multi-Facility Isolation

-- Doctor at Facility A cannot see Facility B patients
CREATE POLICY "facility_isolation"
  ON patients FOR SELECT TO authenticated
  USING (facility_id IN (
    SELECT facility_id FROM staff_assignments WHERE user_id = auth.uid()
  ));

-- Test: login as doctor-facility-a, query facility-b patients
-- Expected: 0 rows returned

Example 3: Safe Logging

// BAD — logs identifiable patient data
console.log('Processing patient:', patient);

// GOOD — logs only opaque internal record ID
console.log('Processing record:', patient.id);
// Note: even patient.id should be an opaque UUID, not a medical record number

Related skills

How it compares

Use healthcare-phi-compliance for regulated patient-data systems; use general appsec skills when the app has no PHI and compliance scope is limited to OWASP basics.

FAQ

Which regulations does healthcare-phi-compliance cover?

healthcare-phi-compliance addresses HIPAA for US healthcare, DISHA for India, GDPR for EU personal data, and general PHI/PII protection patterns for patient, clinician, and financial records in clinical applications.

What healthcare features trigger healthcare-phi-compliance?

healthcare-phi-compliance applies when building patient record features, clinical authentication, healthcare database schemas, APIs returning patient or clinician data, and audit or logging systems that must prove compliant access.

Securityagentsautomation

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.