PHI Gate - the clinical module you are about to ship, read for patient-data exposure and clinical safety
Paste the clinical software module that touches patient data - the source, the schema and the config - and get the review before it ships. A free in-browser measurement runs first and never sends your paste: it inventories which of the eighteen HIPAA Safe Harbor identifiers (45 CFR 164.514(b)(2)) the module actually holds, traces every one that reaches a log line, a URL, an analytics vendor, an exception message, an export or a cache key - following a payload built one statement earlier, because that is how patient data really reaches a vendor - and grades each by the mitigation already present, so a value wrapped in a redaction call is a note to verify and not a critical finding. It reads your written policy prose alongside the code and marks every Security Rule safeguard present, absent, asserted-only or CONTRADICTED, handling negation per topic ("PHI is never written to logs" is an assurance; "there is no audit trail" is a gap), retention written in words ("about seven years"), and multi-vendor business-associate lines where one pending BAA in a list of three must still read as uncovered. Then four model lanes over that one paste: the patient-data exposure audit with a generated redaction denylist; the Security Rule gate with a determination and an evidence requirement per safeguard; the EMR workflow clinical-safety review, ordered by what blocks release; and the decision-support alert review, including what a missing observation does to a NEWS2 or qSOFA score. Every measured flag must be accounted for in the reply, and anything it neither raises nor explains away is shown on the page as unreviewed rather than as cleared. Not a legal opinion, not a HIPAA certification, and not a substitute for the risk analysis required by 45 CFR 164.308(a)(1). Derived from four published agent skills: @affaan-m/healthcare-phi-compliance, @affaan-m/hipaa-compliance, @affaan-m/healthcare-emr-patterns and @affaan-m/healthcare-cdss-patterns. A derived work, not affiliated with their author.
Details
gpt-terra Every public app is built from a security-scanned skill and must pass a clean scan — skill and frontend — before it can be listed. Have a skill of your own? Turn it into an app — or read the step-by-step walkthrough.