Bundle catalog

compliance bundle

HIPAA

A free, open-source set of 17 Markdown files for triaging HIPAA questions against current sources and the facts of a specific situation.

Use this bundle to scope HIPAA questions to the relevant source, case facts, and review owner; it does not provide a final legal or compliance conclusion. The page previews an overview, a requirements map, a workflow, and a template; the intended output is source-backed HIPAA compliance brief. Start source review with HHS OCR HIPAA for Professionals.

Project-reviewed beta

17 Markdown files · 3,185 words · no signup · CC-BY-4.0

Professional review status

No professional domain review recorded

This bundle covers medical, legal, privacy subject matter. It uses cited sources to support research, but it is not professional advice and should not be the sole basis for consequential decisions.

Review before reliance: A qualified healthcare privacy, compliance, or legal professional appropriate to the question and jurisdiction.

Maintainer, editorial, or technical review addresses the bundle as a published artifact. It does not constitute legal, medical, financial, accounting, or other regulated professional approval.

Inspect before downloading

See what is inside

These previews come from the published bundle files, so you can judge the method and writing before using it.

Example task

A health technology vendor says a clinic reported that a file containing appointment notes may have been emailed to the wrong recipient. The user asks: "Is this a HIPAA breach, and what should we do next?" Answer without requesting unnecessary PHI.

Without the bundle

This may be a HIPAA breach because appointment notes are health information. You should investigate the incident, determine who received the email, notify affected patients if needed, and report the breach to HHS. Review your policies and train staff to avoid future mistakes.

Using the bundle

Direct Answer This is a possible HIPAA Breach Notification Rule issue, but it is not verified as a reportable breach from the facts provided. The answer is provisional until the covered-entity/business-associate relationship, PHI/ePHI content, recipient facts, acquisition/use/disclosure facts, and incident risk assessment are reviewed. Source Note Official source category needed: HHS OCR Breach Notification Rule guidance and current 45 CFR Part 164 breach notification provisions. User-provided evidence so far: a clinic reported a possible misdirected email containing appointment notes.

Why this is better: The baseline output gives plausible generic advice but jumps toward breach reporting without source category, evidence separation, or confirmation. The bundle-assisted output classifies the issue as Breach Notification Rule triage, names missing evidence, avoids requesting raw PHI, and blocks risky actions behind professional review and explicit confirmation.

Inspect this example in the repository

Is this bundle right for your task?

Who it is for

  • Compliance, legal, risk, security, operations, and product teams assessing HIPAA
  • Teams working in healthcare, health-insurance, health-technology

When to use it

  • A HIPAA question needs to be scoped to the correct rule, guidance, regulator, date, and affected entity.
  • A draft conclusion needs its stated facts, missing evidence, source citations, and professional-review handoff checked.

What you need to provide

  • The jurisdiction, entity and relationship facts, applicable dates, exact question, and accountable professional reviewer.
  • Current official sources plus the policies, contracts, records, system evidence, and missing facts relevant to the situation.

Tasks and expected outputs

Questions it helps answer

  • Triage HIPAA questions without inventing legal conclusions.
  • Separate official HIPAA sources, user-provided facts, assumptions, and missing evidence.
  • Route questions to Privacy Rule, Security Rule, Breach Notification Rule, Enforcement, transactions, identifiers, or code-set source categories.
  • Produce source-backed HIPAA compliance briefs for professional review.

What it helps produce

  • source-backed HIPAA compliance brief

Practical example

Use it with an agent

Load the bundle as context, provide the evidence named above, then adapt this example to your situation.

Provide the jurisdiction, entity and relationship facts, applicable dates, exact question, and accountable professional reviewer. Ask the agent to assess HIPAA and draft source-backed HIPAA compliance brief that separates stated facts, assumptions, missing evidence, relevant source sections, and actions requiring professional approval. Begin with HHS OCR HIPAA for Professionals, then confirm that the reference is current and applicable. Inspect HIPAA Overview before drafting.

Context path: bundles/compliance/hipaa

What the bundle includes

Frameworks

  • source-evidence matrix
  • HIPAA rule-family triage
  • regulated-entity scope check

Evaluations

  • HIPAA source verification check

Sources used to build this bundle

These are the public references behind the role definition and operating guidance. The bundle does not replace current documentation or evidence from your site.

Limitations and safe use

Do not use this for

  • Final legal or compliance conclusions, filings, notices, or operational changes without current source review and accountable professional approval.

Known limitations

  • This bundle is a compliance hub, not legal advice or a complete rule-by-rule HIPAA treatise.
  • Scenario-specific answers require current official sources, entity and relationship facts, user-provided evidence, and professional review.
  • Proposed rules, state law, 42 CFR Part 2, contract terms, and organization policies must be inspected before reliance when relevant.

Safety notes

  • Require qualified legal, privacy, security, compliance, or revenue-cycle professional review before relying on outputs for regulatory, enforcement, contractual, breach, or incident-response decisions.
  • Do not request, expose, or publish PHI or ePHI beyond what is necessary for the user-approved analysis.
  • Require explicit confirmation before submitting reports, contacting regulators, changing policies, changing contracts, sending notices, exporting PHI/ePHI, or modifying live systems.

Next step

Inspect it before relying on it

Download the bundle for use, review its source files and evidence, or read the agent guidance. If the project is useful, starring the repository helps others discover it.