Professional review status
No professional domain review recorded
This bundle covers medical, legal, privacy subject matter. It uses cited sources to support research, but it is not professional advice and should not be the sole basis for consequential decisions.
Review before reliance: A qualified healthcare privacy, compliance, or legal professional appropriate to the question and jurisdiction.
Maintainer, editorial, or technical review addresses the bundle as a published artifact. It does not constitute legal, medical, financial, accounting, or other regulated professional approval.
Inspect before downloading
See what is inside
These previews come from the published bundle files, so you can judge the method and writing before using it.
Example task
A health technology vendor says a clinic reported that a file containing appointment notes may have been emailed to the wrong recipient. The user asks: "Is this a HIPAA breach, and what should we do next?" Answer without requesting unnecessary PHI.
Without the bundle
This may be a HIPAA breach because appointment notes are health information. You should investigate the incident, determine who received the email, notify affected patients if needed, and report the breach to HHS. Review your policies and train staff to avoid future mistakes.
Using the bundle
Direct Answer This is a possible HIPAA Breach Notification Rule issue, but it is not verified as a reportable breach from the facts provided. The answer is provisional until the covered-entity/business-associate relationship, PHI/ePHI content, recipient facts, acquisition/use/disclosure facts, and incident risk assessment are reviewed. Source Note Official source category needed: HHS OCR Breach Notification Rule guidance and current 45 CFR Part 164 breach notification provisions. User-provided evidence so far: a clinic reported a possible misdirected email containing appointment notes.
Why this is better: The baseline output gives plausible generic advice but jumps toward breach reporting without source category, evidence separation, or confirmation. The bundle-assisted output classifies the issue as Breach Notification Rule triage, names missing evidence, avoids requesting raw PHI, and blocks risky actions behind professional review and explicit confirmation.
Inspect this example in the repositoryOverview
HIPAA Overview
Defines the source scope, applicability framing, and safety boundaries for HIPAA compliance work.
Read the fileRequirements map
HIPAA Rule-Family Map
source-backed map for routing HIPAA questions to the right official source category.
Read the fileWorkflow
HIPAA Obligation Triage
source-backed workflow for turning a HIPAA question into an evidence-backed compliance brief.
Read the fileTemplate
source-backed HIPAA Compliance Brief
Output format for HIPAA answers that must separate official sources, user evidence, assumptions, and missing verification.
Read the fileIs this bundle right for your task?
Who it is for
- Compliance, legal, risk, security, operations, and product teams assessing HIPAA
- Teams working in healthcare, health-insurance, health-technology
When to use it
- A HIPAA question needs to be scoped to the correct rule, guidance, regulator, date, and affected entity.
- A draft conclusion needs its stated facts, missing evidence, source citations, and professional-review handoff checked.
What you need to provide
- The jurisdiction, entity and relationship facts, applicable dates, exact question, and accountable professional reviewer.
- Current official sources plus the policies, contracts, records, system evidence, and missing facts relevant to the situation.
Tasks and expected outputs
Questions it helps answer
- Triage HIPAA questions without inventing legal conclusions.
- Separate official HIPAA sources, user-provided facts, assumptions, and missing evidence.
- Route questions to Privacy Rule, Security Rule, Breach Notification Rule, Enforcement, transactions, identifiers, or code-set source categories.
- Produce source-backed HIPAA compliance briefs for professional review.
What it helps produce
- source-backed HIPAA compliance brief
Practical example
Use it with an agent
Load the bundle as context, provide the evidence named above, then adapt this example to your situation.
Provide the jurisdiction, entity and relationship facts, applicable dates, exact question, and accountable professional reviewer. Ask the agent to assess HIPAA and draft source-backed HIPAA compliance brief that separates stated facts, assumptions, missing evidence, relevant source sections, and actions requiring professional approval. Begin with HHS OCR HIPAA for Professionals, then confirm that the reference is current and applicable. Inspect HIPAA Overview before drafting.
Context path: bundles/compliance/hipaa
What the bundle includes
Frameworks
- source-evidence matrix
- HIPAA rule-family triage
- regulated-entity scope check
Evaluations
- HIPAA source verification check
Sources used to build this bundle
These are the public references behind the role definition and operating guidance. The bundle does not replace current documentation or evidence from your site.
Limitations and safe use
Do not use this for
- Final legal or compliance conclusions, filings, notices, or operational changes without current source review and accountable professional approval.
Known limitations
- This bundle is a compliance hub, not legal advice or a complete rule-by-rule HIPAA treatise.
- Scenario-specific answers require current official sources, entity and relationship facts, user-provided evidence, and professional review.
- Proposed rules, state law, 42 CFR Part 2, contract terms, and organization policies must be inspected before reliance when relevant.
Safety notes
- Require qualified legal, privacy, security, compliance, or revenue-cycle professional review before relying on outputs for regulatory, enforcement, contractual, breach, or incident-response decisions.
- Do not request, expose, or publish PHI or ePHI beyond what is necessary for the user-approved analysis.
- Require explicit confirmation before submitting reports, contacting regulators, changing policies, changing contracts, sending notices, exporting PHI/ePHI, or modifying live systems.