healthcare-eval-harness
affaan-m/ecc
Patient safety verification harness for healthcare deployments with automated CDSS, PHI, and data integrity testing.
What is healthcare-eval-harness?
Automated test suite that validates clinical decision support accuracy, protected health information exposure, and data integrity before healthcare application deployments. Blocks deployments on critical safety failures (100% pass required) and warns on workflow/integration issues (95%+ pass required).
- Runs five test categories: CDSS Accuracy, PHI Exposure, Data Integrity (critical gates), and Clinical Workflow, Integration Compliance (high gates)
- Enforces 100% pass rate on critical safety tests with --bail to stop on first failure
- Validates drug interaction logic, dose validation, clinical scoring against published specifications
- Tests for PHI leaks in API responses, console output, URL parameters, browser storage, and cross-facility isolation
- Checks data integrity: locked encounters, audit trails, cascade delete protection, concurrent edit handling
- Verifies clinical workflows: encounter lifecycle, template rendering, medication sets, prescription generation
How to install healthcare-eval-harness
npx skills add null --skill healthcare-eval-harness- Node.js 20+ and npm installed
- Jest test runner (or equivalent framework: Vitest, pytest, PHPUnit)
- Existing test suites organized in tests/cdss, tests/security/phi, tests/data-integrity, tests/clinical, tests/integration directories
- CI/CD pipeline (GitHub Actions example provided; adaptable to other systems)
How to use healthcare-eval-harness
- 1.Install the skill via npx skills add null --skill healthcare-eval-harness
- 2.Organize your test files into five directories: tests/cdss, tests/security/phi, tests/data-integrity, tests/clinical, tests/integration
- 3.Run critical gates locally: npx jest --testPathPattern='tests/cdss' --bail --ci --coverage && npx jest --testPathPattern='tests/security/phi' --bail --ci && npx jest --testPathPattern='tests/data-integrity' --bail --ci
- 4.Integrate the provided GitHub Actions workflow into your CI/CD pipeline to enforce safety gates on every push and pull request
- 5.Monitor the eval report output; deployment is blocked if any critical gate fails (CDSS, PHI, Data Integrity) or if high gates fall below 95% pass rate
Use cases
- Before deploying any EMR/EHR application to production
- After modifying clinical decision support logic or dose validation rules
- After changing database schemas affecting patient data
- After updating authentication or access control systems
- During CI/CD pipeline configuration for healthcare applications
- Healthcare software engineers and DevOps teams
- Clinical informatics teams deploying CDSS systems
- Healthcare IT compliance and quality assurance roles
- Organizations managing EMR/EHR applications
- Teams responsible for patient data security and integrity
healthcare-eval-harness FAQ
Deployment is blocked immediately. Critical gates (CDSS Accuracy, PHI Exposure, Data Integrity) require 100% pass rate with no exceptions. A single failure stops the pipeline.
No. The 100% threshold for critical gates is non-negotiable for patient safety. Skipping tests or lowering thresholds is an anti-pattern that compromises clinical safety.
Start with the three critical gates (CDSS, PHI, Data Integrity) and add Clinical Workflow and Integration tests incrementally. The harness will report missing test directories.
Yes. The test categories and pass thresholds are framework-agnostic. Adapt the commands for Vitest, pytest, PHPUnit, or your framework of choice.
PASS means all critical gates passed at 100% and high gates passed at 95%+. WARN means high gates are below 95% but can proceed with review. FAIL means a critical gate failed and deployment is blocked.
Full instructions (SKILL.md)
Source of truth, from affaan-m/ecc.
name: healthcare-eval-harness description: Patient safety evaluation harness for healthcare application deployments. Automated test suites for CDSS accuracy, PHI exposure, clinical workflow integrity, and integration compliance. Blocks deployments on safety failures. metadata: origin: Health1 Super Speciality Hospitals — contributed by Dr. Keyur Patel version: "1.0.0"
Healthcare Eval Harness — Patient Safety Verification
Automated verification system for healthcare application deployments. A single CRITICAL failure blocks deployment. Patient safety is non-negotiable.
Note: Examples use Jest as the reference test runner. Adapt commands for your framework (Vitest, pytest, PHPUnit, etc.) — the test categories and pass thresholds are framework-agnostic.
When to Use
- Before any deployment of EMR/EHR applications
- After modifying CDSS logic (drug interactions, dose validation, scoring)
- After changing database schemas that touch patient data
- After modifying authentication or access control
- During CI/CD pipeline configuration for healthcare apps
- After resolving merge conflicts in clinical modules
How It Works
The eval harness runs five test categories in order. The first three (CDSS Accuracy, PHI Exposure, Data Integrity) are CRITICAL gates requiring 100% pass rate — a single failure blocks deployment. The remaining two (Clinical Workflow, Integration) are HIGH gates requiring 95%+ pass rate.
Each category maps to a Jest test path pattern. The CI pipeline runs CRITICAL gates with --bail (stop on first failure) and enforces coverage thresholds with --coverage --coverageThreshold.
Eval Categories
1. CDSS Accuracy (CRITICAL — 100% required)
Tests all clinical decision support logic: drug interaction pairs (both directions), dose validation rules, clinical scoring vs published specs, no false negatives, no silent failures.
npx jest --testPathPattern='tests/cdss' --bail --ci --coverage
2. PHI Exposure (CRITICAL — 100% required)
Tests for protected health information leaks: API error responses, console output, URL parameters, browser storage, cross-facility isolation, unauthenticated access, service role key absence.
npx jest --testPathPattern='tests/security/phi' --bail --ci
3. Data Integrity (CRITICAL — 100% required)
Tests clinical data safety: locked encounters, audit trail entries, cascade delete protection, concurrent edit handling, no orphaned records.
npx jest --testPathPattern='tests/data-integrity' --bail --ci
4. Clinical Workflow (HIGH — 95%+ required)
Tests end-to-end flows: encounter lifecycle, template rendering, medication sets, drug/diagnosis search, prescription PDF, red flag alerts.
tmp_json=$(mktemp)
npx jest --testPathPattern='tests/clinical' --ci --json --outputFile="$tmp_json" || true
total=$(jq '.numTotalTests // 0' "$tmp_json")
passed=$(jq '.numPassedTests // 0' "$tmp_json")
if [ "$total" -eq 0 ]; then
echo "No clinical tests found" >&2
exit 1
fi
rate=$(echo "scale=2; $passed * 100 / $total" | bc)
echo "Clinical pass rate: ${rate}% ($passed/$total)"
5. Integration Compliance (HIGH — 95%+ required)
Tests external systems: HL7 message parsing (v2.x), FHIR validation, lab result mapping, malformed message handling.
tmp_json=$(mktemp)
npx jest --testPathPattern='tests/integration' --ci --json --outputFile="$tmp_json" || true
total=$(jq '.numTotalTests // 0' "$tmp_json")
passed=$(jq '.numPassedTests // 0' "$tmp_json")
if [ "$total" -eq 0 ]; then
echo "No integration tests found" >&2
exit 1
fi
rate=$(echo "scale=2; $passed * 100 / $total" | bc)
echo "Integration pass rate: ${rate}% ($passed/$total)"
Pass/Fail Matrix
| Category | Threshold | On Failure |
|---|---|---|
| CDSS Accuracy | 100% | BLOCK deployment |
| PHI Exposure | 100% | BLOCK deployment |
| Data Integrity | 100% | BLOCK deployment |
| Clinical Workflow | 95%+ | WARN, allow with review |
| Integration | 95%+ | WARN, allow with review |
CI/CD Integration
name: Healthcare Safety Gate
on: [push, pull_request]
jobs:
safety-gate:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: '20'
- run: npm ci
# CRITICAL gates — 100% required, bail on first failure
- name: CDSS Accuracy
run: npx jest --testPathPattern='tests/cdss' --bail --ci --coverage --coverageThreshold='{"global":{"branches":80,"functions":80,"lines":80}}'
- name: PHI Exposure Check
run: npx jest --testPathPattern='tests/security/phi' --bail --ci
- name: Data Integrity
run: npx jest --testPathPattern='tests/data-integrity' --bail --ci
# HIGH gates — 95%+ required, custom threshold check
# HIGH gates — 95%+ required
- name: Clinical Workflows
run: |
TMP_JSON=$(mktemp)
npx jest --testPathPattern='tests/clinical' --ci --json --outputFile="$TMP_JSON" || true
TOTAL=$(jq '.numTotalTests // 0' "$TMP_JSON")
PASSED=$(jq '.numPassedTests // 0' "$TMP_JSON")
if [ "$TOTAL" -eq 0 ]; then
echo "::error::No clinical tests found"; exit 1
fi
RATE=$(echo "scale=2; $PASSED * 100 / $TOTAL" | bc)
echo "Pass rate: ${RATE}% ($PASSED/$TOTAL)"
if (( $(echo "$RATE < 95" | bc -l) )); then
echo "::warning::Clinical pass rate ${RATE}% below 95%"
fi
- name: Integration Compliance
run: |
TMP_JSON=$(mktemp)
npx jest --testPathPattern='tests/integration' --ci --json --outputFile="$TMP_JSON" || true
TOTAL=$(jq '.numTotalTests // 0' "$TMP_JSON")
PASSED=$(jq '.numPassedTests // 0' "$TMP_JSON")
if [ "$TOTAL" -eq 0 ]; then
echo "::error::No integration tests found"; exit 1
fi
RATE=$(echo "scale=2; $PASSED * 100 / $TOTAL" | bc)
echo "Pass rate: ${RATE}% ($PASSED/$TOTAL)"
if (( $(echo "$RATE < 95" | bc -l) )); then
echo "::warning::Integration pass rate ${RATE}% below 95%"
fi
Anti-Patterns
- Skipping CDSS tests "because they passed last time"
- Setting CRITICAL thresholds below 100%
- Using
--no-bailon CRITICAL test suites - Mocking the CDSS engine in integration tests (must test real logic)
- Allowing deployments when safety gate is red
- Running tests without
--coverageon CDSS suites
Examples
Example 1: Run All Critical Gates Locally
npx jest --testPathPattern='tests/cdss' --bail --ci --coverage && \
npx jest --testPathPattern='tests/security/phi' --bail --ci && \
npx jest --testPathPattern='tests/data-integrity' --bail --ci
Example 2: Check HIGH Gate Pass Rate
tmp_json=$(mktemp)
npx jest --testPathPattern='tests/clinical' --ci --json --outputFile="$tmp_json" || true
jq '{
passed: (.numPassedTests // 0),
total: (.numTotalTests // 0),
rate: (if (.numTotalTests // 0) == 0 then 0 else ((.numPassedTests // 0) / (.numTotalTests // 1) * 100) end)
}' "$tmp_json"
# Expected: { "passed": 21, "total": 22, "rate": 95.45 }
Example 3: Eval Report
## Healthcare Eval: 2026-03-27 [commit abc1234]
### Patient Safety: PASS
| Category | Tests | Pass | Fail | Status |
|----------|-------|------|------|--------|
| CDSS Accuracy | 39 | 39 | 0 | PASS |
| PHI Exposure | 8 | 8 | 0 | PASS |
| Data Integrity | 12 | 12 | 0 | PASS |
| Clinical Workflow | 22 | 21 | 1 | 95.5% PASS |
| Integration | 6 | 6 | 0 | PASS |
### Coverage: 84% (target: 80%+)
### Verdict: SAFE TO DEPLOY
Related skills
More from affaan-m/ecc and the wider catalog.
healthcare-phi-compliance
PHI/PII compliance patterns for healthcare applications—data classification, access control, audit trails, and leak prevention.
hermes-imports
Convert Hermes workflows into sanitized, reusable ECC skills without leaking credentials or private state.
hexagonal-architecture
Design domain-centric systems with clear boundaries, dependency inversion, and testable use-case orchestration.
hipaa-compliance
HIPAA-specific entrypoint for healthcare privacy and security work.
homelab-network-readiness
Readiness checklist for homelab VLAN, DNS filtering, and VPN changes before touching router or firewall config.
homelab-network-setup
Plan scalable home and homelab networks with proper IP ranges, DHCP, DNS, and device roles.