PluginBench
Skill
Pass
Audit score 90

healthcare-phi-compliance

affaan-m/ecc

PHI/PII compliance patterns for healthcare applications—data classification, access control, audit trails, and leak prevention.

What is healthcare-phi-compliance?

Patterns for protecting patient and clinician data in healthcare systems under HIPAA, DISHA, GDPR, and similar regulations. Use when building patient-facing features, access controls, APIs, or audit systems to prevent data exposure through error messages, logs, URLs, and browser storage.

  • Classify Protected Health Information (PHI) and Personally Identifiable Information (PII) in healthcare schemas
  • Implement Row-Level Security (RLS) policies for multi-facility and role-based access control
  • Design tamper-proof audit trails that log all PHI access and modifications
  • Identify and block common data leak vectors: error messages, console output, URL parameters, browser storage, and logs
  • Provide deployment checklists to verify PHI protection before release

How to install healthcare-phi-compliance

npx skills add null --skill healthcare-phi-compliance
Claude Code
Cursor
Windsurf
Cline

How to use healthcare-phi-compliance

  1. 1.Classify all patient and clinician data columns using the PHI/PII definitions provided
  2. 2.Enable Row-Level Security on tables containing sensitive data and define facility or role-based access policies
  3. 3.Implement audit logging for all create, read, update, delete, print, and export actions on PHI
  4. 4.Review error handling, logging, and API responses to remove patient-identifying data
  5. 5.Audit URL parameters, browser storage, and service keys to ensure no PHI is exposed client-side
  6. 6.Run the deployment checklist before each release to verify all protections are in place

Use cases

Good for
  • Building patient record systems with facility-level isolation and role-based access
  • Implementing audit logging for compliance audits and breach investigations
  • Reviewing healthcare APIs to prevent PHI leakage in error responses and query parameters
  • Setting up multi-tenant healthcare platforms where clinicians see only their assigned facility's data
  • Designing database schemas with PHI/PII column tagging and RLS policies
Who it's for
  • Healthcare application developers
  • Backend engineers building clinical systems
  • Database architects designing healthcare schemas
  • Security reviewers auditing healthcare code
  • Compliance officers implementing HIPAA, GDPR, or DISHA requirements

healthcare-phi-compliance FAQ

What counts as PHI in healthcare systems?

PHI is any data that identifies a patient AND relates to their health: name, date of birth, address, phone, email, national ID (SSN, Aadhaar, NHS number), medical record number, diagnoses, medications, lab results, imaging, insurance details, and appointment records.

How do I prevent PHI from leaking in error messages?

Never include patient-identifying data in errors sent to the client. Log full details server-side only with opaque record IDs (UUIDs), and return generic error messages like 'Record not found' to the frontend.

What is Row-Level Security (RLS) and why is it needed?

RLS is a database-level policy that restricts which rows a user can access based on their role or facility assignment. It prevents clinicians at one facility from querying patients at another facility, even if they have database access.

Should I log full patient objects in console or error tracking?

No. Log only opaque internal record IDs (UUIDs), not medical record numbers, names, or national IDs. Sanitize stack traces before sending to error tracking services to avoid exposing PHI.

Which regulations does this pattern cover?

The patterns apply to HIPAA (US), DISHA (India), GDPR (EU), and general healthcare data protection frameworks. Adapt the specific policies to your jurisdiction's requirements.

Full instructions (SKILL.md)

Source of truth, from affaan-m/ecc.


name: healthcare-phi-compliance description: Protected Health Information (PHI) and Personally Identifiable Information (PII) compliance patterns for healthcare applications. Covers data classification, access control, audit trails, encryption, and common leak vectors. metadata: origin: Health1 Super Speciality Hospitals — contributed by Dr. Keyur Patel version: "1.0.0"

Healthcare PHI/PII Compliance Patterns

Patterns for protecting patient data, clinician data, and financial data in healthcare applications. Applicable to HIPAA (US), DISHA (India), GDPR (EU), and general healthcare data protection.

When to Use

  • Building any feature that touches patient records
  • Implementing access control or authentication for clinical systems
  • Designing database schemas for healthcare data
  • Building APIs that return patient or clinician data
  • Implementing audit trails or logging
  • Reviewing code for data exposure vulnerabilities
  • Setting up Row-Level Security (RLS) for multi-tenant healthcare systems

How It Works

Healthcare data protection operates on three layers: classification (what is sensitive), access control (who can see it), and audit (who did see it).

Data Classification

PHI (Protected Health Information) — any data that can identify a patient AND relates to their health: patient name, date of birth, address, phone, email, national ID numbers (SSN, Aadhaar, NHS number), medical record numbers, diagnoses, medications, lab results, imaging, insurance policy and claim details, appointment and admission records, or any combination of the above.

PII (Non-patient-sensitive data) in healthcare systems: clinician/staff personal details, doctor fee structures and payout amounts, employee salary and bank details, vendor payment information.

Access Control: Row-Level Security

ALTER TABLE patients ENABLE ROW LEVEL SECURITY;

-- Scope access by facility
CREATE POLICY "staff_read_own_facility"
  ON patients FOR SELECT TO authenticated
  USING (facility_id IN (
    SELECT facility_id FROM staff_assignments
    WHERE user_id = auth.uid() AND role IN ('doctor','nurse','lab_tech','admin')
  ));

-- Audit log: insert-only (tamper-proof)
CREATE POLICY "audit_insert_only" ON audit_log FOR INSERT
  TO authenticated WITH CHECK (user_id = auth.uid());
CREATE POLICY "audit_no_modify" ON audit_log FOR UPDATE USING (false);
CREATE POLICY "audit_no_delete" ON audit_log FOR DELETE USING (false);

Audit Trail

Every PHI access or modification must be logged:

interface AuditEntry {
  timestamp: string;
  user_id: string;
  patient_id: string;
  action: 'create' | 'read' | 'update' | 'delete' | 'print' | 'export';
  resource_type: string;
  resource_id: string;
  changes?: { before: object; after: object };
  ip_address: string;
  session_id: string;
}

Common Leak Vectors

Error messages: Never include patient-identifying data in error messages thrown to the client. Log details server-side only.

Console output: Never log full patient objects. Use opaque internal record IDs (UUIDs) — not medical record numbers, national IDs, or names.

URL parameters: Never put patient-identifying data in query strings or path segments that could appear in logs or browser history. Use opaque UUIDs only.

Browser storage: Never store PHI in localStorage or sessionStorage. Keep PHI in memory only, fetch on demand.

Service role keys: Never use the service_role key in client-side code. Always use the anon/publishable key and let RLS enforce access.

Logs and monitoring: Never log full patient records. Use opaque record IDs only (not medical record numbers). Sanitize stack traces before sending to error tracking services.

Database Schema Tagging

Mark PHI/PII columns at the schema level:

COMMENT ON COLUMN patients.name IS 'PHI: patient_name';
COMMENT ON COLUMN patients.dob IS 'PHI: date_of_birth';
COMMENT ON COLUMN patients.aadhaar IS 'PHI: national_id';
COMMENT ON COLUMN doctor_payouts.amount IS 'PII: financial';

Deployment Checklist

Before every deployment:

  • No PHI in error messages or stack traces
  • No PHI in console.log/console.error
  • No PHI in URL parameters
  • No PHI in browser storage
  • No service_role key in client code
  • RLS enabled on all PHI/PII tables
  • Audit trail for all data modifications
  • Session timeout configured
  • API authentication on all PHI endpoints
  • Cross-facility data isolation verified

Examples

Example 1: Safe vs Unsafe Error Handling

// BAD — leaks PHI in error
throw new Error(`Patient ${patient.name} not found in ${patient.facility}`);

// GOOD — generic error, details logged server-side with opaque IDs only
logger.error('Patient lookup failed', { recordId: patient.id, facilityId });
throw new Error('Record not found');

Example 2: RLS Policy for Multi-Facility Isolation

-- Doctor at Facility A cannot see Facility B patients
CREATE POLICY "facility_isolation"
  ON patients FOR SELECT TO authenticated
  USING (facility_id IN (
    SELECT facility_id FROM staff_assignments WHERE user_id = auth.uid()
  ));

-- Test: login as doctor-facility-a, query facility-b patients
-- Expected: 0 rows returned

Example 3: Safe Logging

// BAD — logs identifiable patient data
console.log('Processing patient:', patient);

// GOOD — logs only opaque internal record ID
console.log('Processing record:', patient.id);
// Note: even patient.id should be an opaque UUID, not a medical record number