Skip to content
hipaa-compliance logo

HIPAA Compliance for Recovery Coach

hipaa-compliance

Ensure HIPAA compliance when handling PHI (Protected Health Information). Use when writing code that accesses user health data, check-ins, journal entries, or any sensitive information. Activates

SKILL.md

Full skill instructions

HIPAA Compliance for Recovery Coach

This skill helps you maintain HIPAA compliance when developing features that handle Protected Health Information (PHI).

What is PHI in This Application?

Data TypePHI StatusHandling
Check-in mood/​cravingsPHIAudit all access
Journal entriesPHIAudit all access
Chat conversationsPHIAudit all access
User profile (name, email)PHIAudit modifications
Sobriety datePHIAudit access
Emergency contactsPHIAudit access
Usage analytics (aggregated)NOT PHINo audit needed
Page views (no content)NOT PHINo audit needed

Audit Logging Requirements

When to Log

Always log these operations:

  • Viewing any PHI (check-ins, journal, messages)
  • Creating/​updating/​deleting PHI
  • Exporting user data
  • Admin access to user information
  • Failed authentication attempts
  • Security events (rate limiting, unauthorized access)

How to Log

Use the audit logging utilities in src/​lib/​hipaa/​audit.ts:

import {
  logPHIAccess,
  logPHIModification,
  logSecurityEvent,
  logAdminAction
} from '@/​lib/​hipaa/​audit';

// Viewing PHI
await logPHIAccess(
  userId,
  'checkin',        // targetType
  checkinId,        // targetId
  AuditAction.PHI_VIEW
);

// Modifying PHI
await logPHIModification(
  userId,
  'journal',
  journalId,
  AuditAction.PHI_UPDATE,
  { field: 'content' }  // Never include actual content!
);

// Security event
await logSecurityEvent(
  userId,
  AuditAction.RATE_LIMIT,
  { path: '/​api/​chat', attempts: 60 }
);

// Admin action
await logAdminAction(
  adminId,
  AuditAction.ADMIN_USER_VIEW,
  'user',
  targetUserId
);

Data Sanitization

Never Log These Fields

The audit system automatically sanitizes, but be explicit:

// BAD - Contains PHI
await logPHIAccess(userId, 'journal', id, action, {
  content: journalEntry.content  // NEVER DO THIS
});

// GOOD - Only metadata
await logPHIAccess(userId, 'journal', id, action, {
  wordCount: journalEntry.content.length,
  hasAttachments: false
});

Sanitized Fields (Auto-Redacted)

  • password, token, secret, key
  • authorization, cookie, session
  • credential, content, message, notes

Session Security Requirements

From src/​lib/​auth.ts:

  • Session timeout: 15 minutes of inactivity (HIPAA requirement)
  • Max session: 8 hours absolute maximum
  • Failed login lockout: 5 attempts = 30 minute ban
  • Password requirements: 12+ chars, mixed case, numbers, special chars

Code Patterns

API Route with Audit Logging

import { getSession, requireAuth } from '@/​lib/​auth';
import { logPHIAccess } from '@/​lib/​hipaa/​audit';

export async function GET(request: Request) {
  const session = await getSession();
  if (!session) {
    return Response.json({ error: 'Unauthorized' }, { status: 401 });
  }

  // Fetch the data
  const data = await fetchUserData(session.userId);

  // Log the access
  await logPHIAccess(
    session.userId,
    'userdata',
    session.userId,
    AuditAction.PHI_VIEW
  );

  return Response.json(data);
}

Component with PHI Access

'use client';

import { useEffect } from 'react';

export function JournalViewer({ entryId }: { entryId: string }) {
  useEffect(() => {
    // Log view on mount (server-side preferred, but client backup)
    fetch('/​api/​audit/​log', {
      method: 'POST',
      body: JSON.stringify({
        action: 'PHI_VIEW',
        targetType: 'journal',
        targetId: entryId
      })
    });
  }, [entryId]);

  // ... render
}

Compliance Checklist

Before shipping any feature that touches PHI:

  • All PHI access is audit logged
  • No PHI content in logs (only IDs and metadata)
  • Data access requires authentication
  • Admin access has separate audit trail
  • Failed access attempts are logged
  • Data export includes audit entry
  • Sensitive fields are encrypted at rest
  • Session timeout is enforced

Audit Log Retention

  • Minimum: 6 years (HIPAA requirement)
  • Format: Raw logs for 1 year, compressed thereafter
  • Location: audit_log table in database
  • Export: Encrypted exports for compliance audits

Emergency Access (Break Glass)

For emergency situations, use break-glass access:

import { requestBreakGlassAccess } from '@/​lib/​hipaa/​break-glass';

// This creates enhanced audit trail
const access = await requestBreakGlassAccess(
  adminId,
  targetUserId,
  'Emergency support required - user reported crisis'
);

Break glass access:

  • Requires written justification
  • Creates permanent audit record
  • Triggers alert to compliance officer
  • Must be reviewed within 24 hours

Resources

  • HIPAA Security Rule: 45 C.F.R. § 164.312
  • Audit controls standard: 45 C.F.R. § 164.312(b)
  • Incident response plan: docs/​INCIDENT-RESPONSE-PLAN.md
  • Security documentation: docs/​SECURITY-HARDENING.md

More Security skills

supabase logo
Security

supabase

Handles the full Supabase workflow from schema changes to deployment, with built-in security guardrails that catch common traps like RLS...

2.7K 308.9K
View

Comprehensive guides and best practices for Neon Serverless Postgres, covering setup, connection methods, authentication, and platform APIs.

98 216.2K
View

Guide for setting up and using Firebase Authentication. Use this skill when the user's app requires user sign-in, user management, or secure data access using auth rules.

462 163.8K
View

A skill to evaluate how secure Firestore security rules are. Use this when Firestore security rules are updated to ensure that the generated rules are extremely secure and robust.

462 127.7K
View

Official skill for integrating Firebase AI Logic (Gemini API) into web applications. Covers setup, multimodal inference, structured output, and security.

462 125.1K
View

Complete Better Auth server and client setup with database adapters, session management, plugins, and security configuration.

222 118.2K
View

Deploy and manage projects on Vercel using token-based authentication. Use when working with Vercel CLI using access tokens rather than interactive login — e.g. "deploy to vercel", "set up vercel", "add environment variables to vercel".

31.9K 116.1K
View
cloudflare logo
Security

cloudflare

Complete Cloudflare platform integration with decision trees for compute, storage, AI, networking, security, and infrastructure-as-code.

3K 110.7K
View

Run Azure compliance and security audits with azqr plus Key Vault expiration checks. Covers best-practice assessment, resource review, policy/compliance validation, and security posture checks. WHEN: compliance scan, security audit, BEFORE running azqr (compliance cli tool), Azure best practices, Key Vault expiration check, expired certificates, expiring secrets, orphaned resources, compliance assessment.

253 103K
View
gws-gmail logo
Security

gws-gmail

Send, read, and manage Gmail messages, drafts, labels, and account settings.

31.2K 78.9K
View

Comprehensive website auditing across 230+ rules in 21 categories including SEO, performance, security, and accessibility.

94 72.3K
View
gws-shared logo
Security

gws-shared

Shared authentication, CLI syntax, and output formatting patterns for gws Google Workspace commands.

31.2K 63.4K
View

Security AI tools

StarByFace logo
Security

StarByFace

Discover your celebrity doppelgänger with StarByFace!

Free
View
GeoSpy logo
Security

GeoSpy

GeoSpy: Pricing, Features, FAQs, and Alternatives for AI Teams

Free
View

Detect AI-generated voices to protect against audio fraud.

Paid
View

Ensure Your Content's Originality with AI Plagiarism Checker

Freemium
View
Img Upscaler logo
Security

Img Upscaler

Upscale images by 400% without quality loss

Freemium
View
AICheatCheck logo
Security

AICheatCheck

Accurately Detect AI-Generated Content with TheChecker.AI

Free
View
D
Security

Detect GPT

Chrome extension that detects and flags AI-generated content

Free
View