Skip to content

Add HIPAA Privacy and Part 2 scope routing fixtures#2006

Open
DENGXUELIN wants to merge 1 commit into
UnitOneAI:mainfrom
DENGXUELIN:improve/hipaa-privacy-part2-scope-fixtures-1692
Open

Add HIPAA Privacy and Part 2 scope routing fixtures#2006
DENGXUELIN wants to merge 1 commit into
UnitOneAI:mainfrom
DENGXUELIN:improve/hipaa-privacy-part2-scope-fixtures-1692

Conversation

@DENGXUELIN

Copy link
Copy Markdown

Summary

  • Adds an early HIPAA Rule Scope Routing checkpoint to keep Security Rule safeguards separate from Privacy Rule, Breach Notification, Part 2/SUD, and non-HIPAA obligations.
  • Adds report output fields and an out-of-scope follow-up table for privacy/legal handoff.
  • Adds vulnerable and benign fixtures for mixed HIPAA requests that either overstate Security Rule coverage or route Privacy/Part 2 topics before scoring.

Bounty

Addresses #1692 as an Improver contribution.

Notes

  • The reproductive health care attestation row is intentionally framed as a current legal-status check because HHS notes a June 18, 2025 court order affecting the 2024 reproductive health Privacy Rule.
  • The Part 2 row is routed out of scope for this Security Rule skill and notes HHS's 2024 final rule effective/compliance timeline for reviewer handoff.

Validation

  • git diff --cached --check
  • Markdown fence-balance check over staged .md files
  • Added-line ASCII check
  • Required marker check for HIPAA-SCOPE-01 through HIPAA-SCOPE-08
  • Sensitive/public-contact pattern scan
  • git diff --check origin/main...HEAD
  • git merge-tree --write-tree origin/main HEAD

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant