Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

Back to skills

Hipaa Release Authorization

ASecurity

Drafts HIPAA-compliant PHI release authorizations for estate-planning workflows under 45 CFR §164.508. Use when drafting release forms, healthcare POA support documents, or record-access instruments. Triggers: HIPAA release, PHI authorization, healthcare agent access, advance directive support, medical record release.

22 stars
0 votes
0 copies
0 views
Added 9/20/2026
businessgodocumentation

Works with

cli

Security Analysis

A100/100

Scanned 9/20/2026

Install to Claude Code

$npx -y skills add lev-os/agents --skill hipaa-release-authorization --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Hipaa Release Authorization?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Hipaa Release Authorization
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/lev-os-hipaa-release-authorization/badge)](https://www.skillsdirectory.com/skills/lev-os-hipaa-release-authorization)

More formats (shields.io, HTML) on the badges page.

Download Zip
Files
SKILL.md
---
name: hipaa-release-authorization
description: >-
  Drafts HIPAA-compliant PHI release authorizations for estate-planning
  workflows under 45 CFR §164.508. Use when drafting release forms,
  healthcare POA support documents, or record-access instruments. Triggers:
  HIPAA release, PHI authorization, healthcare agent access, advance
  directive support, medical record release.
---

# HIPAA Release Authorization

Generates a 45 CFR §164.508-compliant authorization permitting designated recipients to access a patient's protected health information (PHI) from covered entities, typically in an estate-planning context.

## Quick Start

Gather before drafting:

1. **Jurisdiction** — state governs signature and witness/notary formalities
2. **Patient identity** — legal name, DOB, contact details
3. **Recipients** — healthcare agent, successor agent(s), other representatives
4. **Disclosing entities** — providers, hospitals, labs, pharmacies, health plans
5. **PHI scope** — all records or limited categories
6. **Purpose and duration** — expiration date, event, or condition
7. **Representative authority** (if applicable) — POA, guardianship order, court appointment
8. **Related documents** — healthcare proxy, advance directive for terminology alignment

## Required Sections

Every authorization must include these elements per §164.508:

| Section | Key requirement |
|---|---|
| Patient identification | Name, DOB, contact |
| Authorization statement | Voluntary, specific written consent |
| Authorized recipients | Agent names, roles, relationships — no ambiguity |
| Disclosing entities | Covered entities / record holders |
| PHI scope | Explicit categories; do not mix "all records" with narrow limits |
| Purpose | Specific estate-planning healthcare decision-making purpose |
| Expiration | Explicit end date, event, or condition |
| Required notices | Re-disclosure warning, treatment non-conditioning, right to refuse |
| Revocation | How and where written revocation is sent; prospective-only effect |
| Execution block | Patient signature first, then representative if applicable |
| Witness/notary | Only where state law requires [VERIFY] |

## Draft Workflow

1. **Confirm inputs** against the Quick Start checklist; flag any gaps.
2. **Select PHI scope** — if client wants full-record access, state it unambiguously; otherwise enumerate categories. Sensitive categories (substance use, mental health, genetic, HIV/AIDS) require explicit inclusion [VERIFY].
3. **Draft the form** using this structure:
   - Title citing 45 CFR §164.508
   - Patient identification block
   - Authorization statement
   - Disclosers list
   - Recipients list (match names/roles to healthcare POA document)
   - PHI scope with checkbox-style selection
   - Purpose statement tied to healthcare directives
   - Duration clause (date, revocation, or death — whichever first)
   - Patient rights / required statements (all six §164.508 notices)
   - Execution block (patient, then representative if signing on behalf)
   - Witness/notary block if state law applies
4. **Validate** — all placeholders visible, recipients consistent across sections, terminology aligns with governing POA/directive.
5. **Add state-specific addendum** only when confirmed for target jurisdiction.

## Pitfalls

- Never authorize broader disclosure than needed unless client explicitly requests full-record access.
- Never leave recipient or discloser fields unidentified.
- Never leave representative signature fields blank without authority documentation.
- Federal law is not exclusive — state mandates may impose additional form requirements [VERIFY].
- Estate-planning variants must match healthcare POA terminology in the core delegation document [VERIFY].
- Include attorney-review language in cover memo if template is client-facing.

Attribution

lev-oslev-os
View sourceMore from lev-os →
SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Related Skills

Solution Architect

Designs system architecture, component specifications, and technical integration strategy. Use when: designing solutions, system architecture, technology stack, or integration approaches.

192 votes

Akorchak:Venture Assessment

Generate a comprehensive VC investment assessment report for a company

72 votes

Stock Analysis

Analyze stocks and cryptocurrencies using Yahoo Finance data. Supports portfolio management (create, add, remove assets), crypto analysis (Top 20 by market cap), and periodic performance reports (daily/weekly/monthly/quarterly/yearly). 8 analysis dimensions for stocks, 3 for crypto. Use for stock analysis, portfolio tracking, earnings reactions, or crypto monitoring.

6511 votes

Just Fucking Cancel

Find and cancel unwanted subscriptions by analyzing bank transactions. Detects recurring charges, calculates annual waste, and helps you cancel with direct URLs and browser automation. Use when: 'cancel subscriptions', 'audit subscriptions', 'find recurring charges', 'what am I paying for', 'save money', 'subscription cleanup', 'stop wasting money'. Supports CSV import (Apple Card, Chase, Amex, Citi, Bank of America, Capital One, Mint, Copilot) OR Plaid API for automatic transaction pull. Out...

6511 votes

Telegram Compose

Compose rich, readable Telegram messages using HTML formatting via direct Telegram API. Use when: (1) Sending any Telegram message beyond a simple one-line reply, (2) Creating structured messages with sections, lists, or status updates, (3) Need formatting unavailable via Clawdbot's Markdown conversion (underline, spoilers, expandable blockquotes, user mentions by ID), (4) Sending alerts, reports, summaries, or notifications to Telegram, (5) Want professional, scannable message formatting wit...

6511 votes
View all in business →