hipaa-agent

AI-powered HIPAA compliance officer for healthcare practices.

Community: Submitted by a user or imported; check the owner before granting accessOnlineNo sign-inGlobalFreeRead-only

What it can do

  • Scan Practice: Trigger a fresh HIPAA compliance scan for a healthcare practice. Always dispatches a new 70+ control scan via VPS — never returns cached results. Returns a job_id for polling via get_sc
  • Batch Scan: Dispatch fresh HIPAA compliance scans for multiple practices at once. Each practice costs 150 credits. If insufficient credits for the full batch, the entire request is rejected. Max 50 pr
  • Get Scan Status: Check the status of the latest scan for a practice. Returns grade, scan date, and whether data is available. Cost: 25 credits.

What data it sees

Do you need an account

No: the server works without sign-in

AI-powered HIPAA compliance officer for healthcare practices. 73-tool scanning, SRA, BAA generation, breach monitoring, and audit trails. NPI is the universal key.

Server tool list (36)

Raw names from tools/list. Only developers need these.

scan_practiceTrigger a fresh HIPAA compliance scan for a healthcare practice. Always dispatches a new 70+ control scan via VPS — never returns cached results. Returns a job_id for polling via get_scan_status. Optionally specify notification_email to receive the PDF report when the scan completes. Cost: 150 credits.
batch_scanDispatch fresh HIPAA compliance scans for multiple practices at once. Each practice costs 150 credits. If insufficient credits for the full batch, the entire request is rejected. Max 50 practices per call.
get_scan_statusCheck the status of the latest scan for a practice. Returns grade, scan date, and whether data is available. Cost: 25 credits.
get_compliance_scoreGet the HIPAA Agent Compliance Score breakdown for a practice. Returns overall grade, numerical score, and per-category scores across 10 compliance categories. Cost: 25 credits.
get_reportGet the full compliance report for a practice including all findings, severity breakdown, grade, and HIPAA section citations. Cost: 25 credits.
get_audit_logRetrieve the SHA-256 hash chain audit trail for a practice. Returns timestamped, tamper-evident log entries for all compliance actions. Cost: 25 credits.
get_evidence_packageCompile a 10-component evidence package for auditors and insurers. Includes scan results, policy attestations, training records, BAA ledger, and audit trail. Async — returns job_id. Cost: 25 credits.
generate_baaGenerate a Business Associate Agreement for a vendor. Requires active subscription or platform/MSP key. Cost: 25 credits.
get_policiesGet HIPAA policy documents generated for a practice. Optionally email them to a recipient. Requires active subscription or platform/MSP key. Cost: 25 credits.
generate_sraInitiate a HIPAA Security Risk Assessment. Returns the first batch of questions for the respondent to answer. Requires active subscription or platform/MSP key. Cost: 500 credits.
get_breachCheck if a practice has been involved in any known HIPAA breaches reported to HHS. Matches by practice name and state. Cost: 25 credits.
get_breach_scoreCalculate a breach exposure risk score for a practice based on breach history, breached credentials, and industry benchmarks. Cost: 25 credits.
trigger_internal_scanGenerate a deploy token for the internal network scanner agent. Returns an API key and installation instructions for deploying the agent inside a practice network. Cost: 25 credits.
get_internal_scan_statusCheck the status of the internal network scan agent deployment and whether results have been received. Cost: 25 credits.
get_internal_findingsGet the latest internal network scan results including encryption status, MFA compliance, network segmentation, patch levels, and endpoint security. Cost: 25 credits.
lookup_practiceLook up a healthcare practice by NPI number. Always fetches from the NPPES registry and augments with HIPAA Agent scan data if available. Returns provider name, specialty, address, and compliance grade. Cost: 25 credits.
get_outreach_statusGet the outreach and drip campaign status for a practice. Returns email send history, drip stage, and engagement data. Cost: 25 credits.
get_practice_summaryGet a comprehensive summary of a practice combining scan results, compliance score, findings count, breach history, and internal scan status. Cost: 25 credits.
get_training_statusGet staff training completion records for a practice. Returns staff members and their training course completions including scores and dates. Cost: 25 credits.
get_vendor_baa_listGet vendor Business Associate Agreement tracking records for a practice. Returns all vendor BAAs with status, dates, and contact info. Cost: 25 credits.
log_incidentLog a HIPAA security or privacy incident for a practice. Creates an incident report with type, description, and severity. Returns the incident ID for tracking. Cost: 25 credits.
get_incidentsGet incident history for a practice. Returns all logged security and privacy incidents with status, severity, and resolution dates. Cost: 25 credits.
get_compliance_deltaGet compliance controls that changed status since a given date. Shows improved and regressed controls with before/after comparison. Cost: 25 credits.
check_vendorCheck vendor risk profile including breach history, BAA coverage, and security score. Input vendor_name or domain. Cost: 25 credits.
get_compliance_stateGet the HIPAA compliance readiness state for a practice. Tracks 13 requirements against the May 2026 deadline. Returns state (compliant/near_compliant/in_progress/early_stage/not_started), completed count, next action, and per-requirement status. Cost: 25 credits.
subscribe_webhookRegister a webhook URL to receive HIPAA compliance event notifications. Events: breach_detected, score_dropped, baa_expiring, scan_completed, control_failed, sra_expired. Payloads signed with HMAC-SHA256. Cost: 25 credits.
list_webhooksList active webhook subscriptions for a practice. Cost: 25 credits.
get_breach_probabilityCalculate breach probability for a practice. Model: HHS base rate by specialty, adjusted by security grade penalty, gap penalties (no MFA +8%, no encryption +12%, flat network +15%, no backups +10%), and prior breach history 3x multiplier. Cost: 25 credits.
validate_workflowValidate whether a data workflow is HIPAA-compliant. Synchronous guardrail — returns allowed/denied with risk score, missing controls, and HIPAA citations. No prior scan required. Zero PHI. Cost: 25 credits.
get_controlsGet HIPAA/NIST control-level assessment for a practice. Maps scan findings to 13 standardized controls with pass/fail/partial status, risk scores, and required actions. Cost: 25 credits.
execute_agent_baaExecute a digital Business Associate Agreement between two healthcare practices. Verifies both parties have passing compliance grades (C or above), creates a signed BAA with SHA-256 digital signature, and logs to the audit trail. Cost: 25 credits.
get_model_insightsGet HIPAA Agent data intelligence model stats — vulnerability patterns discovered, remediation effectiveness tracking, breach calibration coefficients, specialty benchmarks, and state coverage. Cost: 25 credits.
get_state_coverageGet scanning coverage by US state — total NPIs in registry, scanned count, average grade per state. Shows which states have been expanded and their scan progress. Cost: 25 credits.
get_threat_intelGet recent healthcare threat intelligence alerts from FBI Watchdog, HHS HC3, CISA KEV, and MS-ISAC. Returns alerts with severity, healthcare relevance scores, and source attribution. Cost: 25 credits.
get_reputationGet HIPAA Agent verified reputation stats — total scans, unique practices, documents generated, breaches tracked, uptime, and SHA-256 data integrity hash. Free, no authentication required.
get_blockchain_anchorGet the blockchain anchor proof for a specific date. Returns the SHA-256 root hash of all audit events from that date, the Base L2 transaction hash, and a Basescan verification link. Proves compliance records have not been tampered with. Free, no authentication required.
hipaa-agent: connect to Claude, ChatGPT, Cursor · Connectors.fun