OP

openevidence-security-basics

Implementation guide for HIPAA-compliant handling of OpenEvidence API keys and patient data.

Install

mkdir -p .claude/skills/openevidence-security-basics && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/8157" && unzip -o skill.zip -d .claude/skills/openevidence-security-basics && rm skill.zip

Installs to .claude/skills/openevidence-security-basics

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Security Basics for OpenEvidence.
33 charsno explicit “when” trigger
Intermediate

Key capabilities

  • →Manage OpenEvidence API keys in secure environments
  • →Verify webhook signatures using HMAC-SHA256
  • →Validate clinical queries against predefined schemas
  • →Redact PHI from application logs
  • →Enforce TLS 1.2+ for data in transit

How it works

The skill enforces security by providing code patterns for API key management, webhook verification, and field-level PHI redaction. It mandates the use of HIPAA-compliant secrets managers and TLS encryption for all clinical data.

Inputs & outputs

You give it
Clinical query data or webhook request
You get back
Validated query or verified webhook signature

When to use openevidence-security-basics

  • →Implement HIPAA-compliant API security
  • →Secure webhook communication
  • →Configure environment variables for secrets
  • →Audit access logs for clinical data

About this skill

OpenEvidence Security and Contract Due Diligence

Overview

Separate public vendor assertions from the controls and commitments actually governing the institution’s use. Keep inputs minimal, separate observed facts from assumptions, and leave consequential decisions with the named accountable owner.

Prerequisites

  • A clearly bounded workflow, accountable clinical owner, and organizational policy
  • Current first-party OpenEvidence documentation and applicable institution agreements
  • Synthetic or properly authorized minimum-necessary data

Tool Discipline

Use Read, Glob, and Grep to inspect supplied policies, plans, and evidence. Use WebFetch only for current first-party OpenEvidence documentation. Use Write or Edit only when the user requests a named deliverable with an approved destination. Never expose credentials, PHI, recordings, or unrestricted environment output.

Current Contract

  • The public security page states HIPAA handling, SOC 2 Type II, encryption in transit and at rest, annual penetration testing, and a disclosure contact.
  • The Trust Center provides current security-program evidence, while access to detailed artifacts may be controlled.
  • Institution commitments are governed by applicable MSA, BAA, SLA, and other written agreements.

Authentication

Use only the official OpenEvidence web/mobile sign-in or an institution-approved access path. Do not invent API keys, OAuth clients, SDK credentials, service accounts, or private endpoints. Never ask a user to reveal a password, session token, cookie, or recovery code.

Instructions

  1. Scope workflow, users, data classes, recording, communications, devices, exports, and downstream systems.
  2. Collect the dated security page, Trust Center evidence, terms/privacy, and current institution agreements.
  3. Map vendor claims and contract commitments separately to required controls; mark absent evidence unknown.
  4. Review identity lifecycle, minimum necessary data, encryption boundaries, retention/deletion, subprocessors, incident notice, availability, and exit.
  5. Route gaps to security, privacy, legal, clinical, procurement, and vendor owners.
  6. Issue approve, conditional, or reject with evidence dates, exceptions, compensating controls, and reassessment trigger.

Approval Boundaries

Do not create or share accounts; change access, roles, agreements, consent, retention, or security settings; enter PHI; record a conversation; copy content into another system; contact a patient; make a diagnosis or treatment decision; submit billing; transmit a support packet; run a production pilot; or represent vendor capabilities without explicit approval from the accountable owner. A qualified professional remains responsible for clinical decisions.

Output

Return scope, current first-party evidence and date, data classification, workflow or findings, citations reviewed, assumptions rejected, clinical and governance owners, approval state, unresolved risk, and the exact next action. Redact patient and credential data.

Error Handling

ConditionResponse
Public claim lacks artifactTreat it as a vendor assertion, not independently verified control.
Contract conflicts with webpageEscalate to legal/procurement; do not choose silently.
Vulnerability discoveredUse responsible disclosure and the organization’s incident process.

Examples

This compact example shows the minimum reviewable handoff; adapt fields to the approved workflow without adding sensitive data.

Input:

workflow=Visits with PHI; evidence=security-page+BAA; artifacts=Trust-Center

Expected handoff:

decision=conditional; verified-claims=5; contract-gaps=2; owners=assigned

Resources

When not to use it

  • →Logging PHI in application logs
  • →Storing API keys without a secrets manager

Prerequisites

Business Associate Agreement (BAA) with OpenEvidence

Limitations

  • →PHI must never be logged in application logs
  • →BAA must be signed before integration goes live

How it compares

This approach provides specific code-level security controls for PHI handling rather than generic API security practices.

Compared to similar skills

openevidence-security-basics side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
openevidence-security-basics (this skill)02moReviewIntermediate
apollo-security-basics12moCautionIntermediate
auth-implementation-patterns15moNo flagsAdvanced
maintainx-enterprise-rbac12moReviewAdvanced

Try saying

Example prompts that trigger this skill in your AI assistant.

More by jeremylongshore

View all by jeremylongshore →

analyzing-logs

jeremylongshore

Analyze application logs to detect performance issues, identify error patterns, and improve stability by extracting key insights.

14123

ollama-setup

jeremylongshore

Configure auto-configure Ollama when user needs local LLM deployment, free AI alternatives, or wants to eliminate hosted API costs. Trigger phrases: "install ollama", "local AI", "free LLM", "self-hosted AI", "replace OpenAI", "no API costs". Use when appropriate context detected. Trigger with relevant phrases based on skill purpose.

1167

backtesting-trading-strategies

jeremylongshore

Backtest crypto and traditional trading strategies against historical data. Calculates performance metrics (Sharpe, Sortino, max drawdown), generates equity curves, and optimizes strategy parameters. Use when user wants to test a trading strategy, validate signals, or compare approaches. Trigger with phrases like "backtest strategy", "test trading strategy", "historical performance", "simulate trades", "optimize parameters", or "validate signals".

1071

generating-database-seed-data

jeremylongshore

Process this skill enables AI assistant to generate realistic test data and database seed scripts for development and testing environments. it uses faker libraries to create realistic data, maintains relational integrity, and allows configurable data volumes. u... Use when working with databases or data models. Trigger with phrases like 'database', 'query', or 'schema'.

1033

cursor-codebase-indexing

jeremylongshore

Execute set up and optimize Cursor codebase indexing. Triggers on "cursor index setup", "codebase indexing", "index codebase", "cursor semantic search". Use when working with cursor codebase indexing functionality. Trigger with phrases like "cursor codebase indexing", "cursor indexing", "cursor".

885

testing-mobile-apps

jeremylongshore

Execute mobile app testing on iOS and Android devices/simulators. Use when performing specialized testing. Trigger with phrases like "test mobile app", "run iOS tests", or "validate Android functionality".

810

You might also like

apollo-security-basics

jeremylongshore

Apply Apollo.io API security best practices. Use when securing Apollo integrations, managing API keys, or implementing secure data handling. Trigger with phrases like "apollo security", "secure apollo api", "apollo api key security", "apollo data protection".

13

auth-implementation-patterns

sickn33

Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems. Use when implementing auth systems, securing APIs, or debugging security issues.

12

maintainx-enterprise-rbac

jeremylongshore

Configure enterprise role-based access control for MaintainX integrations. Use when implementing SSO, managing organization-level permissions, or setting up enterprise access controls with MaintainX. Trigger with phrases like "maintainx rbac", "maintainx sso", "maintainx enterprise", "maintainx permissions", "maintainx roles".

11

juicebox-security-basics

jeremylongshore

Apply Juicebox security best practices. Use when securing API keys, implementing access controls, or auditing Juicebox integration security. Trigger with phrases like "juicebox security", "secure juicebox", "juicebox API key security", "juicebox access control".

10

api-security-hardening

aj-geddes

>

00

vercel-webhooks-events

jeremylongshore

Implement Vercel webhook signature validation and event handling. Use when setting up webhook endpoints, implementing signature verification, or handling Vercel event notifications securely. Trigger with phrases like "vercel webhook", "vercel events", "vercel webhook signature", "handle vercel events", "vercel notifications".

325

Search skills

Search the agent skills registry