openevidence-security-basics
Implementation guide for HIPAA-compliant handling of OpenEvidence API keys and patient data.
Install
mkdir -p .claude/skills/openevidence-security-basics && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/8157" && unzip -o skill.zip -d .claude/skills/openevidence-security-basics && rm skill.zipInstalls to .claude/skills/openevidence-security-basics
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Security Basics for OpenEvidence.Key capabilities
- →Manage OpenEvidence API keys in secure environments
- →Verify webhook signatures using HMAC-SHA256
- →Validate clinical queries against predefined schemas
- →Redact PHI from application logs
- →Enforce TLS 1.2+ for data in transit
How it works
The skill enforces security by providing code patterns for API key management, webhook verification, and field-level PHI redaction. It mandates the use of HIPAA-compliant secrets managers and TLS encryption for all clinical data.
Inputs & outputs
When to use openevidence-security-basics
- →Implement HIPAA-compliant API security
- →Secure webhook communication
- →Configure environment variables for secrets
- →Audit access logs for clinical data
About this skill
OpenEvidence Security and Contract Due Diligence
Overview
Separate public vendor assertions from the controls and commitments actually governing the institution’s use. Keep inputs minimal, separate observed facts from assumptions, and leave consequential decisions with the named accountable owner.
Prerequisites
- A clearly bounded workflow, accountable clinical owner, and organizational policy
- Current first-party OpenEvidence documentation and applicable institution agreements
- Synthetic or properly authorized minimum-necessary data
Tool Discipline
Use Read, Glob, and Grep to inspect supplied policies, plans, and evidence. Use WebFetch only for current first-party OpenEvidence documentation. Use Write or Edit only when the user requests a named deliverable with an approved destination. Never expose credentials, PHI, recordings, or unrestricted environment output.
Current Contract
- The public security page states HIPAA handling, SOC 2 Type II, encryption in transit and at rest, annual penetration testing, and a disclosure contact.
- The Trust Center provides current security-program evidence, while access to detailed artifacts may be controlled.
- Institution commitments are governed by applicable MSA, BAA, SLA, and other written agreements.
Authentication
Use only the official OpenEvidence web/mobile sign-in or an institution-approved access path. Do not invent API keys, OAuth clients, SDK credentials, service accounts, or private endpoints. Never ask a user to reveal a password, session token, cookie, or recovery code.
Instructions
- Scope workflow, users, data classes, recording, communications, devices, exports, and downstream systems.
- Collect the dated security page, Trust Center evidence, terms/privacy, and current institution agreements.
- Map vendor claims and contract commitments separately to required controls; mark absent evidence unknown.
- Review identity lifecycle, minimum necessary data, encryption boundaries, retention/deletion, subprocessors, incident notice, availability, and exit.
- Route gaps to security, privacy, legal, clinical, procurement, and vendor owners.
- Issue approve, conditional, or reject with evidence dates, exceptions, compensating controls, and reassessment trigger.
Approval Boundaries
Do not create or share accounts; change access, roles, agreements, consent, retention, or security settings; enter PHI; record a conversation; copy content into another system; contact a patient; make a diagnosis or treatment decision; submit billing; transmit a support packet; run a production pilot; or represent vendor capabilities without explicit approval from the accountable owner. A qualified professional remains responsible for clinical decisions.
Output
Return scope, current first-party evidence and date, data classification, workflow or findings, citations reviewed, assumptions rejected, clinical and governance owners, approval state, unresolved risk, and the exact next action. Redact patient and credential data.
Error Handling
| Condition | Response |
|---|---|
| Public claim lacks artifact | Treat it as a vendor assertion, not independently verified control. |
| Contract conflicts with webpage | Escalate to legal/procurement; do not choose silently. |
| Vulnerability discovered | Use responsible disclosure and the organization’s incident process. |
Examples
This compact example shows the minimum reviewable handoff; adapt fields to the approved workflow without adding sensitive data.
Input:
workflow=Visits with PHI; evidence=security-page+BAA; artifacts=Trust-Center
Expected handoff:
decision=conditional; verified-claims=5; contract-gaps=2; owners=assigned
Resources
When not to use it
- →Logging PHI in application logs
- →Storing API keys without a secrets manager
Prerequisites
Limitations
- →PHI must never be logged in application logs
- →BAA must be signed before integration goes live
How it compares
This approach provides specific code-level security controls for PHI handling rather than generic API security practices.
Compared to similar skills
openevidence-security-basics side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| openevidence-security-basics (this skill) | 0 | 2mo | Review | Intermediate |
| apollo-security-basics | 1 | 2mo | Caution | Intermediate |
| auth-implementation-patterns | 1 | 5mo | No flags | Advanced |
| maintainx-enterprise-rbac | 1 | 2mo | Review | Advanced |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by jeremylongshore
View all by jeremylongshore →You might also like
apollo-security-basics
jeremylongshore
Apply Apollo.io API security best practices. Use when securing Apollo integrations, managing API keys, or implementing secure data handling. Trigger with phrases like "apollo security", "secure apollo api", "apollo api key security", "apollo data protection".
auth-implementation-patterns
sickn33
Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems. Use when implementing auth systems, securing APIs, or debugging security issues.
maintainx-enterprise-rbac
jeremylongshore
Configure enterprise role-based access control for MaintainX integrations. Use when implementing SSO, managing organization-level permissions, or setting up enterprise access controls with MaintainX. Trigger with phrases like "maintainx rbac", "maintainx sso", "maintainx enterprise", "maintainx permissions", "maintainx roles".
juicebox-security-basics
jeremylongshore
Apply Juicebox security best practices. Use when securing API keys, implementing access controls, or auditing Juicebox integration security. Trigger with phrases like "juicebox security", "secure juicebox", "juicebox API key security", "juicebox access control".
api-security-hardening
aj-geddes
>
vercel-webhooks-events
jeremylongshore
Implement Vercel webhook signature validation and event handling. Use when setting up webhook endpoints, implementing signature verification, or handling Vercel event notifications securely. Trigger with phrases like "vercel webhook", "vercel events", "vercel webhook signature", "handle vercel events", "vercel notifications".