openevidence-security-basics
Implementation guide for HIPAA-compliant handling of OpenEvidence API keys and patient data.
Install
mkdir -p .claude/skills/openevidence-security-basics && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/8157" && unzip -o skill.zip -d .claude/skills/openevidence-security-basics && rm skill.zipInstalls to .claude/skills/openevidence-security-basics
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Security Basics for OpenEvidence.Key capabilities
- →Manage OpenEvidence API keys in secure environments
- →Verify webhook signatures using HMAC-SHA256
- →Validate clinical queries against predefined schemas
- →Redact PHI from application logs
- →Enforce TLS 1.2+ for data in transit
How it works
The skill enforces security by providing code patterns for API key management, webhook verification, and field-level PHI redaction. It mandates the use of HIPAA-compliant secrets managers and TLS encryption for all clinical data.
Inputs & outputs
When to use openevidence-security-basics
- →Implement HIPAA-compliant API security
- →Secure webhook communication
- →Configure environment variables for secrets
- →Audit access logs for clinical data
About this skill
OpenEvidence Security Basics
Overview
OpenEvidence provides AI-powered clinical evidence synthesis that processes protected health information (PHI), patient queries, and medical literature references. Integrations must comply with HIPAA requirements for PHI handling, audit logging, and access controls. A breach exposes patient health questions, clinical recommendations, and potentially identifiable medical conditions. Every API interaction must be treated as a HIPAA-regulated transaction.
API Key Management
function createOpenEvidenceClient(): { apiKey: string; baseUrl: string } {
const apiKey = process.env.OPENEVIDENCE_API_KEY;
if (!apiKey) {
throw new Error("Missing OPENEVIDENCE_API_KEY — store in HIPAA-compliant secrets manager");
}
// PHI-adjacent access — enforce audit logging on every request
console.log("OpenEvidence client initialized (key suffix:", apiKey.slice(-4), ")");
return { apiKey, baseUrl: "https://api.openevidence.com/v1" };
}
Webhook Signature Verification
import crypto from "crypto";
import { Request, Response, NextFunction } from "express";
function verifyOpenEvidenceWebhook(req: Request, res: Response, next: NextFunction): void {
const signature = req.headers["x-openevidence-signature"] as string;
const secret = process.env.OPENEVIDENCE_WEBHOOK_SECRET!;
const expected = crypto.createHmac("sha256", secret).update(req.body).digest("hex");
if (!signature || !crypto.timingSafeEqual(Buffer.from(signature), Buffer.from(expected))) {
res.status(401).send("Invalid signature");
return;
}
next();
}
Input Validation
import { z } from "zod";
const ClinicalQuerySchema = z.object({
query_id: z.string().uuid(),
clinical_question: z.string().min(10).max(2000),
specialty: z.enum(["oncology", "cardiology", "neurology", "general", "pediatrics", "emergency"]).optional(),
evidence_level: z.enum(["systematic_review", "rct", "cohort", "case_report", "expert_opinion"]).optional(),
include_guidelines: z.boolean().default(true),
});
function validateClinicalQuery(data: unknown) {
return ClinicalQuerySchema.parse(data);
}
Data Protection
const OPENEVIDENCE_PHI_FIELDS = ["patient_name", "date_of_birth", "mrn", "clinical_question", "diagnosis", "medication_list"];
function redactOpenEvidenceLog(record: Record<string, unknown>): Record<string, unknown> {
const redacted = { ...record };
for (const field of OPENEVIDENCE_PHI_FIELDS) {
if (field in redacted) redacted[field] = "[REDACTED_PHI]";
}
return redacted;
}
Security Checklist
- API keys stored in HIPAA-compliant secrets manager
- Separate keys per environment (dev/staging/prod)
- Key rotation scheduled quarterly
- HIPAA audit logging enabled on every API call
- PHI never logged in application logs (field-level redaction)
- BAA (Business Associate Agreement) on file with OpenEvidence
- Clinical query data encrypted at rest and in transit (TLS 1.2+)
- Access controls enforce minimum necessary PHI exposure
Error Handling
| Vulnerability | Risk | Mitigation |
|---|---|---|
| Leaked API key | Unauthorized access to clinical evidence queries | HIPAA-compliant secrets manager + rotation |
| PHI in application logs | HIPAA violation and patient data exposure | Mandatory PHI field redaction |
| Missing BAA | Regulatory non-compliance penalty | BAA signed before integration goes live |
| Unencrypted clinical data | PHI breach during transit or storage | TLS 1.2+ in transit, AES-256 at rest |
| Missing audit trail | HIPAA audit failure | Immutable audit logs for all API interactions |
Resources
Next Steps
See openevidence-prod-checklist.
When not to use it
- →Logging PHI in application logs
- →Storing API keys without a secrets manager
Prerequisites
Limitations
- →PHI must never be logged in application logs
- →BAA must be signed before integration goes live
How it compares
This approach provides specific code-level security controls for PHI handling rather than generic API security practices.
Compared to similar skills
openevidence-security-basics side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| openevidence-security-basics (this skill) | 0 | 27d | Review | Intermediate |
| apollo-security-basics | 1 | 27d | Caution | Intermediate |
| auth-implementation-patterns | 1 | 4mo | No flags | Advanced |
| maintainx-enterprise-rbac | 1 | 27d | Review | Advanced |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by jeremylongshore
View all by jeremylongshore →You might also like
apollo-security-basics
jeremylongshore
Apply Apollo.io API security best practices. Use when securing Apollo integrations, managing API keys, or implementing secure data handling. Trigger with phrases like "apollo security", "secure apollo api", "apollo api key security", "apollo data protection".
auth-implementation-patterns
sickn33
Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems. Use when implementing auth systems, securing APIs, or debugging security issues.
maintainx-enterprise-rbac
jeremylongshore
Configure enterprise role-based access control for MaintainX integrations. Use when implementing SSO, managing organization-level permissions, or setting up enterprise access controls with MaintainX. Trigger with phrases like "maintainx rbac", "maintainx sso", "maintainx enterprise", "maintainx permissions", "maintainx roles".
juicebox-security-basics
jeremylongshore
Apply Juicebox security best practices. Use when securing API keys, implementing access controls, or auditing Juicebox integration security. Trigger with phrases like "juicebox security", "secure juicebox", "juicebox API key security", "juicebox access control".
api-security-hardening
aj-geddes
>
vercel-webhooks-events
jeremylongshore
Implement Vercel webhook signature validation and event handling. Use when setting up webhook endpoints, implementing signature verification, or handling Vercel event notifications securely. Trigger with phrases like "vercel webhook", "vercel events", "vercel webhook signature", "handle vercel events", "vercel notifications".