← Back to search

io.github.CSOAI-ORG/hipaa-compliance-mcp

CSOAI-ORG Scanned 23d ago

HIPAA healthcare compliance assessment tools for AI agents. Capabilities: assess safeguards,...

C
71.9 / 100

Versions

1.0.3latest
first seen Jun 5, 2026
1.0.6
first seen May 19, 2026
PermissionsTool SafetyAuthAnnotationsCode QualityStabilitySpecVuln HistoryAuthorTransparencyCommunity

Tools 7

assess_hipaa_compliance
annotations: none low

Evaluate an organization against HIPAA Administrative, Physical, and Technical safeguards. Behavior: This tool is read-only and stateless — it produces analysis output without modifying any external systems, databases, or files. Safe to call repeatedly with identical inputs (idempotent). Free tier: 10/day rate limit. Pro tier: unlimited. No authentication required for basic usage. When to use: Use this tool when you need to assess, audit, or verify compliance requirements. Ideal for gap analysis, readiness checks, and generating compliance documentation. When NOT to use: Do not use as a substitute for qualified legal counsel. This tool provides technical compliance guidance, not legal advice. Args: organization_name (str): The organization name to analyze or process. has_risk_analysis (bool): The has risk analysis to analyze or process. has_security_officer (bool): The has security officer to analyze or process. has_workforce_training (bool): The has workforce training to analyze or process. has_incident_procedures (bool): The has incident procedures to analyze or process. has_contingency_plan (bool): The has contingency plan to analyze or process. has_facility_controls (bool): The has facility controls to analyze or process. has_workstation_security (bool): The has workstation security to analyze or process. has_access_control (bool): The has access control to analyze or process. has_audit_controls (bool): The has audit controls to analyze or process. has_transmission_security (bool): The has transmission security to analyze or process. has_encryption (bool): The has encryption to analyze or process. has_authentication (bool): The has authentication to analyze or process. api_key (str): The api key to analyze or process. Behavioral Transparency: - Side Effects: This tool is read-only and produces no side effects. It does not modify any external state, databases, or files. All output is computed in-memory and returned directly to the caller. - Authentication: No authentication required for basic usage. Pro/Enterprise tiers require a valid MEOK API key passed via the MEOK_API_KEY environment variable. - Rate Limits: Free tier: 10 calls/day. Pro tier: unlimited. Rate limit headers are included in responses (X-RateLimit-Remaining, X-RateLimit-Reset). - Error Handling: Returns structured error objects with 'error' key on failure. Never raises unhandled exceptions. Invalid inputs return descriptive validation errors. - Idempotency: Fully idempotent — calling with the same inputs always produces the same output. Safe to retry on timeout or transient failure. - Data Privacy: No input data is stored, logged, or transmitted to external services. All processing happens locally within the MCP server process.

caller str api_key str has_encryption bool has_risk_analysis bool organization_name str has_access_control bool has_audit_controls bool has_authentication bool has_contingency_plan bool has_security_officer bool has_facility_controls bool has_workforce_training bool has_incident_procedures bool has_workstation_security bool has_transmission_security bool
check_phi_handling
annotations: none low

Check Protected Health Information handling compliance. Behavior: This tool is read-only and stateless — it produces analysis output without modifying any external systems, databases, or files. Safe to call repeatedly with identical inputs (idempotent). Free tier: 10/day rate limit. Pro tier: unlimited. No authentication required for basic usage. When to use: Use this tool when you need to assess, audit, or verify compliance requirements. Ideal for gap analysis, readiness checks, and generating compliance documentation. When NOT to use: Do not use as a substitute for qualified legal counsel. This tool provides technical compliance guidance, not legal advice. Args: data_description (str): The data description to analyze or process. identifiers_present (str): The identifiers present to analyze or process. storage_encrypted (bool): The storage encrypted to analyze or process. transmission_encrypted (bool): The transmission encrypted to analyze or process. access_logged (bool): The access logged to analyze or process. minimum_necessary_applied (bool): The minimum necessary applied to analyze or process. api_key (str): The api key to analyze or process. Behavioral Transparency: - Side Effects: This tool is read-only and produces no side effects. It does not modify any external state, databases, or files. All output is computed in-memory and returned directly to the caller. - Authentication: No authentication required for basic usage. Pro/Enterprise tiers require a valid MEOK API key passed via the MEOK_API_KEY environment variable. - Rate Limits: Free tier: 10 calls/day. Pro tier: unlimited. Rate limit headers are included in responses (X-RateLimit-Remaining, X-RateLimit-Reset). - Error Handling: Returns structured error objects with 'error' key on failure. Never raises unhandled exceptions. Invalid inputs return descriptive validation errors. - Idempotency: Fully idempotent — calling with the same inputs always produces the same output. Safe to retry on timeout or transient failure. - Data Privacy: No input data is stored, logged, or transmitted to external services. All processing happens locally within the MCP server process.

caller str api_key str access_logged bool data_description str storage_encrypted bool identifiers_present str transmission_encrypted bool minimum_necessary_applied bool
generate_baa
annotations: none low

Generate a Business Associate Agreement template per HIPAA requirements. Behavior: This tool generates structured output without modifying external systems. Output is deterministic for identical inputs. No side effects. Free tier: 10/day rate limit. Pro tier: unlimited. No authentication required for basic usage. When to use: Use this tool when you need to assess, audit, or verify compliance requirements. Ideal for gap analysis, readiness checks, and generating compliance documentation. When NOT to use: Do not use as a substitute for qualified legal counsel. This tool provides technical compliance guidance, not legal advice. Args: covered_entity_name (str): The covered entity name to analyze or process. business_associate_name (str): The business associate name to analyze or process. services_description (str): The services description to analyze or process. effective_date (str): The effective date to analyze or process. term_years (int): The term years to analyze or process. api_key (str): The api key to analyze or process. Behavioral Transparency: - Side Effects: This tool is read-only and produces no side effects. It does not modify any external state, databases, or files. All output is computed in-memory and returned directly to the caller. - Authentication: No authentication required for basic usage. Pro/Enterprise tiers require a valid MEOK API key passed via the MEOK_API_KEY environment variable. - Rate Limits: Free tier: 10 calls/day. Pro tier: unlimited. Rate limit headers are included in responses (X-RateLimit-Remaining, X-RateLimit-Reset). - Error Handling: Returns structured error objects with 'error' key on failure. Never raises unhandled exceptions. Invalid inputs return descriptive validation errors. - Idempotency: Fully idempotent — calling with the same inputs always produces the same output. Safe to retry on timeout or transient failure. - Data Privacy: No input data is stored, logged, or transmitted to external services. All processing happens locally within the MCP server process.

caller str api_key str term_years int effective_date str covered_entity_name str services_description str business_associate_name str
breach_notification_check
annotations: none low

Check breach notification compliance against HIPAA 45-day and 60-day rules. Behavior: This tool is read-only and stateless — it produces analysis output without modifying any external systems, databases, or files. Safe to call repeatedly with identical inputs (idempotent). Free tier: 10/day rate limit. Pro tier: unlimited. No authentication required for basic usage. When to use: Use this tool when you need to assess, audit, or verify compliance requirements. Ideal for gap analysis, readiness checks, and generating compliance documentation. When NOT to use: Do not use as a substitute for qualified legal counsel. This tool provides technical compliance guidance, not legal advice. Args: breach_date (str): The breach date to analyze or process. discovery_date (str): The discovery date to analyze or process. individuals_affected (int): The individuals affected to analyze or process. notification_sent (bool): The notification sent to analyze or process. notification_date (str): The notification date to analyze or process. involves_unsecured_phi (bool): The involves unsecured phi to analyze or process. api_key (str): The api key to analyze or process. Behavioral Transparency: - Side Effects: This tool is read-only and produces no side effects. It does not modify any external state, databases, or files. All output is computed in-memory and returned directly to the caller. - Authentication: No authentication required for basic usage. Pro/Enterprise tiers require a valid MEOK API key passed via the MEOK_API_KEY environment variable. - Rate Limits: Free tier: 10 calls/day. Pro tier: unlimited. Rate limit headers are included in responses (X-RateLimit-Remaining, X-RateLimit-Reset). - Error Handling: Returns structured error objects with 'error' key on failure. Never raises unhandled exceptions. Invalid inputs return descriptive validation errors. - Idempotency: Fully idempotent — calling with the same inputs always produces the same output. Safe to retry on timeout or transient failure. - Data Privacy: No input data is stored, logged, or transmitted to external services. All processing happens locally within the MCP server process.

caller str api_key str breach_date str discovery_date str notification_date str notification_sent bool individuals_affected int involves_unsecured_phi bool
minimum_necessary_check
annotations: none low

Evaluate data minimization compliance per HIPAA Minimum Necessary Rule (164.502(b)). Behavior: This tool is read-only and stateless — it produces analysis output without modifying any external systems, databases, or files. Safe to call repeatedly with identical inputs (idempotent). Free tier: 10/day rate limit. Pro tier: unlimited. No authentication required for basic usage. When to use: Use this tool when you need to assess, audit, or verify compliance requirements. Ideal for gap analysis, readiness checks, and generating compliance documentation. When NOT to use: Do not use as a substitute for qualified legal counsel. This tool provides technical compliance guidance, not legal advice. Args: data_request_description (str): The data request description to analyze or process. requester_role (str): The requester role to analyze or process. purpose (str): The purpose to analyze or process. data_elements_requested (str): The data elements requested to analyze or process. role_based_access (bool): The role based access to analyze or process. policy_documented (bool): The policy documented to analyze or process. api_key (str): The api key to analyze or process. Behavioral Transparency: - Side Effects: This tool is read-only and produces no side effects. It does not modify any external state, databases, or files. All output is computed in-memory and returned directly to the caller. - Authentication: No authentication required for basic usage. Pro/Enterprise tiers require a valid MEOK API key passed via the MEOK_API_KEY environment variable. - Rate Limits: Free tier: 10 calls/day. Pro tier: unlimited. Rate limit headers are included in responses (X-RateLimit-Remaining, X-RateLimit-Reset). - Error Handling: Returns structured error objects with 'error' key on failure. Never raises unhandled exceptions. Invalid inputs return descriptive validation errors. - Idempotency: Fully idempotent — calling with the same inputs always produces the same output. Safe to retry on timeout or transient failure. - Data Privacy: No input data is stored, logged, or transmitted to external services. All processing happens locally within the MCP server process.

caller str api_key str purpose str requester_role str policy_documented bool role_based_access bool data_elements_requested str data_request_description str
predict_risk_neural
annotations: none low

Neural network-based risk prediction that improves from every compliance check. Behavior: This tool is read-only and stateless — it produces analysis output without modifying any external systems, databases, or files. Safe to call repeatedly with identical inputs (idempotent). Free tier: 10/day rate limit. Pro tier: unlimited. No authentication required for basic usage. When to use: Use this tool when you need to assess, audit, or verify compliance requirements. Ideal for gap analysis, readiness checks, and generating compliance documentation. When NOT to use: Do not use as a substitute for qualified legal counsel. This tool provides technical compliance guidance, not legal advice. Args: system_name (str): The system name to analyze or process. uses_biometric (bool): The uses biometric to analyze or process. uses_health_data (bool): The uses health data to analyze or process. has_human_oversight (bool): The has human oversight to analyze or process. affected_users (int): The affected users to analyze or process. sector (str): The sector to analyze or process. has_documentation (bool): The has documentation to analyze or process. prior_incidents (int): The prior incidents to analyze or process. api_key (str): The api key to analyze or process. Behavioral Transparency: - Side Effects: This tool is read-only and produces no side effects. It does not modify any external state, databases, or files. All output is computed in-memory and returned directly to the caller. - Authentication: No authentication required for basic usage. Pro/Enterprise tiers require a valid MEOK API key passed via the MEOK_API_KEY environment variable. - Rate Limits: Free tier: 10 calls/day. Pro tier: unlimited. Rate limit headers are included in responses (X-RateLimit-Remaining, X-RateLimit-Reset). - Error Handling: Returns structured error objects with 'error' key on failure. Never raises unhandled exceptions. Invalid inputs return descriptive validation errors. - Idempotency: Fully idempotent — calling with the same inputs always produces the same output. Safe to retry on timeout or transient failure. - Data Privacy: No input data is stored, logged, or transmitted to external services. All processing happens locally within the MCP server process.

sector str api_key str system_name str affected_users int uses_biometric bool prior_incidents int uses_health_data bool has_documentation bool has_human_oversight bool
neural_insights
annotations: none low

Get aggregate learning insights from the neural compliance model. Behavior: This tool is read-only and stateless — it produces analysis output without modifying any external systems, databases, or files. Safe to call repeatedly with identical inputs (idempotent). Free tier: 10/day rate limit. Pro tier: unlimited. No authentication required for basic usage. When to use: Use this tool when you need to assess, audit, or verify compliance requirements. Ideal for gap analysis, readiness checks, and generating compliance documentation. When NOT to use: Do not use as a substitute for qualified legal counsel. This tool provides technical compliance guidance, not legal advice. Args: api_key (str): The api key to analyze or process. Behavioral Transparency: - Side Effects: This tool is read-only and produces no side effects. It does not modify any external state, databases, or files. All output is computed in-memory and returned directly to the caller. - Authentication: No authentication required for basic usage. Pro/Enterprise tiers require a valid MEOK API key passed via the MEOK_API_KEY environment variable. - Rate Limits: Free tier: 10 calls/day. Pro tier: unlimited. Rate limit headers are included in responses (X-RateLimit-Remaining, X-RateLimit-Reset). - Error Handling: Returns structured error objects with 'error' key on failure. Never raises unhandled exceptions. Invalid inputs return descriptive validation errors. - Idempotency: Fully idempotent — calling with the same inputs always produces the same output. Safe to retry on timeout or transient failure. - Data Privacy: No input data is stored, logged, or transmitted to external services. All processing happens locally within the MCP server process.

api_key str

Permissions 4

filesystem low
Server uses filesystem capabilities via: os
database medium
Server uses database capabilities via: sqlite3
network medium
Server uses network capabilities via: urllib
env_vars low
Server uses env_vars capabilities via: os.environ

Scan Findings 35

low
Tool 'generate_baa' has no annotations annotation_checker · 100%
low
Tool 'assess_hipaa_compliance' has no annotations annotation_checker · 100%
low
Tool 'check_phi_handling' has no annotations annotation_checker · 100%
low
Tool 'breach_notification_check' has no annotations annotation_checker · 100%
low
Tool 'minimum_necessary_check' has no annotations annotation_checker · 100%
low
Tool 'predict_risk_neural' has no annotations annotation_checker · 100%
low
Tool 'neural_insights' has no annotations annotation_checker · 100%
info
Sandbox failed to start for behavioral verification behavioral_verifier · 100%
medium
Vulnerable dependency: mcp@1.0.0 (GHSA-3qhf-m339-9g5v) dependency_analyzer · 95%
medium
Vulnerable dependency: mcp@1.0.0 (GHSA-9h52-p55h-vw2f) dependency_analyzer · 95%
medium
Vulnerable dependency: mcp@1.0.0 (GHSA-j975-95f5-7wqh) dependency_analyzer · 95%
medium
Vulnerable dependency: mcp@1.0.0 (GHSA-jpw9-pfvf-9f58) dependency_analyzer · 95%
medium
Vulnerable dependency: mcp@1.0.0 (GHSA-vj7q-gjh5-988w) dependency_analyzer · 95%
medium
Vulnerable dependency: mcp@1.0.0 (PYSEC-2026-1616) dependency_analyzer · 95%
medium
Vulnerable dependency: mcp@1.0.0 (PYSEC-2026-1617) dependency_analyzer · 95%
medium
Vulnerable dependency: mcp@1.0.0 (PYSEC-2026-1618) dependency_analyzer · 95%
medium
Vulnerable dependency: mcp@1.0.0 (PYSEC-2026-3482) dependency_analyzer · 95%
medium
Vulnerable dependency: mcp@1.0.0 (PYSEC-2026-3483) dependency_analyzer · 95%
info
pyproject.toml metadata manifest_parser · 100%
info
Tool: minimum_necessary_check manifest_parser · 90%
info
Tool: assess_hipaa_compliance manifest_parser · 90%
info
Tool: check_phi_handling manifest_parser · 90%
info
Tool: generate_baa manifest_parser · 90%
info
Tool: breach_notification_check manifest_parser · 90%
info
Tool: predict_risk_neural manifest_parser · 90%
info
Tool: neural_insights manifest_parser · 90%
info
Transport: streamable-http manifest_parser · 80%
info
Required env vars (5) manifest_parser · 80%
info
Sandbox failed to start for output poisoning scan output_poisoning · 100%
medium
Permission: network access detected permission_analyzer · 80%
low
Permission: filesystem access detected permission_analyzer · 70%
medium
Permission: database access detected permission_analyzer · 90%
low
Permission: env_vars access detected permission_analyzer · 90%
info
No dependency files found for SBOM generation sbom_generator · 100%
medium
No build provenance detected (SLSA L0) slsa_assessor · 90%