
Compliance & Governance
Ensure pipelines meet regulatory requirements when preparing for audits or implementing data privacy regulations.
Prompt Template
Help me ensure [PIPELINE/FOLDER] meets [REGULATION/STANDARD] requirements:1. Regulatory requirements: - Regulation: [SPECIFIC_REGULATION] - Non-compliance penalties: [CONSEQUENCES]2. Current gaps: - [GAP_1]: [DESCRIPTION] - [GAP_2]: [DESCRIPTION]3. Data classification: - Sensitive data types: [PII/PHI/PCI/FINANCIAL] - Storage requirements: [ENCRYPTION/RETENTION] - Access controls: [WHO_NEEDS_ACCESS]4. Compliance needs: - Audit trail: [REQUIREMENTS] - Data lineage: [TRACKING_NEEDS] - Right to deletion: [ERASURE_REQUIREMENTS]Please provide:- Compliance assessment and gap analysis- Remediation steps with priority- Best practices for ongoing compliance- Documentation templates for auditors
Industry Example
Help me ensure patient-analytics folder meets HIPAA Privacy Rule, Security Rule, and HITECH Act requirements:1. Regulatory requirements: - Regulation: HIPAA Privacy Rule, Security Rule, and HITECH Act breach notification - Specific mandates: Minimum necessary standard, encryption at rest and in transit, access logging for all PHI - Non-compliance penalties: $100-$50K per violation (max $1.5M per year per violation type), potential criminal charges2. Current gaps: - Overly broad access: Clinical researchers have access to identifiable patient data when de-identified data would suffice - Incomplete audit logging: Pipeline access logs don't capture the "purpose of access" required by HIPAA - Retention violations: Patient discharge summaries retained for 10 years but state law only requires 7 years3. Data classification: - Sensitive data types: Direct PHI (names, MRNs, SSNs, dates of birth), clinical data (diagnoses, medications) - Storage requirements: AES-256 encryption at rest, TLS 1.2+ in transit - Access controls: Physicians need patient-level data, billing team needs financial+demographic only, researchers need de-identified cohorts4. Compliance needs: - Audit trail: Log every access to PHI with user ID, timestamp, patient(s) accessed, purpose/justification - Data lineage: Track which downstream reports/dashboards contain PHI for breach impact assessment - Right to deletion: Implement patient data deletion within 30 days of written request