Skip to main content
Glama

compliance_audit

Scan data for PHI exposure (SSN, MRN, DOB) with severity scores and remediation recommendations to ensure HIPAA compliance.

Instructions

HIPAA compliance audit. Scans data for PHI exposure (SSN, MRN, DOB patterns), returns findings with severity, score (0-100), and remediation recommendations.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
dataYesData to audit for compliance issues
auditTypeNoType of audit (default: general)

Implementation Reference

  • Schema/tool definition for compliance_audit. Defines input schema with 'data' (record of unknown) and optional 'auditType' (general|hipaa). Points to endpoint '/agent/v1/compliance/audit'.
    {
      name: 'compliance_audit',
      description: 'HIPAA compliance audit. Scans data for PHI exposure (SSN, MRN, DOB patterns), returns findings with severity, score (0-100), and remediation recommendations.',
      price: '$0.25',
      endpoint: '/agent/v1/compliance/audit',
      schema: {
        data: z.record(z.unknown()).describe('Data to audit for compliance issues'),
        auditType: z.enum(['general', 'hipaa']).optional().describe('Type of audit (default: general)'),
      },
  • src/index.js:19-61 (registration)
    Registration of compliance_audit via the generic MCP_TOOLS loop in createMcpServer(). The tool is registered with the MCP server using s.tool().
    for (const tool of MCP_TOOLS) {
      s.tool(tool.name, tool.description, tool.schema, async (params) => {
        const toolDef = getToolByName(tool.name);
        if (!toolDef) {
          return { content: [{ type: 'text', text: `Unknown tool: ${tool.name}` }], isError: true };
        }
        try {
          const response = await fetch(`${API_BASE_URL}${toolDef.endpoint}`, {
            method: 'POST',
            headers: {
              'Content-Type': 'application/json',
              ...(API_KEY && { 'X-API-Key': API_KEY }),
              'X-Agent-ID': 'mcp-client',
              'User-Agent': '@mymedi-ai/mcp-server/1.2.1',
            },
            body: JSON.stringify(params),
          });
          if (response.status === 402) {
            const paymentInfo = await response.json();
            return {
              content: [{ type: 'text', text: JSON.stringify({
                error: 'payment_required',
                message: `This tool costs ${toolDef.price} per call. Register at ${API_BASE_URL}/bot-marketplace/register for an API key with 10 free starter credits, or pay per call with on-chain USDC (no signup) via the x402 protocol.`,
                price: toolDef.price, register: `${API_BASE_URL}/bot-marketplace/register`, ...paymentInfo,
              }, null, 2) }], isError: true,
            };
          }
          if (!response.ok) {
            const error = await response.json().catch(() => ({ message: response.statusText }));
            return { content: [{ type: 'text', text: JSON.stringify({ error: true, status: response.status, ...error }, null, 2) }], isError: true };
          }
          const data = await response.json();
          const creditsSpent = response.headers.get('X-Credits-Spent');
          const creditsRemaining = response.headers.get('X-Credits-Remaining');
          if (creditsSpent) {
            data._billing = { creditsSpent: parseInt(creditsSpent, 10), creditsRemaining: creditsRemaining ? parseInt(creditsRemaining, 10) : undefined, priceUSD: toolDef.price };
          }
          return { content: [{ type: 'text', text: JSON.stringify(data, null, 2) }] };
        } catch (err) {
          return { content: [{ type: 'text', text: JSON.stringify({ error: true, message: err.message, hint: 'Ensure MCP_API_BASE_URL and MCP_API_KEY environment variables are set.' }, null, 2) }], isError: true };
        }
      });
    }
  • Helper function getToolByName that looks up tool definitions by name, used during handler execution to find the compliance_audit definition.
    export function getToolByName(name) {
      return MCP_TOOLS.find((t) => t.name === name);
    }
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are present, so the description carries full burden. It indicates a read-only scanning operation (no mention of side effects) and specifies returned data (findings, severity, score, recommendations). Could explicitly state it is non-destructive, but current text is sufficiently clear for a read-only audit.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two sentences, no redundancy, front-loaded with the key qualifier 'HIPAA'. Every word adds meaning, and the structure is efficient.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The description covers the tool's purpose, input parameters (partially via schema context), and output format. No output schema exists, but the return values are described. It lacks details on default auditType, but the schema covers that. Adequate for an AI agent to invoke correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, providing baseline 3. The description adds value by elaborating on the 'data' parameter (emphasizing PHI patterns like SSN, MRN, DOB) and mentioning output details, which supplement the schema's generic descriptions.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the verb ('scans'), resource ('data for PHI exposure'), and provides specific outputs (severity, score, recommendations). It distinguishes from siblings like claims_validate and code_validate by focusing on HIPAA compliance auditing.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies usage for HIPAA compliance audits but does not explicitly state when to use this tool versus alternatives (e.g., claims_validate for claim validation). No exclusions or alternate tool references are provided.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Install Server

Other Tools

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/MyMedi-AI/mymedi-ai-mcp-server'

If you have feedback or need assistance with the MCP directory API, please join our Discord server