Healthclaw Guardrails
HealthClaw Guardrails is the security layer between AI agents and clinical FHIR data. Every agent read passes through PHI redaction (names truncated to initials, DOBs to year, identifiers masked). Every write requires an HMAC-signed step-up token with a 5-minute TTL. Clinical writes (Condition, MedicationRequest, DiagnosticReport) return HTTP 428 until a human confirms. Every access lands in an append-only audit trail scoped by tenant. Supports FHIR R4 US Core v9 (stable) and FHIR R6 v6.0.0-bal
Works with: Claude Code (native)
native: this artifact type is that client's own format
Category: Security — see all ranked ›
Work: Regulatory compliance · Security review · Agent configuration
Who it is for: Legal / compliance · Security engineer · Agent operator
Install (Claude Code):
/plugin marketplace add anthropics/claude-plugins-community
/plugin install healthclaw-guardrails@claude-community“Demo server is hard-pinned to synthetic data; 29 tools sit under walls of release notes”
This grade is wrong ›- tashan score: 55.0
- Instruction depth: 74.0 (solid — documents the job properly, with examples you could follow)
- Adoption: 1 repos
- Upkeep: 92.0
- Freshness: 83.0
- Evidence coverage: 84% of the inputs this score can use — the rest are unknown, and the score is discounted for it
- Health: active
- GitHub stars: 27
- Contributors: 7
- License: MIT
Security audit
Not scanned yet. We audit npm-published capabilities for known advisories, install-time scripts and permission surface; this one has no npm package we can resolve, or has not reached the queue.
You searched for one. Check the rest of your stack:
npx tashan-cli doctorReads the config already on your machine and names what is dead, deprecated or running code at install time. No account, nothing uploaded.
Healthclaw Guardrails scores 55 today. Pro keeps the series, so you can see whether that is a project getting better or one on its way down.
- The whole series behind any row, back to the first day we measured it
- The replacement, named — not just the news that something died
tashan doctorover your own config, on your own machine
Start a 7-day trial › Everything measured on this page stays free.
source ↗ · plugin:aks129/healthclawguardrails/healthclaw-guardrails
Everything on this page is public evidence and free. What it cannot know is whether you run this — check your whole config, free, in the browser. tashan Pro adds the series behind each row and names a replacement for anything dying.
Already running this? Check your whole config — free, in your browser, nothing installed. Or npx tashan-cli doctor locally, which sends nothing at all.
Measured 2026-09-13 · scorer s5 · how · something wrong here?