em-dash: Hard-Coding HIPAA into the Agentic Workflow

Moving beyond "vibes-based" compliance with Rego policies, evidence hashing, and the Claude Code ecosystem.

8 min read • View on GitHub • More from aanishs

A thin line separating chaotic paperwork from clean cryptographic code, representing evidence hashing.
By treating compliance as code, em-dash replaces ambiguous documentation with verifiable cryptographic hashes.
Key Takeaways

The End of the "Trust Me" Audit

The tech industry has a compliance problem. For years, passing a security audit meant paying a firm thousands of dollars to generate static PDFs. It was a snapshot of security, entirely disconnected from the actual codebase. When AI agents entered the workflow, the problem multiplied. Agents can easily fabricate "evidence" of compliance to satisfy a prompt, creating a dangerous illusion of security.

The open-source project em-dash was built as a direct countermeasure to this hallucinated compliance. It operates as an "Agentic Compliance Environment" injected directly into the Claude Code CLI. Rather than acting as an external observer, it provides Claude with the exact tools needed to scan, verify, and remediate code in real time.

The core innovation is its insistence on verifiable proof. Through a utility called bin/hipaa-evidence-hash, the system creates cryptographic hashes of compliance artifacts. This local, hashed evidence ensures that every security claim is mathematically tied to the state of the repository. It turns a subjective audit into a verifiable pull request.

Mapping Law to Logic: The Registry

Translating legal statutes into executable code is notoriously difficult. A regulation like HIPAA §164.312 requires "access controls," but that phrase means nothing to a compiler. The architecture of em-dash solves this translation problem through a centralized registry.

The files checks-registry.ts and schema.ts act as a mapping engine. They decouple the abstract regulatory requirement from the technical implementation. A single "Check" defined in this registry might trigger a grep command for exposed Social Security Numbers or invoke an Open Policy Agent (Rego) scan against a Terraform manifest.

A multi-layered mapping diagram. On the left

This decoupling is powerful. It allows the framework to evaluate Infrastructure-as-Code against healthcare-specific security policies before deployment. If a developer attempts to merge a misconfigured Kubernetes manifest, the Rego policies catch the violation and map it directly back to the specific HIPAA paragraph it violates.

Claude as the Compliance Officer

Traditional compliance platforms are passive dashboards. They tell you what is broken and leave the fixing to the engineering team. By building on top of Claude Code, em-dash shifts from a passive monitor to an active participant.

A human hand holding a checklist beside a mechanical hand writing a Rego policy on a scroll.
The system pairs human oversight with agentic remediation, allowing Claude to write the patches it recommends.

The /skills directory defines specialized workflows for the AI. For example, the hipaa-assess skill uses LLM-driven interviewing instead of static forms. Claude acts as the auditor, asking contextual questions to satisfy requirements like identifying the "Designated Security Officer."

A cyclical pipeline representing the Skill Execution Loop. Nodes are arranged in a circle: "Environment Detection"

When the system identifies a vulnerability, it does not just log a ticket. Through the hipaa-remediate skill, Claude generates the necessary code patches to fix the issue. It applies HIPAA-compliant patterns directly to the codebase, compressing days of security review into minutes.

The Version-Controlled Paper Trail

In heavily regulated environments, proving you were secure yesterday is just as important as being secure today. A dashboard showing green checkmarks is useless during an audit if it cannot provide historical context.

The persistence layer of em-dash handles this through the hipaa-review-log script. Every time a compliance check runs, the system appends a JSON record to a local log. Crucially, this record includes the exact Git commit hash of the repository at the time of the scan.

Feature Traditional Audit em-dash Framework
Cadence Yearly snapshots Continuous (per commit)
Evidence Format Static PDFs and screenshots JSONL logs and cryptographic hashes
Remediation Manual ticket creation Agentic code patching
Infrastructure Validation Post-deployment scanning Pre-deployment Rego checks

This approach transforms compliance from an annual interruption into a continuous, version-controlled process. By binding security posture directly to Git history, em-dash ensures that the audit trail is as immutable and transparent as the code itself.


Sources: Technical details and architectural patterns are derived from the em-dash source code and repository documentation.