Healthcare Protection Operations
The night watch for smaller healthcare organizations.
CuraDefend assesses 48 protection controls across your organization, turns the gaps into a prioritized 30/60/90-day plan, and keeps watch as evidence ages and risks change — with a human reviewer behind every score.
01 — The problem
Breaches at small organizations are rarely dramatic. They’re ordinary things, unattended.
The unreturned laptop
A nurse leaves; the laptop doesn't come back. Nobody disables the account for six weeks. Device inventory and same-day offboarding are two of the 48 controls we assess.
DEV-001 · IAM-005
The shared login
The front desk shares one password because it's faster. Every action becomes untraceable. Unique accounts and access reviews close this quietly.
IAM-001 · IAM-004
The vendor without a BAA
A billing service has been handling patient information for two years on a handshake. Vendor inventory and business associate agreements make the invisible visible.
VEN-001 · VEN-002
The backup nobody restored
Backups ran nightly for years — and the first restore attempt happens during the ransomware incident. We ask when you last proved a restore works.
REC-001 · REC-002
02 — Two numbers, never blended
One score would be simpler. It would also be wrong.
Protection Readiness
82/100
Developed
Overall Risk
High
1 unresolved high-severity finding
Both can be true.
A practice can do most things well and still have one gap that matters — an offboarding miss, an unencrypted laptop. That’s why CuraDefend reports two numbers and never blends them: readiness shows the shape of your program, risk shows what could hurt you right now.
A CuraDefend Protection Readiness Score is not a measurement or certification of legal compliance.
03 — How it works
Assessment is the beginning, not the product.
01
Assess
Your team answers 48 plain-English controls across 8 domains — governance, access, devices, recovery, workforce, vendors, incident response, and AI use. Honest answers beat perfect ones; “Unsure” is always acceptable.
02
Review
A CuraDefend reviewer examines every answer, asks follow-ups, verifies evidence, and approves the maturity behind each control. Scores are never self-graded and never AI-graded.
03
Plan
Findings become a 30/60/90-day plan ordered by real risk — likelihood times impact, not alphabetical order. Critical work is never postponed to make the chart look balanced.
04
Monitor
Protection decays quietly: evidence goes stale, people leave, vendors change. CuraDefend Monitor keeps a verification schedule on every fix and reopens what ages out.
Every verified state ages honestly: AttestedFounder verifiedStale
04 — Founding Agency program
The first ten organizations shape the product — and keep the founding rate.
CuraDefend works with its first ten customers directly: your assessment is reviewed personally, your feedback steers the roadmap, and your price stays at the founding rate. We qualify every application — this is a working relationship, not a checkout page.
Founding Agency
$795one-time assessment
First 10 organizations · $1,250 standard rate afterward
- Full 48-control Protection Assessment
- Human review of every answer and evidence item
- Issued report with a 30/60/90-day plan
- CuraDefend Monitor — $249/mo, cancel anytime
Why we exist
“Give smaller healthcare organizations the clarity and tools to understand their risks, fix what matters most, and protect the people and information entrusted to them.”