Skip to content

Free Protection Check

Twelve questions. Three minutes. An honest signal.

Answer for how things actually work today — not how the binder says they should. “Unsure” is always an acceptable answer and scores the same as “No,” because unknown protection isn’t protection. You’ll see your result immediately; no email is required.

This quick check is a directional signal, not an assessment, and your answers are not stored unless you choose to share them at the end.

A CuraDefend Protection Readiness Score is not a measurement or certification of legal compliance.

0 OF 12 ANSWERED

  1. 01 · SECURITY LEADERSHIPIs responsibility for healthcare information security clearly assigned?

    Someone specific — by name or role — owns security decisions, even part-time.

  2. 02 · RISK ANALYSIS · WEIGHS DOUBLEDoes the organization maintain a current, documented security risk analysis?

    A written analysis of where ePHI could be exposed, reviewed within a reasonable period.

  3. 03 · EPHI AWARENESSDoes the organization know the major systems and locations where ePHI is stored or transmitted?

    EHR, email, file storage, billing, devices, fax — the map of where patient data lives.

  4. 04 · ACCESS PROTECTION (MFA) · WEIGHS DOUBLEIs appropriate MFA enabled for important remote, cloud, email, and administrative access?

    Multi-factor authentication on the accounts an attacker would want most.

  5. 05 · WORKFORCE ACCOUNTS · WEIGHS DOUBLEAre workforce accounts unique, and is access promptly removed when someone leaves?

    No shared logins, and departures trigger same-day or next-day access removal.

  6. 06 · DEVICESAre devices that access ePHI inventoried and appropriately secured?

    You know which laptops, phones, and tablets touch patient data, and they are protected.

  7. 07 · BACKUP AND RECOVERY · WEIGHS DOUBLEDoes the organization maintain backups and know that critical information can be restored?

    Backups exist — and someone has actually confirmed a restore works.

  8. 08 · SECURITY TRAININGDoes the workforce receive security training?

    New hires and existing staff learn how to handle information safely.

  9. 09 · VENDORS AND BAASDoes the organization maintain an inventory of relevant vendors and BAAs?

    A current list of who handles PHI for you, and signed business associate agreements.

  10. 10 · INCIDENT RESPONSE · WEIGHS DOUBLEIs there a documented security-incident response process?

    Written steps for what happens when something goes wrong, and who is called.

  11. 11 · ACTIVITY REVIEWDoes the organization review account or system activity for suspicious or inappropriate activity?

    Someone periodically looks at logins, access logs, or system alerts.

  12. 12 · AI AWARENESSDoes the organization know which AI tools employees use and what information may be entered into them?

    Chatbots, transcription, and note-drafting tools — do you know what staff paste into them?

Answer all 12 to see your score.