Legal
Disclaimers
CuraDefend provides organizational risk, security, and compliance-support services. CuraDefend assessments and scores are informational risk-management tools and do not constitute legal advice, regulatory certification, or a guarantee of HIPAA compliance.
Not legal advice
Nothing in CuraDefend’s website, application, assessments, reports, findings, plans, or communications is legal advice, and no attorney-client relationship is created by using our services. Regulatory obligations depend on facts and law specific to your organization; consult qualified legal counsel for legal questions.
Not certification
There is no such thing as an official “HIPAA certification,” and CuraDefend does not certify, warrant, or guarantee compliance with HIPAA or any law or regulation. A CuraDefend Protection Readiness Score is not a measurement or certification of legal compliance. Scores summarize reviewer-approved answers about organizational practices at a point in time — nothing more.
Not a breach or violation determination
CuraDefend findings describe organizational risk. They are not determinations that a security incident, breach, or regulatory violation has or has not occurred. Whether an event constitutes a reportable breach is a legal determination your organization must make with appropriate counsel.
No government affiliation
CuraDefend is not affiliated with, endorsed by, or acting on behalf of the U.S. Department of Health and Human Services, the Office for Civil Rights, NIST, or any government agency. References to laws, rules, and guidance are for orientation; source classifications in the product indicate whether each item is current law, guidance, or our recommendation, and proposed rules are never treated as current legal requirements.
Point-in-time nature of assessments
An issued report reflects information available during the assessment period and is frozen as of its issuance date. Your risk posture changes as your organization changes; a report does not update itself, which is precisely why CuraDefend Monitor exists.
Limits of review
CuraDefend review relies on information your organization provides. Reviewers verify evidence where feasible, but CuraDefend does not perform penetration testing, forensic examination, or exhaustive technical audit unless explicitly stated in a service agreement, and cannot detect information that was not disclosed.
No patient information
CuraDefend services are designed to operate without receiving protected health information, and our terms prohibit submitting it. CuraDefend is not a business associate for purposes of the services described on this site, and no business associate agreement is offered for them.