Methodology
Every number in CuraDefend can be recomputed by hand.
Scores are deterministic: the same reviewed answers always produce the same result. AI never calculates a score, never changes a severity, and never approves evidence. Here is the entire method.
01 — Protection Readiness Score · engine PRS-1.0.0
Reviewer-approved maturity, weighted twice.
Each of the 48 controls receives a maturity from 0 to 4, approved by a human reviewer — never self-assigned, never AI-assigned. Maturity 4 requires verified evidence.
- Control score = maturity ÷ 4 × importance, where importance is 1–3 set in the control library.
- Domain score = earned ÷ maximum within the domain, as a percentage. Controls approved as Not Applicable are excluded from both sides — they neither help nor hurt.
- Overall score = the weighted sum of domain scores using the fixed weights shown here. If a domain is entirely N/A, its weight is redistributed proportionally.
Decimals are kept internally; you see rounded numbers. Issued reports freeze the score, the engine version, and the control library version — a past report is never silently recalculated.
A CuraDefend Protection Readiness Score is not a measurement or certification of legal compliance.
| GOV | Governance and Risk Management | 2000% |
| IAM | Identity and Access | 1500% |
| DEV | Devices and Remote Workforce | 1500% |
| REC | Data Protection and Recovery | 1500% |
| WRK | Workforce Security | 1000% |
| VEN | Vendors and Business Associates | 1000% |
| INC | Incident Readiness | 1000% |
| AI | AI and Shadow Technology | 500% |
| 90–100 | Mature |
| 75–89 | Developed |
| 60–74 | Developing |
| 40–59 | Weak |
| 0–39 | Significant Gaps |
02 — Risk severity · engine RISK-1.0.0
Risk is a separate engine — on purpose.
Each finding gets a likelihood (1–5) and an impact (1–5), reviewed by a human. Severity = likelihood × impact:
- 1–4 Improvement
- 5–9 Moderate
- 10–16 High
- 17–25 Critical
Your overall risk level is the highest unresolved finding — including risks you have formally accepted or deferred. A documented decision to live with a risk is respected, recorded, and revisited on a schedule; it does not make the risk disappear from awareness.
A reviewer may urgently elevate a severity with a documented reason — elevate only, never downgrade — and every change is written to the audit log.
| L↓ · I→ | 1 | 2 | 3 | 4 | 5 |
|---|---|---|---|---|---|
| 1 | 1 | 2 | 3 | 4 | 5 |
| 2 | 2 | 4 | 6 | 8 | 10 |
| 3 | 3 | 6 | 9 | 12 | 15 |
| 4 | 4 | 8 | 12 | 16 | 20 |
| 5 | 5 | 10 | 15 | 20 | 25 |
Protection Readiness
82/100
Developed
Overall Risk
High
1 unresolved high-severity finding
Both can be true.
A practice can do most things well and still have one gap that matters — an offboarding miss, an unencrypted laptop. That’s why CuraDefend reports two numbers and never blends them: readiness shows the shape of your program, risk shows what could hurt you right now.
A CuraDefend Protection Readiness Score is not a measurement or certification of legal compliance.
03 — Where controls come from
Seven source classifications, always visible.
Every control shows badges for the sources behind it, so you always know whether something is current law, official guidance, or our professional recommendation. Proposed rules are clearly marked and are never scored as current legal requirements.
Current HIPAA Rule
A required implementation specification or standard in the current HIPAA Security Rule.
Addressable HIPAA Specification
An addressable specification — you must assess it and implement it or document an equivalent alternative.
HHS Guidance
Published guidance from the U.S. Department of Health and Human Services.
HHS Cybersecurity Goal
A voluntary HHS Cybersecurity Performance Goal for the health sector.
NIST Guidance
Voluntary guidance from NIST publications relevant to small healthcare organizations.
CuraDefend Practice
A CuraDefend-recommended practice grounded in incident patterns at small organizations.
Proposed — Not Current Law
From a proposed regulation that is not current law. Never scored as a legal requirement.
04 — Method governance
Versioned, frozen, audited.
- The control library, scoring engine, risk engine, and report template each carry a version. Your report names the exact versions used.
- Issued reports are immutable — enforced at the database level, not by policy.
- Every consequential change (a maturity decision, a severity override, an evidence verification) records who, when, and why in an append-only audit log.
- AI is never in the scoring path. If AI-assisted narrative drafting is ever enabled, it is labeled, logged, human-approved, and OFF by default.
CuraDefend provides organizational risk, security, and compliance-support services. CuraDefend assessments and scores are informational risk-management tools and do not constitute legal advice, regulatory certification, or a guarantee of HIPAA compliance.