Skip to content

Methodology

Every number in CuraDefend can be recomputed by hand.

Scores are deterministic: the same reviewed answers always produce the same result. AI never calculates a score, never changes a severity, and never approves evidence. Here is the entire method.

01 — Protection Readiness Score · engine PRS-1.0.0

Reviewer-approved maturity, weighted twice.

Each of the 48 controls receives a maturity from 0 to 4, approved by a human reviewer — never self-assigned, never AI-assigned. Maturity 4 requires verified evidence.

  1. Control score = maturity ÷ 4 × importance, where importance is 1–3 set in the control library.
  2. Domain score = earned ÷ maximum within the domain, as a percentage. Controls approved as Not Applicable are excluded from both sides — they neither help nor hurt.
  3. Overall score = the weighted sum of domain scores using the fixed weights shown here. If a domain is entirely N/A, its weight is redistributed proportionally.

Decimals are kept internally; you see rounded numbers. Issued reports freeze the score, the engine version, and the control library version — a past report is never silently recalculated.

A CuraDefend Protection Readiness Score is not a measurement or certification of legal compliance.

Domain weights · library 2026.08
GOVGovernance and Risk Management2000%
IAMIdentity and Access1500%
DEVDevices and Remote Workforce1500%
RECData Protection and Recovery1500%
WRKWorkforce Security1000%
VENVendors and Business Associates1000%
INCIncident Readiness1000%
AIAI and Shadow Technology500%
Readiness labels
90100Mature
7589Developed
6074Developing
4059Weak
039Significant Gaps

02 — Risk severity · engine RISK-1.0.0

Risk is a separate engine — on purpose.

Each finding gets a likelihood (1–5) and an impact (1–5), reviewed by a human. Severity = likelihood × impact:

  • 1–4 Improvement
  • 5–9 Moderate
  • 10–16 High
  • 17–25 Critical

Your overall risk level is the highest unresolved finding — including risks you have formally accepted or deferred. A documented decision to live with a risk is respected, recorded, and revisited on a schedule; it does not make the risk disappear from awareness.

A reviewer may urgently elevate a severity with a documented reason — elevate only, never downgrade — and every change is written to the audit log.

Severity = likelihood × impact
L↓ · I→12345
112345
2246810
33691215
448121620
5510152025
Likelihood and impact are assigned per finding during human review.

Protection Readiness

82/100

Developed

Overall Risk

High

1 unresolved high-severity finding

Both can be true.

A practice can do most things well and still have one gap that matters — an offboarding miss, an unencrypted laptop. That’s why CuraDefend reports two numbers and never blends them: readiness shows the shape of your program, risk shows what could hurt you right now.

A CuraDefend Protection Readiness Score is not a measurement or certification of legal compliance.

03 — Where controls come from

Seven source classifications, always visible.

Every control shows badges for the sources behind it, so you always know whether something is current law, official guidance, or our professional recommendation. Proposed rules are clearly marked and are never scored as current legal requirements.

Current HIPAA Rule

A required implementation specification or standard in the current HIPAA Security Rule.

Addressable HIPAA Specification

An addressable specification — you must assess it and implement it or document an equivalent alternative.

HHS Guidance

Published guidance from the U.S. Department of Health and Human Services.

HHS Cybersecurity Goal

A voluntary HHS Cybersecurity Performance Goal for the health sector.

NIST Guidance

Voluntary guidance from NIST publications relevant to small healthcare organizations.

CuraDefend Practice

A CuraDefend-recommended practice grounded in incident patterns at small organizations.

Proposed — Not Current Law

From a proposed regulation that is not current law. Never scored as a legal requirement.

04 — Method governance

Versioned, frozen, audited.

  • The control library, scoring engine, risk engine, and report template each carry a version. Your report names the exact versions used.
  • Issued reports are immutable — enforced at the database level, not by policy.
  • Every consequential change (a maturity decision, a severity override, an evidence verification) records who, when, and why in an append-only audit log.
  • AI is never in the scoring path. If AI-assisted narrative drafting is ever enabled, it is labeled, logged, human-approved, and OFF by default.

CuraDefend provides organizational risk, security, and compliance-support services. CuraDefend assessments and scores are informational risk-management tools and do not constitute legal advice, regulatory certification, or a guarantee of HIPAA compliance.