Skip to content

Sample report

This is the actual deliverable.

Harborlight Home Health is our synthetic demonstration agency — a realistic 22-person home health organization with realistic strengths and gaps. The report below was produced by the same engines, review workflow, and template every customer receives. Nothing in it is hand-tuned for marketing.

CuraDefend

CD-PA-000001 • Assessment v1.0 • Control Library 2026.08

Protection Assessment Report

Harborlight Home Health — Demonstration Organization

doing business as Harborlight Home Health

Demonstration organization — synthetic data

Protection Readiness

67/100

Developing

Overall Risk

High

highest unresolved finding

Issued

August 14, 2026

Scoring PRS-1.0.0 · Risk RISK-1.0.0

A CuraDefend Protection Readiness Score is not a measurement or certification of legal compliance.

02About this report

This report presents the results of a CuraDefend Protection Assessment: a structured, human-reviewed evaluation of Harborlight Home Health — Demonstration Organization’s organizational security and compliance-support practices across 48 controls in 8 domains. Every maturity level in this report was approved by a CuraDefend reviewer; no score was self-assigned or machine-assigned.

CuraDefend provides organizational risk, security, and compliance-support services. CuraDefend assessments and scores are informational risk-management tools and do not constitute legal advice, regulatory certification, or a guarantee of HIPAA compliance.

03How to read the numbers

Protection Readiness · 0–100

The shape of your program: reviewer-approved maturity (0–4) on each control, weighted by importance, aggregated through fixed domain weights. Labels: 90+ Mature · 75+ Developed · 60+ Developing · 40+ Weak · below 40 Significant Gaps.

Risk · severity of findings

What could hurt you now: each finding carries likelihood × impact (1–5 each). 1–4 Improvement · 5–9 Moderate · 10–16 High · 17–25 Critical. Your overall risk is the highest unresolved finding — including formally accepted risks.

Readiness 67 with High risk is a coherent result: a program can be broadly sound and still carry one gap that matters. The two numbers are computed by separate engines and are never blended.

04Organization profile

Organization
Harborlight Home Health — Demonstration Organization
Type
home health
Workforce size
22
Locations
2
States
ME, NH
HIPAA entity status
covered entity

05Executive summary

Harborlight Home Health — Demonstration Organization is a home health agency with a workforce of about 22. Based on reviewer-approved answers across the CuraDefend control library, its Protection Readiness Score is 67 (Developing), and its current overall risk level is High. The assessment identified 5 high, 2 moderate, and 1 improvement findings that remain open or otherwise unresolved. The strongest areas today are workforce security and identity and access. The areas needing the most attention are AI and shadow technology and vendors and business associates. The highest-priority work is: “BAA coverage is incomplete or unknown”, “Staff have not been told the PHI-in-AI rule”, and “Personal-device and remote-work risks are uncontrolled”. The 30/60/90-day plan in this report sequences that work. A CuraDefend Protection Readiness Score is not a measurement or certification of legal compliance.

06Protection Readiness Score

07Domain detail

08Risk overview

09Top priorities

10Findings in detail

11Accepted and deferred risks

No risks have been formally accepted or deferred for this assessment.

12The 30 / 60 / 90-day plan

Sequenced by severity and dependency — critical work is never postponed to balance the chart. Each action names an owner role, the evidence that will demonstrate completion, and whether CuraDefend verification is required before it closes.

13Evidence summary

14Control matrix

ControlMaturityEvidence
GOV-001 Security responsibility is formally assigned to a specific individual or role.●●●3/4not provided
GOV-002 A documented security risk analysis has been completed and is maintained.●●●●4/4founder verified
GOV-003 The organization has identified where ePHI is created, received, maintained, and transmitted.●●●3/4not provided
GOV-004 An active risk-management and remediation plan exists with owners and target dates.●●●3/4not provided
GOV-005 Security policies are documented, available, and periodically reviewed.●●●3/4not provided
GOV-006 Security is reevaluated when technology, vendors, locations, or operations materially change.●●●●2/4not provided
GOV-007 Required security documentation and historical records are retained appropriately.●●●●2/4not provided
IAM-001 Workforce members use unique accounts where technically supported.●●●3/4not provided
IAM-002 Access is granted according to role and business need.●●●3/4not provided
IAM-003 Appropriate MFA is deployed for remote, cloud, email, and privileged access.●●●●4/4founder verified
IAM-004 Privileged or administrator accounts are appropriately separated from routine activity.●●●3/4not provided
IAM-005 Access is promptly removed when workforce members leave or no longer require it.●●●3/4not provided
IAM-006 Access rights and relevant system activity are periodically reviewed.●●●●2/4not provided
DEV-001 The organization maintains an inventory of devices capable of accessing ePHI.●●●3/4not provided
DEV-002 Workstation use and physical-security expectations are documented and implemented.●●●3/4not provided
DEV-003 Laptops and mobile devices are protected or encrypted based on documented risk analysis.●●●3/4attested
DEV-004 Endpoints are protected against malware and common threats.●●●3/4not provided
DEV-005 Operating systems and software are updated, and known vulnerabilities are addressed.●●●●2/4not provided
DEV-006 Personal-device, BYOD, and remote-work risks are controlled.●●●1/4not provided
DEV-007 Devices and media are securely disposed of or sanitized before reuse.●●●3/4not provided
REC-001 Critical ePHI is backed up through documented procedures.●●●3/4not provided
REC-002 The organization has demonstrated that critical backups can be restored.●●●●0/4not provided
REC-003 Disaster-recovery and emergency-mode procedures are established.●●●3/4not provided
REC-004 ePHI is appropriately protected during electronic transmission.●●●3/4not provided
REC-005 Controls protect ePHI integrity against inappropriate alteration or destruction.●●●3/4not provided
REC-006 Critical systems and processes are identified for continuity and recovery priorities.●●●●2/4not provided
WRK-001 New workforce members receive appropriate security training.●●●●4/4founder verified
WRK-002 Security awareness is reinforced after onboarding and when risks change.●●●3/4not provided
WRK-003 Appropriate sanctions exist for security or privacy policy violations.●●●3/4not provided
WRK-004 Workforce education addresses phishing, credential theft, and common cyber threats.●●●3/4not provided
WRK-005 Workforce members acknowledge relevant security responsibilities and policies.●●●●2/4not provided
VEN-001 A current inventory exists for vendors that create, receive, maintain, or transmit PHI or ePHI.●●●3/4not provided
VEN-002 Appropriate BAAs are present for applicable business-associate relationships.●●●●2/4not provided
VEN-003 Privacy and security risk are considered before new vendors are approved.●●●●2/4not provided
VEN-004 Applicable vendor arrangements address incident and security reporting responsibilities.●●●●2/4not provided
VEN-005 Data and system access are handled appropriately when a vendor relationship ends.●●●●2/4not provided
VEN-006 Vendors are reviewed when services, systems, or risks materially change.●●●●2/4not provided
INC-001 A written security-incident response procedure exists.●●●3/4attested
INC-002 Workforce members know how and where to report suspected incidents.●●●3/4not provided
INC-003 Security incidents and outcomes are documented.●●●3/4not provided
INC-004 An escalation process exists for incidents that may involve PHI.●●●3/4not provided
INC-005 Response roles and important internal and external contacts are identified.●●●●2/4not provided
INC-006 The organization has tested or reviewed its response process.●●●1/4not provided
AI-001 The organization knows which generative-AI and AI-enabled services its workforce uses.●●●●2/4not provided
AI-002 An approved, conditional, and prohibited AI-tool policy exists.●●●1/4not provided
AI-003 Workforce members are instructed when PHI may or may not be entered into AI systems.●●●1/4not provided
AI-004 Business-associate status and BAA needs are evaluated when an AI vendor handles PHI.●●●●2/4not provided
AI-005 AI use cases are reviewed for privacy, security, operational, and human-impact risks before adoption.●●●1/4not provided

15Sources and classifications

Each control in this report is tagged with its sources. Badges mean exactly this:

  • Current HIPAA Rule
  • Addressable HIPAA Specification
  • HHS Guidance
  • HHS Cybersecurity Goal
  • NIST Guidance
  • CuraDefend Practice
  • Proposed — Not Current Lawnever scored as current law

Your 30/60/90-day plan is live in the CuraDefend portal. Each action can be worked, completed, and — where marked — verified by your reviewer. With CuraDefend Monitor, completed work carries a reverification schedule, evidence ages honestly, and accepted risks return for reconsideration on their review dates.

A reassessment is recommended annually, or after significant change: new locations, new systems, workforce growth, or an incident.

17Methodology and versions

Scores are deterministic: identical reviewed answers always produce identical results. This report is frozen as of its issuance date and is never recalculated retroactively. Full formulas are published at curadefend.com/methodology.

18Disclaimers

CuraDefend provides organizational risk, security, and compliance-support services. CuraDefend assessments and scores are informational risk-management tools and do not constitute legal advice, regulatory certification, or a guarantee of HIPAA compliance.

A CuraDefend Protection Readiness Score is not a measurement or certification of legal compliance.

This report is not legal advice and does not determine whether any breach, violation, or reportable event has occurred. CuraDefend is not affiliated with or endorsed by any government agency. Findings reflect information provided by the organization during the assessment period; conditions may have changed since issuance.

CD-PA-000001 • Assessment v1.0 • Control Library 2026.08 · CuraDefend is operated by Psalm Wave LLC.