Harborlight Home Health is our synthetic demonstration agency — a realistic 22-person home health organization with realistic strengths and gaps. The report below was produced by the same engines, review workflow, and template every customer receives. Nothing in it is hand-tuned for marketing.
CD-PA-000001 • Assessment v1.0 • Control Library 2026.08
Protection Assessment Report
Harborlight Home Health — Demonstration Organization
doing business as Harborlight Home Health
Demonstration organization — synthetic data
Protection Readiness
67/100
Developing
Overall Risk
High
highest unresolved finding
Issued
August 14, 2026
Scoring PRS-1.0.0 · Risk RISK-1.0.0
A CuraDefend Protection Readiness Score is not a measurement or certification of legal compliance.
02 — About this report
This report presents the results of a CuraDefend Protection Assessment: a structured, human-reviewed evaluation of Harborlight Home Health — Demonstration Organization’s organizational security and compliance-support practices across 48 controls in 8 domains. Every maturity level in this report was approved by a CuraDefend reviewer; no score was self-assigned or machine-assigned.
CuraDefend provides organizational risk, security, and compliance-support services. CuraDefend assessments and scores are informational risk-management tools and do not constitute legal advice, regulatory certification, or a guarantee of HIPAA compliance.
03 — How to read the numbers
Protection Readiness · 0–100
The shape of your program: reviewer-approved maturity (0–4) on each control, weighted by importance, aggregated through fixed domain weights. Labels: 90+ Mature · 75+ Developed · 60+ Developing · 40+ Weak · below 40 Significant Gaps.
Risk · severity of findings
What could hurt you now: each finding carries likelihood × impact (1–5 each). 1–4 Improvement · 5–9 Moderate · 10–16 High · 17–25 Critical. Your overall risk is the highest unresolved finding — including formally accepted risks.
Readiness 67 with High risk is a coherent result: a program can be broadly sound and still carry one gap that matters. The two numbers are computed by separate engines and are never blended.
04 — Organization profile
Organization
Harborlight Home Health — Demonstration Organization
Type
home health
Workforce size
22
Locations
2
States
ME, NH
HIPAA entity status
covered entity
05 — Executive summary
Harborlight Home Health — Demonstration Organization is a home health agency with a workforce of about 22. Based on reviewer-approved answers across the CuraDefend control library, its Protection Readiness Score is 67 (Developing), and its current overall risk level is High. The assessment identified 5 high, 2 moderate, and 1 improvement findings that remain open or otherwise unresolved. The strongest areas today are workforce security and identity and access. The areas needing the most attention are AI and shadow technology and vendors and business associates. The highest-priority work is: “BAA coverage is incomplete or unknown”, “Staff have not been told the PHI-in-AI rule”, and “Personal-device and remote-work risks are uncontrolled”. The 30/60/90-day plan in this report sequences that work. A CuraDefend Protection Readiness Score is not a measurement or certification of legal compliance.
06 — Protection Readiness Score
Developing
Domain
Weight
Score
GOVGovernance and Risk Management
2000%
75
IAMIdentity and Access
1500%
77
DEVDevices and Remote Workforce
1500%
65
RECData Protection and Recovery
1500%
58
WRKWorkforce Security
1000%
80
VENVendors and Business Associates
1000%
56
INCIncident Readiness
1000%
68
AIAI and Shadow Technology
500%
35
A CuraDefend Protection Readiness Score is not a measurement or certification of legal compliance.
07 — Domain detail
Governance and Risk Management
75
7 controls · avg maturity 2.9/4
Identity and Access
77
6 controls · avg maturity 3.0/4
Devices and Remote Workforce
65
7 controls · avg maturity 2.6/4
Data Protection and Recovery
58
6 controls · avg maturity 2.3/4
Workforce Security
80
5 controls · avg maturity 3.0/4
Vendors and Business Associates
56
6 controls · avg maturity 2.2/4
Incident Readiness
68
6 controls · avg maturity 2.5/4
AI and Shadow Technology
35
5 controls · avg maturity 1.4/4
08 — Risk overview
Overall risk level: High — determined by the highest-severity unresolved finding.
0
Critical
5
High
2
Moderate
1
Improvement
Counts include open, in-remediation, accepted, and deferred findings. Verified and closed findings are listed in section 10 but no longer count toward overall risk.
09 — Top priorities
01 · CD-F-00003 · VEN-002
High
BAA coverage is incomplete or unknown
Cross-check the vendor inventory against signed BAAs. For each gap, obtain a BAA or stop the PHI flow — and record legal review where the business-associate question is unclear.
02 · CD-F-00006 · AI-003
High
Staff have not been told the PHI-in-AI rule
Issue an unambiguous rule — no PHI in any AI tool unless that tool has been approved with a BAA in place — and repeat it in training and reminders.
03 · CD-F-00001 · DEV-006
High
Personal-device and remote-work risks are uncontrolled
Decide and document your rules for personal devices and remote work — required protections, prohibited storage, and what happens when a device is lost or someone leaves.
04 · CD-F-00002 · REC-002
High
Backups exist but restore capability is unproven
Schedule a restore test: recover a real file or dataset from backup, confirm it is usable, and record the date and result. Repeat on a recurring cadence.
05 · CD-F-00007 · AI-004
High
AI vendors handling PHI lack business-associate review
Before any AI tool touches PHI: confirm business-associate status, obtain a BAA, and review the vendor's data handling. No BAA, no PHI.
10 — Findings in detail
CD-F-00003 · control VEN-002 · L4 × I4 = 16
High
BAA coverage is incomplete or unknown
Business associate agreements are missing or unconfirmed for vendors that handle PHI.
Why it matters
PHI flowing to a vendor without a BAA is an ongoing impermissible disclosure — a compliance gap that exists every day the relationship continues.
Recommended action
Cross-check the vendor inventory against signed BAAs. For each gap, obtain a BAA or stop the PHI flow — and record legal review where the business-associate question is unclear.
Evidence expected: BAA tracking list showing agreement dates per vendor · Owner: Administrator
Current HIPAA Rule
CD-F-00006 · control AI-003 · L4 × I4 = 16
High
Staff have not been told the PHI-in-AI rule
Workforce members have not been specifically instructed when PHI may or may not enter AI tools.
Why it matters
Pasting a visit note into a public chatbot is a PHI disclosure to a vendor with no BAA — an innocent, common act with regulatory consequences.
Recommended action
Issue an unambiguous rule — no PHI in any AI tool unless that tool has been approved with a BAA in place — and repeat it in training and reminders.
Evidence expected: Staff communication or training slide stating the PHI-in-AI rule · Owner: Administrator
Current HIPAA RuleCuraDefend Practice
CD-F-00001 · control DEV-006 · L4 × I3 = 12
High
Personal-device and remote-work risks are uncontrolled
BYOD and remote work happen without documented, communicated controls.
Why it matters
Ungoverned personal devices and home setups move ePHI outside every safeguard the agency has built, invisibly and by default.
Recommended action
Decide and document your rules for personal devices and remote work — required protections, prohibited storage, and what happens when a device is lost or someone leaves.
Backups are configured, but no restore has been demonstrated recently — recovery is assumed, not known.
Why it matters
Restore failures are discovered at the worst possible moment; an untested backup provides confidence without protection.
Recommended action
Schedule a restore test: recover a real file or dataset from backup, confirm it is usable, and record the date and result. Repeat on a recurring cadence.
Evidence expected: Note or screenshot from the most recent successful restore test · Owner: IT support
Addressable HIPAA SpecificationHHS Guidance
CD-F-00007 · control AI-004 · L3 × I4 = 12
High
AI vendors handling PHI lack business-associate review
AI services that would handle PHI are adopted without business-associate evaluation and BAAs.
Why it matters
An AI scribe or transcription vendor processing encounters is very likely a business associate; using it without a BAA is a structural HIPAA gap, not an edge case.
Recommended action
Before any AI tool touches PHI: confirm business-associate status, obtain a BAA, and review the vendor's data handling. No BAA, no PHI.
Evidence expected: BAA or vendor-review record for any AI tool touching PHI · Owner: Administrator
Current HIPAA Rule
CD-F-00005 · control AI-002 · L3 × I3 = 9
Moderate
No AI-tool policy (approved / conditional / prohibited)
There is no policy telling staff which AI tools are approved, conditional, or prohibited.
Why it matters
Without stated rules, each employee improvises their own AI policy — and the strictest written ban loses to the most convenient unwritten habit.
Recommended action
Publish a one-page AI policy with approved, conditional, and prohibited lists, and a simple path for staff to request a new tool.
Evidence expected: AI-tool policy or approved/conditional/prohibited list · Owner: Administrator
NIST GuidanceCuraDefend Practice
CD-F-00008 · control AI-005 · L2 × I3 = 6
Moderate
AI use cases are adopted without risk review
New AI use cases enter operations without privacy, security, or human-impact review.
Why it matters
AI failures in care settings are quiet — a wrong summary, an unchecked draft; a short pre-adoption review keeps a human responsible for every consequential output.
Recommended action
Adopt a short AI review: intended use, data involved, failure modes, human review of output, and who approved it. File one per adopted tool.
Evidence expected: Completed AI use-case review note · Owner: Administrator
NIST GuidanceCuraDefend Practice
CD-F-00004 · control INC-006 · L2 × I2 = 4
Improvement
The response process has never been tested
The incident-response process has not been exercised or reviewed against a realistic scenario.
Why it matters
Plans fail at the seams — the phone number that changed, the backup nobody can find — and a 30-minute tabletop finds those seams before an incident does.
Recommended action
Run a short tabletop exercise on one realistic scenario, note what stumbled, and fix the procedure. Repeat yearly.
Evidence expected: Note from the most recent tabletop or plan review · Owner: Security official
HHS Cybersecurity GoalCuraDefend Practice
11 — Accepted and deferred risks
No risks have been formally accepted or deferred for this assessment.
12 — The 30 / 60 / 90-day plan
Sequenced by severity and dependency — critical work is never postponed to balance the chart. Each action names an owner role, the evidence that will demonstrate completion, and whether CuraDefend verification is required before it closes.
Now — first 30 days
Action
Owner
Evidence expected
Due
CD-F-00003BAA coverage is incomplete or unknownverify
Administrator
BAA tracking list showing agreement dates per vendor
Sep 13
CD-F-00006Staff have not been told the PHI-in-AI ruleverify
Administrator
Staff communication or training slide stating the PHI-in-AI rule
Sep 13
CD-F-00002Backups exist but restore capability is unprovenverify
IT support
Note or screenshot from the most recent successful restore test
AI-tool policy or approved/conditional/prohibited list
Oct 13
Build — days 61–90
Action
Owner
Evidence expected
Due
CD-F-00008AI use cases are adopted without risk review
Administrator
Completed AI use-case review note
Nov 12
CD-F-00004The response process has never been tested
Security official
Note from the most recent tabletop or plan review
Nov 12
13 — Evidence summary
Founder verified3
Attested2
CuraDefend verifies evidence primarily by reviewer examination without retaining files. Verified evidence carries a review date; past it, the state becomes stale and the item resurfaces in Monitor.
14 — Control matrix
Control
Importance
Maturity
Evidence
GOV-001Security responsibility is formally assigned to a specific individual or role.
●●
●●●●3/4
not provided
GOV-002A documented security risk analysis has been completed and is maintained.
●●●
●●●●4/4
founder verified
GOV-003The organization has identified where ePHI is created, received, maintained, and transmitted.
●●●
●●●●3/4
not provided
GOV-004An active risk-management and remediation plan exists with owners and target dates.
●●●
●●●●3/4
not provided
GOV-005Security policies are documented, available, and periodically reviewed.
●●
●●●●3/4
not provided
GOV-006Security is reevaluated when technology, vendors, locations, or operations materially change.
●●
●●●●2/4
not provided
GOV-007Required security documentation and historical records are retained appropriately.
●
●●●●2/4
not provided
IAM-001Workforce members use unique accounts where technically supported.
●●
●●●●3/4
not provided
IAM-002Access is granted according to role and business need.
●●●
●●●●3/4
not provided
IAM-003Appropriate MFA is deployed for remote, cloud, email, and privileged access.
●●●
●●●●4/4
founder verified
IAM-004Privileged or administrator accounts are appropriately separated from routine activity.
●●
●●●●3/4
not provided
IAM-005Access is promptly removed when workforce members leave or no longer require it.
●●●
●●●●3/4
not provided
IAM-006Access rights and relevant system activity are periodically reviewed.
●●
●●●●2/4
not provided
DEV-001The organization maintains an inventory of devices capable of accessing ePHI.
●●
●●●●3/4
not provided
DEV-002Workstation use and physical-security expectations are documented and implemented.
●●
●●●●3/4
not provided
DEV-003Laptops and mobile devices are protected or encrypted based on documented risk analysis.
●●●
●●●●3/4
attested
DEV-004Endpoints are protected against malware and common threats.
●●
●●●●3/4
not provided
DEV-005Operating systems and software are updated, and known vulnerabilities are addressed.
●●
●●●●2/4
not provided
DEV-006Personal-device, BYOD, and remote-work risks are controlled.
●●
●●●●1/4
not provided
DEV-007Devices and media are securely disposed of or sanitized before reuse.
●●
●●●●3/4
not provided
REC-001Critical ePHI is backed up through documented procedures.
●●●
●●●●3/4
not provided
REC-002The organization has demonstrated that critical backups can be restored.
●●●
●●●●0/4
not provided
REC-003Disaster-recovery and emergency-mode procedures are established.
●●●
●●●●3/4
not provided
REC-004ePHI is appropriately protected during electronic transmission.
●●●
●●●●3/4
not provided
REC-005Controls protect ePHI integrity against inappropriate alteration or destruction.
●●
●●●●3/4
not provided
REC-006Critical systems and processes are identified for continuity and recovery priorities.
●●
●●●●2/4
not provided
WRK-001New workforce members receive appropriate security training.
●●●
●●●●4/4
founder verified
WRK-002Security awareness is reinforced after onboarding and when risks change.
●●
●●●●3/4
not provided
WRK-003Appropriate sanctions exist for security or privacy policy violations.
●●
●●●●3/4
not provided
WRK-004Workforce education addresses phishing, credential theft, and common cyber threats.
●●
●●●●3/4
not provided
WRK-005Workforce members acknowledge relevant security responsibilities and policies.
●
●●●●2/4
not provided
VEN-001A current inventory exists for vendors that create, receive, maintain, or transmit PHI or ePHI.
●●●
●●●●3/4
not provided
VEN-002Appropriate BAAs are present for applicable business-associate relationships.
●●●
●●●●2/4
not provided
VEN-003Privacy and security risk are considered before new vendors are approved.
●●
●●●●2/4
not provided
VEN-004Applicable vendor arrangements address incident and security reporting responsibilities.
●●
●●●●2/4
not provided
VEN-005Data and system access are handled appropriately when a vendor relationship ends.
●●
●●●●2/4
not provided
VEN-006Vendors are reviewed when services, systems, or risks materially change.
●
●●●●2/4
not provided
INC-001A written security-incident response procedure exists.
●●●
●●●●3/4
attested
INC-002Workforce members know how and where to report suspected incidents.
●●●
●●●●3/4
not provided
INC-003Security incidents and outcomes are documented.
●●
●●●●3/4
not provided
INC-004An escalation process exists for incidents that may involve PHI.
●●●
●●●●3/4
not provided
INC-005Response roles and important internal and external contacts are identified.
●●
●●●●2/4
not provided
INC-006The organization has tested or reviewed its response process.
●
●●●●1/4
not provided
AI-001The organization knows which generative-AI and AI-enabled services its workforce uses.
●●
●●●●2/4
not provided
AI-002An approved, conditional, and prohibited AI-tool policy exists.
●●
●●●●1/4
not provided
AI-003Workforce members are instructed when PHI may or may not be entered into AI systems.
●●●
●●●●1/4
not provided
AI-004Business-associate status and BAA needs are evaluated when an AI vendor handles PHI.
●●●
●●●●2/4
not provided
AI-005AI use cases are reviewed for privacy, security, operational, and human-impact risks before adoption.
●●
●●●●1/4
not provided
15 — Sources and classifications
Each control in this report is tagged with its sources. Badges mean exactly this:
Current HIPAA Rule
Addressable HIPAA Specification
HHS Guidance
HHS Cybersecurity Goal
NIST Guidance
CuraDefend Practice
Proposed — Not Current Lawnever scored as current law
16 — What happens next
Your 30/60/90-day plan is live in the CuraDefend portal. Each action can be worked, completed, and — where marked — verified by your reviewer. With CuraDefend Monitor, completed work carries a reverification schedule, evidence ages honestly, and accepted risks return for reconsideration on their review dates.
A reassessment is recommended annually, or after significant change: new locations, new systems, workforce growth, or an incident.
Scores are deterministic: identical reviewed answers always produce identical results. This report is frozen as of its issuance date and is never recalculated retroactively. Full formulas are published at curadefend.com/methodology.
18 — Disclaimers
CuraDefend provides organizational risk, security, and compliance-support services. CuraDefend assessments and scores are informational risk-management tools and do not constitute legal advice, regulatory certification, or a guarantee of HIPAA compliance.
A CuraDefend Protection Readiness Score is not a measurement or certification of legal compliance.
This report is not legal advice and does not determine whether any breach, violation, or reportable event has occurred. CuraDefend is not affiliated with or endorsed by any government agency. Findings reflect information provided by the organization during the assessment period; conditions may have changed since issuance.
CD-PA-000001 • Assessment v1.0 • Control Library 2026.08 · CuraDefend is operated by Psalm Wave LLC.