Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

System · Live Diagnostics

One number. Always current. Always defensible.

A single composite score across every module on the platform. Updated in real time. Present it to auditors, board members, your team — it's always now.

Included in Core·Starting at $39/mo
Patient Protect — Live Diagnostics
Patient Protect Live Diagnostics dashboard showing composite compliance score with category breakdown across all 20 modules and historical trend

HIPAA mapping

What this satisfies in the Security Rule.

3 citations, each with the specific Live Diagnostics behavior that satisfies it. The mapping is the receipt — what you can show an auditor without assembling anything new.

§164.308(a)(1)

Security management process

The composite score is the visible expression of program state. Auditors evaluating the process see it at a glance.

§164.308(a)(8)

Evaluation

Continuous evaluation, not periodic. The score's history demonstrates ongoing assessment.

§164.316(b)(2)

Time limit (six-year retention)

Score history is retained with full granularity for the regulatory six-year window.

What it does

The number that's true now.

Compliance reporting traditionally answers “what was true at some point in the past.” Practices assemble status before audit, present it to a board, file it away. Between assemblies, no one knows the number.

Live Diagnostics flips that. The composite compliance score is always current — derived continuously from your SRA, your Advice queue, your workforce records, your audit log, your training completions, your BAA states. The number is what's true now. Show it to anyone, anytime.

The history is the second piece. The dashboard shows where you are now and where you've been — the practices that look strong on audit are the ones whose history shows steady improvement over months, not a heroic week before review.

How it works

5 mechanisms keep Live Diagnostics working.

01

One composite, many contributors.

The composite score aggregates twenty modules. Each module reports its own internal completeness. The composite weights them by regulatory significance. The dashboard shows both the composite and the contributing breakdown — useful for spotting which modules are pulling the number up or down.

02

Real-time updates.

Every state change in any module fires an update event. The dashboard receives updates within seconds. There is no batch job, no scheduled refresh, no “as of” date that's older than this morning.

03

Score history with full granularity.

Every score state is retained — daily snapshots, plus event-level granularity for material changes. The history view shows trend curves over 30, 90, and 365 days. Hover a point to see what specific events drove the score state at that moment.

04

Category breakdown by Security Rule structure.

Beyond the per-module breakdown, the score categorizes by Security Rule structure: Administrative Safeguards (§164.308), Physical Safeguards (§164.310), Technical Safeguards (§164.312). Auditors looking at specific categories see them isolated without losing the composite.

05

Export for board and auditor presentation.

The dashboard exports as PDF for board packets, as CSV for analytics, and as an audit-pack that includes the score plus its history plus the underlying contributing data. Boards get the headline number; auditors get the substantiating record.

Who this is for

Built for the practices that need it most.

Practice owners and operators.

The score is the answer to “how are we doing?” without a prep meeting or a status email chain. Pull up the dashboard, see where you stand, see what changed since last week.

Compliance leadership.

The Security Officer and Privacy Officer use the score as the working surface for the program. Movements in the score surface both wins (training completion bumps) and slippage (a BAA going expired before renewal). The dashboard makes both visible.

Boards and oversight committees.

Practice boards rarely want to read 30-page compliance reports. They want the number, the trend, and the brief on what changed. The dashboard exports a board-ready packet in one click.

Auditors and consultants.

External reviewers get a current view rather than a stale snapshot. The history view substantiates that the number is the result of continuous evaluation, not assembled-before-audit bookkeeping.

What you get

5outcomes you'll feel in week one.

One number, always current.

Composite compliance score, derived from twenty modules, updated in real time.

Trend visibility.

30-day, 90-day, 365-day views of where the program is going.

Category breakdown.

Administrative, Physical, Technical — matching auditor expectations.

Event-level attribution.

Every score change traces to a specific platform event.

Board-ready and audit-ready exports.

PDF for boards, audit-pack for OCR.

FAQ

What people ask first.

6 questions cover most first-time evaluations. See all FAQs →

What does a “good” score look like?
Most well-run independent practices on the platform settle in the 78–92 range as their working state, with movement up and down a few points week-to-week as work happens. Scores below 70 typically indicate something specific (a major SRA gap or a recent vendor relationship not yet papered) rather than overall program weakness.
Is the score gameable?
The contributing inputs are platform-observable behaviors — training completions, policy adoptions, BAA states, audit log patterns. Manipulating the score requires manipulating the underlying records, which is logged and visible. Practices that try to game scores typically produce telltale patterns (simultaneous completions, sudden BAA activations) that surface as anomalies.
Can I see what's pulling my score down?
Yes. The dashboard shows category-level breakdown and links to specific gaps. Click a category and see the open Advice items, unresolved SRA findings, or workforce gaps driving the sub-score.
What if I disagree with the weighting?
The weighting is documented and consistent across practices — intentionally not user-configurable so the score stays comparable across audits and across time. If you have feedback on weighting methodology, your account manager can route it; the methodology evolves periodically based on regulatory and enforcement patterns.
How does this differ from “Compliance Status: Yes/No”?
Compliance status is the question regulators ask in binary form (are you in compliance — yes or no). The score is the operational view that lets you see the spectrum and prioritize work toward yes.
Can I share the dashboard externally?
Read-only views can be granted to specific external parties (consultants, board members) with time-limited access. Auditors typically receive the audit-pack export rather than direct dashboard access.

Next step

See your composite score light up in 90 minutes.

Most practices have their first composite score within 90 minutes of starting. The trend line begins compounding from there.

No contracts. No consultants. Starting at $39/mo.