Your compliance score (0–100, graded A–F) is a single, weighted read on how your HIPAA program is doing right now. It's computed live across five dimensions:
The org-wide score above is separate from the score on an individual assessment, which is simply the share of applicable questions you answered Yes.
Questions you mark N/A are excluded from the score entirely — they leave both the top and the bottom of the fraction. A question that doesn't apply to you isn't a partial failure, so it shouldn't pull your score down. If your assessment has 130 questions and 40 genuinely don't apply to your organization, your score is measured out of the 90 that do.
This is why marking N/A honestly matters in both directions: marking something N/A that does apply hides a real gap, and answering No to something that doesn't apply understates a program that's actually in good shape. The platform requires a note when you mark a question N/A so the reasoning is on the record for an auditor.
Changed 25 July 2026. N/A answers previously counted as half credit and
stayed in the denominator, which understated any organization with a
meaningful number of inapplicable questions. Scores computed after this change
may be higher than before for the same answers. Nothing about your answers or
your findings changed — only how N/A is counted.
Once a day a snapshot of your score is recorded. Score History shows today's score immediately, plus a 90-day trend chart once a few days of snapshots have accrued. The trend is org-wide and continuous — distinct from the per-assessment score, which is recorded only when an assessment is completed.
If your score drops by 5 or more points versus the previous snapshot, your org admins are notified (the alert names which dimensions regressed). This is the "3 controls slipped this quarter" early-warning — catch a regression before an auditor does. The alert respects the weekly-digest notification preference.
Reports → Gap Analysis turns the score into a work list. Pick a target (default A / 90) and the report shows every program dimension and assessment category that's below it — worst gap first — with the points-to-target and a concrete next action for each ("resolve the open findings", "answer the 4 remaining Security questions and remediate the gaps", "get a BAA on file"). It's deterministic (no AI): program scores come from findings, policies, training, incidents, and BA coverage; category scores come from your assessment answers. When nothing is below target, it says so.