Your HVA Is Read Once a Year. The Hazards on It Are Live the Other 364 Days.
A hazard vulnerability analysis is a spreadsheet with a row per hazard and seven columns: probability, then human, property and business impact, then preparedness, internal response and external response. Each cell is rated 0 to 3, three of the columns run backwards, and the last column is a relative risk worked out from the others. It is the document a surveyor reads once a year, and for most facilities it is the same document as last year with the date changed.
That is not laziness. It is that six of the seven columns are judgments about your building that no outside record holds, and the seventh — probability — is usually filled from memory because looking it up is tedious. We built the tool around that split.
One column from the record, six from you
Calchis keeps one analysis per site, 52 hazards across the four categories a surveyor expects: natural, technological, human and hazardous materials. The probability column is pre-filled from the county's federal record: every NOAA storm event since 1996, every FEMA disaster declaration since 1953, and the basis printed beside the number. A hospital in Miami-Dade County sees, next to "Hurricane / Tropical Storm," that the county has 88 NCEI hurricane events over 31 years and 24 federal declarations naming it, and a probability of 3 with the rule that produced it. A hospital in Fort Drum, New York sees a different number and a different basis.
The other six columns are left blank on purpose. Whether a generator failure is a business-impact 3 for your building is your judgment, and a document that guessed it would be worth less than one that did not. A blank is not a zero: a row with any blank is not scored, the summary counts only the rows you rated, and it prints the denominator.
Four things the tool refuses to do
It never stores a relative risk. The number is recomputed from the seven ratings every time it is shown, so there is no way for a stale percentage to survive a changed rating. It never averages across buildings: a system with three sites gets three analyses and a rollup that says which hazards each site put at the top, not a blended score that describes none of them. It freezes the ratings when the analysis is approved, with the approver's name and date, because a rating changed after sign-off is a different assessment. And it does not freeze the action plan — the assessment is signed off so the work can happen, and a plan that could not record that the work was done would be furniture.
Year to year, the tool shows what changed since the previous analysis, offers last year's ratings as a starting point for rows you have not touched, takes the spreadsheet in and out as CSV, and prints the document with its sources, its rating scale and its approval block. Whether that document satisfies the CMS Emergency Preparedness Rule is your finding and your surveyor's. It is built to the all-hazards structure surveyors expect; that is the claim, and the whole of it.
The other 364 days
Here is the part a spreadsheet cannot do. The hazards you rated moderate or high name the federal products that would activate your emergency plan. Rate "Temperature Extremes" high and the plan triggers are the NWS Extreme Heat Watch, Extreme Heat Warning and Heat Advisory covering your area. Rate flooding high and they are the flood watch and the flood warning inside it. Hurricane: the NHC forecast cone covering the site, then the watch, then the warning. Those become conditions the site is watched for, evaluated once a minute against the live feed, and a condition that is met puts a banner on every screen until someone acknowledges it, with a tone if you want one.
The document also watches its own calendar. Every Monday a digest goes to the account: which analyses have a review date inside the next 45 days, which mitigation actions are overdue, and at which sites. It is the only thing in the product that reports on dates the facility set rather than on something happening outside.
A sample you can open
The Facilities page carries a complete sample analysis for a Lee County, Florida site as a PDF anyone can open without an account, so a compliance director can read exactly what the surveyor would be handed before adding a single building. The numbers in it come from the federal record and can be checked against it. That is the standard we hold the rest of the product to, and it is the reason the probability column is the only one we fill.
Related Articles
Decision-support intelligence — not a primary alerting or dispatch system. Verify against official sources. All data referenced in this article is sourced from publicly available federal agencies and peer-reviewed publications.