A Fortify 24x7 brand. Plating over the equipment that holds patient records.Client sign inAsk an engineer
Patient Data Armor
Plate 06 / Field plating

The tablet in room three is a computer, and nobody has looked at it since March.

Plating only helps across the surface it actually covers. This layer is the unglamorous business of knowing every machine the practice owns, keeping each one current, deciding where it may go, running Apple hardware as Apple meant it, and putting something on the phones people read charts from in a car park. Four lines, and they are what stops the other five having holes behind them.

N-able N-sightAddigyZimperium
4 lines / Windows, Apple and handsets / per device
Lines here4
Built byN-able N-sight, Addigy, Zimperium
Counted inDevices
CoversDesktop, laptop, tablet, phone

Updating is dull and it decides everything

What gets exploited in a clinic is nearly always old and publicly documented. A desktop eight weeks behind. A browser nobody closes because the schedule is always open on it. An operating system that went out of support while everybody had other things on. N-sight carries the monitoring, the updating, the scripting and the remote sessions on one agent, and it produces the equipment list every cyber insurance questionnaire eventually demands.

Name filtering rides along on that agent. Nothing extra gets racked in a supply closet and no traffic takes a detour, which matters in a building where the network cupboard doubles as storage for printer paper.

Manufacturer locked clinical equipment generally cannot take an agent of any kind.

Apple and handsets: separate work, honestly priced

A Mac at reception and an iPad in an operatory are not Windows machines with different keyboards. Addigy runs them the way Apple designed them to be run, with proper enrollment, configuration profiles and control over when releases land. Zimperium lives on the handset itself, hunting hostile applications, unsafe networks and phishing that arrives through channels never touching your mail tenant.

One thing we would rather say here than let you find out later: manufacturer locked clinical equipment generally cannot take an agent of any kind. Imaging modalities, chairside units and lab analysers arrive sealed, and what protects them is being fenced off and watched from outside.

Lines on this plate

Specifications and rates

Every figure below arrives from the billing system while this page opens. Whatever you add sits waiting in the panel while you keep reading.

Fortify-RMMSpecification

Remote Monitoring and Management

N-able N-sight, driven by our engineers

Watching, updating, scripting and remote sessions across the machines your practice depends on. The equipment list this produces happens to answer most of a cyber insurance questionnaire, which is a useful thing to get for free.

  • Operating system and application updates on a rhythm that fits clinic hours.
  • Health checks on disks, services and the things that fail without announcing it.
  • Remote sessions, so a stuck machine does not require somebody driving over.
Built onN-able N-sight
Runs onWindows, macOS and Linux
CarriesWatching, updating, scripting, remote sessions
ProducesAn equipment list you can send to an insurer
TimingWorked around the appointment book wherever possible
Counted inManaged devices, monthly
Fetching the rateper managed device
taken monthly, up front
QTY
Fortify-RMM-DNSSpecification

Web and DNS Filtering

N-able N-sight, with filtering on the very same agent

Name lookups filtered at the machine, so it cannot reach known hostile infrastructure whether it is sitting in your building or on somebody's home broadband. No appliance, no diverted traffic, no extra box in the cupboard.

  • Blocking applied at the machine, so it goes with a laptop out of the building.
  • Category rules you can set one way for clinical staff and another for reception.
  • A record of what got blocked, useful the day somebody wants to know why.
Built onN-able N-sight
MethodFiltering at name lookup, on the machine itself
TravelsYes, the rules apply away from the practice network
RulesBy category, set per group of staff
RequiresThe monitoring line, on that same machine
Counted inManaged devices, monthly
Fetching the rateper managed device
taken monthly, up front
QTY
Fortify-ControlSpecification

Apple Fleet Management

Addigy, for Macs and iPads

Apple hardware run the way Apple intends: enrollment, configuration profiles, control over releases, and software pushed out centrally. For a practice with Macs at the desk and iPads in the rooms, this is what turns a heap of personal feeling devices into something managed.

  • Enrollment and profiles applied without anybody handling each device.
  • Release control, so a major update never arrives in the middle of clinic.
  • Software and settings pushed to Macs and iPads under one set of rules.
Built onAddigy
Runs onmacOS, iPadOS and iOS
CarriesEnrollment, profiles, release control, software delivery
SuitsPractices with Macs at the desk and iPads in the rooms
Goes withHandset defense on the same hardware
Counted inApple devices, monthly
Fetching the rateper Apple device
taken monthly, up front
QTY
Fortify-MobileSpecification

Mobile Threat Defense

Zimperium, running on the handset

Judgment made on the phone, without traffic being shipped anywhere to be examined. Providers read mail and check schedules on phones constantly, and a handset on a hostile network is a route into everything that account can open.

  • Hostile and risky applications caught on the device itself, not in a console.
  • Warnings about unsafe networks, which is what hotel and airport wifi often is.
  • Phishing arriving by text or chat, well outside your mail tenant.
Built onZimperium
Runs oniOS and Android
MethodJudgment on the handset, no traffic diverted
CatchesApplications, networks, device state, bad links
PrivacyDesigned for personally owned handsets as well as issued ones
Counted inMobile devices, monthly
Fetching the rateper mobile device
taken monthly, up front
QTY
Material limits

Where the field plating gives out

Fleet work is where the honest conversation about clinical hardware belongs, so here it is at full length.

  • Sealed clinical equipment takes no agent. Imaging modalities, chairside units, lab analysers, infusion hardware and their relatives are locked by whoever built them, and putting software on one can breach a support contract or a regulatory clearance. What protects them is being fenced off and watched from the network, which is design and monitoring work, not something you add to a basket.
  • Updating cannot rescue software the vendor walked away from. Where a practice management or imaging application pins an ancient operating system, no update rhythm fixes it. That becomes an isolation project and a difficult conversation with the vendor, and we would sooner say that than sell a subscription papering over the hole.
  • Personally owned devices count only once enrolled. A phone or a home machine outside enrollment cannot be seen by anything here. Whether you require enrollment is a policy your practice writes, not a switch we can throw for you.
  • Name filtering is not a firewall. Blocking by name stops a great deal of ordinary traffic heading somewhere bad. It is not perimeter design, it is not segmentation, and it does not replace the equipment that keeps a clinical network apart from a guest one.
  • An equipment list is evidence, not compliance. The inventory answers questions from insurers and auditors. It is not your risk analysis and it does not make anybody HIPAA compliant.
BILLING

Heads up: card statements show FORTIFY 24X7 - Patient Data Armor is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.