A Fortify 24x7 brand. Plating over the equipment that holds patient records.Client sign inAsk an engineer
Patient Data Armor
Plate 07 / Record seal

You cannot govern a folder of records nobody has found yet.

Every practice we have examined holds patient data somewhere it never meant to: a batch of scans on a desktop, an extract somebody produced for an audit in 2021, a spreadsheet of balances with dates of birth sitting in column D. Two lines here. The first goes looking and comes back with a number. The second decides what may happen to whatever was found.

ActifileLook firstThen encrypt and restrict
2 lines / find, then rule / per device
Lines here2
Built byActifile
Counted inDevices
OrderLook first, rule afterwards

A search gives the work an order

Sweeping machines and shares for regulated material hands a practice something it rarely has: a ranked list. Not a general unease about patient data, but a specific statement that the reception desktop is holding nine thousand records in scanned batches while the laptop in the back office holds forty in an old extract. Ranking by exposure is what converts an uncomfortable subject into a plan with an obvious first job.

Scoring also produces something a carrier will accept. Cyber insurance questionnaires now want to know how much regulated data you keep and where it sits, and replying with a measurement instead of a guess changes the tone of that conversation considerably.

Ranking by exposure converts an uncomfortable subject into a plan with an obvious first job.

Rules on the routes data really uses

Once the material has been located, the second line takes over: encryption applied to what is sensitive, and rules on the ways data leaves, which inside a clinic means memory sticks, personal cloud accounts and outbound mail far more often than anything ingenious.

We would rather be direct about the sequence. Enforcing without searching first means writing rules over ground nobody measured, and that ends either in a control everybody routes around or in one that halts clinical work. Search first. Every time.

Lines on this plate

Specifications and rates

Every figure below arrives from the billing system while this page opens. Whatever you add sits waiting in the panel while you keep reading.

Fortify-DLP-ClassifySpecification

Sensitive Data Discovery

Actifile, sweeping machines and shares

Goes looking for regulated and sensitive material across whatever you enroll, works out which category it falls into, counts it, and scores each machine so that remediation has somewhere obvious to begin.

  • Sweeps machines and file shares for health, financial and identity material.
  • Counts what turns up, so the answer is a figure rather than an impression.
  • Scores exposure per machine, which is what puts the remediation in order.
Built onActifile
ExaminesMachines and the file shares attached to them
FindsHealth, financial and identity material sitting at rest
ProducesRecord counts plus a per machine score
Handy forInsurance questionnaires and scoping your own risk analysis
Counted inDevices, monthly
Fetching the rateper device
taken monthly, up front
QTY
Fortify-DLP-EnforceSpecification

Encryption and Channel Control

Actifile, acting on whatever the search turned up

Encryption over sensitive files, plus rules on the routes data uses to leave. Meant to run after the search, so the rules are written against ground that somebody has genuinely measured.

  • Encryption over sensitive files, so a lost laptop becomes a smaller event.
  • Rules covering memory sticks, personal cloud accounts and outbound routes.
  • A record of movement, which is the part every investigation wants later.
Built onActifile
DoesEncryption at rest and rules over the exit routes
RoutesMemory sticks, personal cloud accounts, outbound mail
OrderRuns after the search, over measured ground
SuitsPractices carrying records on hardware that travels
Counted inDevices, monthly
Fetching the rateper device
taken monthly, up front
QTY
Material limits

Where the record seal gives out

Data protection is the layer most frequently oversold, so this list runs longer and blunter than the others.

  • Nothing here makes a practice HIPAA compliant. Encrypting and searching are technical safeguards. A compliance program is risk analysis, written policy, workforce training, business associate agreements and documentation, every one of which belongs to the covered entity. We hold up part of the program without ever becoming it.
  • Running the risk analysis is still your job. These lines produce measurements a risk analysis can be built from. They do not carry one out, put a name to one, or discharge the requirement that one exists.
  • Somebody entitled to a record can walk off with it. A person allowed to open a chart may decide to keep a copy. Rules on the exit routes narrow the options and record the movement. Employment agreements, access review and the offboarding checklist are what address intent.
  • The search covers what it can reach. Material held inside a practice management database, on a vendor hosted platform, or on a system nobody enrolled will not be swept. The report names the ground it covered, and reading that line beats assuming everything was inside.
  • Deciding on a breach is not ours to do. When something moves, you get the facts and the sequence. Whether notification is owed, to whom, and by when, is worked out by your practice with your counsel.
BILLING

Heads up: card statements show FORTIFY 24X7 - Patient Data Armor is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.