A Fortify 24x7 brand. Plating over the equipment that holds patient records.Client sign inAsk an engineer
Patient Data Armor
Plate 04 / Hard plate

Nothing runs on the charting machine without somebody having approved it.

The layer above watches for trouble. This one removes the chance of it. Rather than keeping a list of forbidden things and praying the list keeps pace, the machine holds a roster of what may run on it, and whatever is missing from that roster is turned away. One line on this sheet, and on the machines that reach records it shifts the odds further than anything else we sell.

ThreatLockerRefuse by defaultApprovals worked by us
1 line / roster plus ringfence / per endpoint
Lines here1
Built byThreatLocker
Counted inEndpoints
ApprovalsHandled at our desk

Watching first, refusing second

Clinics run stranger software than most offices do. A viewer built for an imaging unit in 2014. A claims utility the clearinghouse will not work without. A driver bundle for a chairside scanner. A practice management suite whose updates nobody has ever documented. Switching refusal on from a cold start would break half of that before the first patient arrives, so we never do it that way. The agent observes for a while, assembles the roster from what your people genuinely open, and only afterwards does anything begin getting turned away.

With it live, releases from your vendors are followed, so a routine update does not leave a hygienist locked out of the chart at eight. When something genuinely new does need clearing, the request reaches our engineers rather than whoever at your practice happens to be standing closest to the phone.

Most damage now travels inside software you already cleared and would clear again tomorrow.

Ringfencing, which is the half nobody mentions

A roster settles whether a program may start. A ringfence settles what that program may then get up to: which other programs it may open, which folders it may read, and which addresses it may talk to. The distinction earns its keep because most damage now travels inside software you already cleared and would clear again tomorrow.

In practice this means a document viewer opens documents and cannot start a command prompt, and a scanning utility writes into its own folder without ever browsing the share where the record archive lives.

Lines on this plate

Specifications and rates

Every figure below arrives from the billing system while this page opens. Whatever you add sits waiting in the panel while you keep reading.

Fortify-ZeroTrustSpecification

Execution Control

ThreatLocker, with our engineers taking requests

A roster of permitted software, with ringfencing and elevation handling, on whichever machines you nominate. Observation first, refusal afterwards, and a genuine human at the far end of every request, so the control does not become the obstacle your staff learn to walk around.

  • An observation period assembles the roster from software your practice opens.
  • We follow vendor releases, so an update never stalls the schedule.
  • Elevation requests and escalations are dealt with by Fortify 24x7 engineers.
Built onThreatLocker
MethodPermitted roster, ringfencing, elevation handling
Runs onWindows and macOS
ApprovalsRequests reach our desk, day or night
SuitsCharting, imaging, billing and reception machines
Counted inEndpoints, monthly
Fetching the rateper endpoint
taken monthly, up front
QTY
Material limits

Where the hard plate gives out

Refusing by default is the single strongest control on this storefront, and it still has edges, which are worth understanding before you buy it.

  • Cleared software can still be turned against you. A permitted program in the hands of somebody with legitimate access is doing exactly what clearance allowed. A ringfence narrows that, supervision narrows it further, and neither of them removes it.
  • It reaches nothing you cannot install on. Sealed clinical hardware, vendor operated appliances and anything under a contract forbidding third party software all fall outside this line. What protects those is separating them on the network, which is design work rather than a subscription.
  • Browsers and cloud applications are a separate problem. Something running inside a browser tab is not a program the operating system was asked to start. Mail cover, identity settings and the record seal lines are where that risk gets addressed.
  • It is not a license audit. The roster records what may execute. Reconciling that against what your practice actually paid a vendor for is procurement work, and we will hand over the list rather than pretend the two questions are the same one.
  • Nothing here makes a practice HIPAA compliant. Controlling access is one technical safeguard out of many, and a compliance program is assembled from risk analysis, written policy, training and documentation that remain yours to own. This line holds up part of that program. It never stands in for having one.
BILLING

Heads up: card statements show FORTIFY 24X7 - Patient Data Armor is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.