Patient detail refuses to stay filed. Somebody exports it to fight an appeal, carries it on a laptop to a home visit, or drops it onto a shared drive at speed. None of that is wrongdoing. It is only why any control here has to begin from a truthful map.
Every practice believes its patient data lives inside the practice management system. Every practice is partly mistaken. Somewhere there is a folder of scanned referrals, a workbook assembled during a claims dispute two years ago, an export left in a downloads folder after a migration, and an image set copied onto a drive the week the network crawled.
Discovery reads the devices in scope and reports what is actually there, in records and locations rather than as a single abstract score. That output is uncomfortable and it is the most useful thing on this page, because it turns a risk analysis from an interview into an inventory.
The instinct after a discovery report is to ban exports. That instinct fails, because the export existed for a reason and the reason has not gone away. The second line encrypts files carrying sensitive material where they sit and governs the routes a copy may take out of the practice, so the workflow survives and the exposure does not.
Profiles can be shaped around the obligations your organization is genuinely under, which in healthcare is rarely just one thing. Federal expectations, state health privacy law, payment card rules where you take cards, and whatever your cyber insurer has written into the renewal all pull in slightly different directions.
Both figures come live from billing. Most practices start with discovery on its own and add enforcement once they have seen the report.
You cannot protect a file whose existence nobody has established. This line reads the machines in scope and reports where patient detail, payment card data and other sensitive material actually sits, including the exports and copies that never made it into any system of record.
| Cut for | Any device you suspect is carrying copies of patient records |
|---|---|
| Turns on | Actifile |
| Held in | Findings and risk reporting in the Actifile tenant raised for you |
| Rekeyed | Scans repeat on a schedule, because copies keep being made |
| Master level | Fortify 24x7 goes through the findings alongside you and settles what follows |
Discovery reports where the records travelled. This line acts upon that report. Anything holding sensitive material gets encrypted where it lies, and the routes a copy might take out of the practice come under rules rather than under habit.
| Cut for | Devices where sensitive files must not travel unprotected |
|---|---|
| Turns on | Actifile |
| Held in | Policy and enforcement records in the Actifile tenant |
| Rekeyed | Rules revised when a workflow changes rather than after somebody trips over one |
| Master level | Fortify 24x7 authors the profiles and works the exceptions |
Governing data is the part of a program where overpromising is most tempting and most damaging. Here is the boundary.
Heads up: card statements show FORTIFY 24X7 - Health Lock Solutions is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.