A Fortify 24x7 brand. Lock work for practices, clinics, and the offices that bill for them.Client sign inAsk a locksmith
Health Lock Solutions
Keyway 05 / Records, and where they travel

Draw the map first. Rule on what may leave second.

Patient detail refuses to stay filed. Somebody exports it to fight an appeal, carries it on a laptop to a home visit, or drops it onto a shared drive at speed. None of that is wrongdoing. It is only why any control here has to begin from a truthful map.

ActifileDiscovery before enforcementEncryption at the file
2 lines / discovery then enforcement / counted by device
Lines on this keyway2
PlatformActifile
Counted byEach device
SequenceMap first, rules after

The map comes before the lock

Every practice believes its patient data lives inside the practice management system. Every practice is partly mistaken. Somewhere there is a folder of scanned referrals, a workbook assembled during a claims dispute two years ago, an export left in a downloads folder after a migration, and an image set copied onto a drive the week the network crawled.

Discovery reads the devices in scope and reports what is actually there, in records and locations rather than as a single abstract score. That output is uncomfortable and it is the most useful thing on this page, because it turns a risk analysis from an interview into an inventory.

Discovery turns a risk analysis from an interview into an inventory.

Then govern the copies rather than forbidding them

The instinct after a discovery report is to ban exports. That instinct fails, because the export existed for a reason and the reason has not gone away. The second line encrypts files carrying sensitive material where they sit and governs the routes a copy may take out of the practice, so the workflow survives and the exposure does not.

Profiles can be shaped around the obligations your organization is genuinely under, which in healthcare is rarely just one thing. Federal expectations, state health privacy law, payment card rules where you take cards, and whatever your cyber insurer has written into the renewal all pull in slightly different directions.

Cut cards

Two cut cards, with live rates.

Both figures come live from billing. Most practices start with discovery on its own and add enforcement once they have seen the report.

Fortify-DLP-ClassifyCut card

Sensitive Data Discovery

Actifile, locating the records ahead of everything else

You cannot protect a file whose existence nobody has established. This line reads the machines in scope and reports where patient detail, payment card data and other sensitive material actually sits, including the exports and copies that never made it into any system of record.

  • Discovery across local drives and the file locations people genuinely use.
  • Risk reporting expressed in records and locations rather than in an abstract score alone.
  • Gives a risk analysis something factual to work from instead of an interview and a hunch.
P15P24P33P42P51
Cut forAny device you suspect is carrying copies of patient records
Turns onActifile
Held inFindings and risk reporting in the Actifile tenant raised for you
RekeyedScans repeat on a schedule, because copies keep being made
Master levelFortify 24x7 goes through the findings alongside you and settles what follows
Readingper device
billed monthly, in advance
QTY
Fortify-DLP-EnforceCut card

Encryption and Channel Control

Actifile, holding the copies to your rules

Discovery reports where the records travelled. This line acts upon that report. Anything holding sensitive material gets encrypted where it lies, and the routes a copy might take out of the practice come under rules rather than under habit.

  • Encryption applied to the files that matter, without asking staff to remember a step.
  • Channel rules for the applications people use to move things around.
  • Profiles that can be shaped around the obligations your organization is actually under.
P13P22P31P45P52
Cut forDevices where sensitive files must not travel unprotected
Turns onActifile
Held inPolicy and enforcement records in the Actifile tenant
RekeyedRules revised when a workflow changes rather than after somebody trips over one
Master levelFortify 24x7 authors the profiles and works the exceptions
Readingper device
billed monthly, in advance
QTY
Honest scope

What this cut does not open

Governing data is the part of a program where overpromising is most tempting and most damaging. Here is the boundary.

  • Classification is very good and not perfect. Pattern based discovery finds a great deal and will both miss things and flag things that are harmless. Treat the report as a strong first draft that a person from your side reads, not as a finished legal document.
  • Encryption is not de-identification. An encrypted file holding patient records still holds patient records. It changes who can read it. It does not change what it is, what rules apply to it, or your obligations if it is disclosed.
  • Paper is entirely outside this. Charts in a cabinet, printed schedules on a desk, forms in a recycling bin. No software on this page reaches any of it, and in most practices paper remains a real part of the exposure.
  • A determined insider is a different problem. Channel control raises the effort required and creates a record. Somebody authorised to see records who photographs a screen is beyond what any of this reaches, and belongs to supervision, agreements and access review.
  • Minimum necessary stays a decision you make. Who should be able to see what, in which role, is a policy judgement about how your practice works. We will enforce the answer once you have written it down. We will not write it for you.
STAMP 01

Heads up: card statements show FORTIFY 24X7 - Health Lock Solutions is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.