A Fortify 24x7 brand. Records room habits, applied to clinical systems.Your shelfRecords desk
MediTrust Cyber
Shelf 00 / Security work for healthcare organizations

Security work you can pull off a shelf and read.

MediTrust Cyber runs the technical safeguards sitting beneath a healthcare security program, and keeps the paperwork showing that each one ran. Twenty four subscription lines. Every one carries a countable unit, a rate printed ahead of purchase, and a plain sentence saying where it quits being useful. Filed for medical and dental offices, for clinics, for behavioral health teams, and for whoever handles their billing.

Kept byFortify 24x7
Shelved forMedical and dental offices, clinics, behavioral health, billing
ChargedBy the unit, monthly, in advance
Statement markFORTIFY 24X7
Register 01 / Where records actually travel

Four lines from a register nobody keeps.

Patient information leaves an office through ordinary doors held open for ordinary reasons. Nothing below counts as misconduct, and each item began with somebody keeping the day moving inside a clinic. What never got written is the closing entry: a date of return, and a name beside whoever checked it.

What went outSigned out forHow it travelledChecked back in
Release of informationAn attorney, an insurer, the next providerAttachment on a messageNo entry
After hours messagesThe answering service, overnightMail into a shared boxNo entry
The replaced workstationA hardware refresh last springA drive behind the printer paperNo entry
The shared clinical inboxReading messages between roomsA phone somebody bought themselvesNo entry
Note 01

Release of information

Records requests get answered all day. An attorney wants a chart, an insurer wants an operative note, a new provider wants the last two years. Somebody attaches the file and sends it. Most practices can say the request came in. Very few can say what left, on which day, to which address, and who authorized it.

Note 02

After hours messages

The answering service takes calls overnight and passes them on by mail, so symptoms, dates of birth and callback numbers land in a shared box before the first appointment. Nothing ages any of it out. Two years on, that box is a searchable archive of clinical detail nobody set out to build.

Note 03

The replaced workstation

A machine gets swapped out, the new one goes on the desk, and the old one goes in the closet. The practice management client is still installed, its cache is still on the drive, and no line anywhere records that the disk was wiped or that the box ever left the building.

Note 04

The shared clinical inbox

A clinician adds the practice inbox to their own phone so messages can be read between rooms, which is exactly what a busy clinic needs from them. The handset is not enrolled and nothing on it is managed. When that person moves on, the mailbox goes with them.

Not one of the four needs a new policy written before it can be dealt with. Each needs somebody able to say what left, when, and whether it came back. That is the entire job of the lines shelved further down this page.

Rack 02 / Six jackets

Six jackets. Take the ones holding something you own.

Nothing here is bundled and nothing is tiered. Choose a jacket, choose the lines inside it, and whatever you shelve arrives on one monthly charge. Every jacket page states what the software does, what a unit counts, and the exact point at which it stops helping you.

A red tab marks a jacket that acts while something is happening. Somebody or something intervenes at the moment of the event.

A blue tab marks a jacket that keeps a record you can go back to. Its value shows up later, when a question is asked about last month.

Jacket 41

Detection and live response

6 lines · SentinelOne with Fluency

An agent rides each managed machine and forms its own view of what a piece of software is up to. A correlation layer lays those views beside sign-ins and mail movement. Engineers read the result through the small hours, when a building has emptied and a network has not.

  • Verdicts form on the hardware, so a desk cut off from everything still holds one.
  • Fluency draws endpoint activity, logins and traffic onto a single timeline under a single clock.
  • Three grades of answer: tell you, work it beside you, or pull the machine off the wire unasked.
Pull this jacket
Jacket 52

Execution control

1 line · ThreatLocker

Charts, claims and imaging open on a handful of machines. Across those, keeping a roster of software cleared to start beats asking a scanner to recognise whatever shows up in a fortnight. Missing from the roster means it never starts, and nobody is left judging in the moment how wrong something looked.

  • A watching phase draws the roster from clinical and office software your colleagues genuinely open.
  • Whatever your vendors release gets followed, so no Monday morning update locks an office out of its own systems.
  • Ringfencing draws bounds around whatever a cleared program is then free to launch, read, or reach.
Pull this jacket
Jacket 63

Mailbox protection and drills

2 lines · Ironscales

Cover fastens over the API onto the mailbox itself. Nothing stands in front of your mail the way a gateway would, and the difference is practical rather than semantic: correspondence delivered an hour back is still reachable. Beside it, brief drills for the colleagues handling referrals and remittances hour upon hour.

  • Fastens onto a tenant you hold already, whether that runs on Microsoft 365 or on Google Workspace.
  • Impersonation and takeover get measured against how your own colleagues build a sentence.
  • Drills and two minute lessons, pointed where wanted instead of sprayed over a roster.
Pull this jacket
Jacket 74

The equipment register

4 lines · N-able N-sight, Addigy, Zimperium

A list of machines that is true on the day it gets read. Patch state somebody can be shown. Filtering carried on the agent already installed. Apple hardware run as Apple hardware. And the handsets clinicians glance at on the way between rooms.

  • One agent carries the list, the health readings, patch delivery, scripting, remote sessions.
  • Web and name filtering rides that very agent, so no fresh box needs racking anywhere.
  • Apple equipment is Addigy work. Handsets running iOS or Android are Zimperium work.
Pull this jacket
Jacket 85

Finding and sealing records

2 lines · Actifile

Regulated files settle in places nobody planned for. Locate them first and price the exposure. Then rule on which exits a file may use, and seal the copies bound to travel whatever anybody decides.

  • Workstations, servers and the shares they reach get swept for health and payment detail, then ranked.
  • Encryption applied to the document itself, so a copy stays sealed wherever it lands.
  • Rules on the everyday exits: removable media, the browser, chat clients, mail.
Pull this jacket
Jacket 96

Duplicates and return to service

9 lines · N-able Cove with Dropsuite

Copies of files. Copies of entire machines. Physical servers and virtual ones. The cloud tenants holding mail and documents. The directory settling who gets through a door at all. And a rehearsal showing that a restore hands back something readable.

  • Workstations, servers and virtual machines taken as images instead of as lists of files.
  • Separate lines for Microsoft 365, for Google Workspace, for QuickBooks Online, and for Entra ID configuration.
  • Restore verification does the recovery on a timetable and gives you back a dated result.
Pull this jacket
Custody 03 / Whose signature goes on which part

What we hold, and what never leaves your desk.

A HIPAA security program is a list of obligations and only part of that list is software. Below is an honest split. Nothing in the right hand column can be bought from this storefront, or from anybody else, however carefully a page is worded.

Held here

Signed for by Fortify 24x7

  • The technical safeguards, operated. Detection, allowlisting, mailbox cover, equipment management, discovery, encryption and copies. Engineers on shift work them, rather than passing you a console login and wishing you luck with it.
  • Dated proof. Patch reports, sweep findings, drill results, restore evidence. Material a risk analysis of yours can quote directly, and an underwriter can be handed, without anybody reconstructing it a year afterwards.
  • A written scope. Which machines, which mailboxes, which tenants, what retention, and what has been left outside the file deliberately so nobody assumes otherwise.
  • Paperwork ahead of provisioning. Where a line would place Fortify 24x7 alongside protected health information, nothing is switched on until a signature sits on the business associate agreement.
Held at your desk

Signed for by you

  • The risk analysis. The document weighing your own organization. Nothing sold here produces it, and a vendor writing it on your behalf produces a result that means very little to a regulator.
  • Policies, procedures and the sanction process. Written on your letterhead, applied by your managers, and generally the first thing an investigator asks to read.
  • Workforce training records. We run the drills and give back what happened in them. The duty to train people, and to keep that file current, sits with you.
  • Agreements with everybody else. Your clearinghouse, your practice management vendor, your answering service, your shredding company. Keeping that register is your work and not ours.
  • Ruling on whether something is a breach. Ruling an incident reportable, then settling whom the law obliges you to tell, is your decision alongside counsel, taken over our evidence spread out on a table.
Not in this file
  • Nobody becomes HIPAA compliant by buying. These lines hold up the technical safeguards within a security program. Compliance describes a whole organization set against the risk analysis it produced for itself, and no shelf of software has ever created that state.
  • No certificate waits at the end of this. Not one body anywhere certifies security software against the Security Rule inside HIPAA, so there is no certificate to hand over. A compliance badge sitting on a vendor site was drawn by a designer, and it records a finding by nobody.
  • Equipment a manufacturer locked will usually refuse an agent. Imaging units, analysers, dental sensors and their relatives come routinely under a written ban on outside software. What they want is separation on the network plus a decision somebody wrote down, and that is other work rather than a line on this rack.
  • No outcome gets guaranteed. Nobody honest tells you that nothing will ever get through. The written part is what runs, who watches it, what it may do on its own authority, and what lands on your desk afterwards.
Card index 04 / Ten platforms

Whose software is actually running.

Ten platforms carry twenty four lines, and each of the ten is named on this page. Any managed service that refuses to name whose agent runs on hardware full of patient records is asking you to extend a trust nobody there ever earned.

CARD 01

SentinelOne

Behavioral agent living on the endpoint. Makes its mind up locally, whether or not a network is present.

CARD 02

Fluency

The correlation layer. Puts an agent account of events alongside sign-in, mailbox and traffic evidence on one timeline.

CARD 03

ThreatLocker

Allowlisting. Approved software starts. Nothing else is offered the chance.

CARD 04

Ironscales

Protection attached to the mailbox itself over the API. Not a gateway, and never sold here as one.

CARD 05

N-able N-sight

The health, patch level and hardware list, gathered by one agent over Windows, macOS and Linux.

CARD 06

Addigy

Apple management. Enrolment, profiles and software delivery across macOS and iOS.

CARD 07

Zimperium

Mobile threat defense running on the phone, forming its opinion there instead of asking a service.

CARD 08

Actifile

Locating regulated material, scoring the exposure, then sealing documents one at a time.

CARD 09

N-able Cove

Whole machine and file level copies, for workstations, for physical servers and for virtual ones.

CARD 10

Dropsuite

Second copies held apart: Entra ID configuration, a QuickBooks Online company file, the Google Workspace tenant, the Microsoft 365 tenant.

Chain of custody 05 / After you sign

How a file gets opened, and who handles it.

Five stages, listed in the order they arrive, so that nothing in the opening fortnight lands sideways. Two of them want something from you. The other three do not.

01

Signed for

Your card is charged, the order enters the build queue, and Stripe posts a receipt headed FORTIFY 24X7. Nothing at all is asked of you on that day.

02

Made up

Engineers here raise the tenant. Against each machine line an installer gets cut, with its enrolment link beside it. Cloud accounts your scope names receive authorization links of their own.

03

First read

An opening sweep and an opening copy take longest, since both must cover everything in scope one pass before settling down. Leave machines powered throughout. After that, only differences ever travel.

04

Corrections

Rosters bed in. Filters collect exceptions. Timetables get cut down to what your office truly holds. A small number of quick conversations with us belong to that period.

05

Standing order

Alerting lands on our bench. It never lands in yours. The portal keeps whatever lines are charged to you, whatever installers were cut for your equipment, and each note the desk received from you.

Index 06 / Twenty four lines

The whole catalog, filed by jacket.

Billing hands each rate over while this page comes up. Whatever a card shows is therefore the sum your card meets. Shelve as you go. Signing sits apart from all that, and it comes later.

The rate card stayed quiet on that request. Try the page once more, and where it still declines to answer, put a line into support@meditrustcyber.com and a person there will price the lines out by hand for you.
Jacket 41

Detection and live response

6 lines
Reading the rate card
Jacket 52

Execution control

1 line
Reading the rate card
Jacket 63

Mailbox protection and drills

2 lines
Reading the rate card
Jacket 74

The equipment register

4 lines
Reading the rate card
Jacket 85

Finding and sealing records

2 lines
Reading the rate card
Jacket 96

Duplicates and return to service

9 lines
Reading the rate card
Filed note

Heads up: card statements show FORTIFY 24X7 - MediTrust Cyber is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.

Sign-out card0 in the file$0.00a month