Twice-daily capture of working documents and databases on Windows machines, with any version from the last 28 days recoverable in seconds.
Whole-machine protection for Windows, macOS, and Linux, with bare-metal recovery on Windows and 500 GB of pooled storage.
Full server protection with native support for SQL, Oracle, MySQL, Exchange, and SharePoint, and 2,000 GB of pooled storage.
The same server-grade protection for virtual machines, including the ones your practice management vendor stood up and never documented.
Exchange, SharePoint, OneDrive, and Teams held independently of the tenant, with seven-year mail retention and shared mailboxes at no charge.
Gmail captured twelve times a day, drives three times a day, with restore granularity down to one message.
Continuous protection for the accounting file, because Intuit does not guarantee that your data can be recovered.
Unlimited history of directory configuration, real-time change visibility, and rollback measured in seconds rather than weeks.
Automated weekly or monthly restore testing that returns proof of a successful recovery, which is the artifact the contingency plan safeguard asks for.
Contingency planning is the safeguard most often failed at the testing step.
The Security Rule devotes an entire standard to contingency planning, and it is unusually specific. It asks for a data backup plan, a disaster recovery plan, an emergency mode operation plan, procedures for periodic testing and revision, and an assessment of which applications and data are critical.
Most organizations can show the first. Many can describe the second and third. Very few can produce evidence of the fourth, because testing a restore is work somebody has to schedule, perform, and write up, and it competes with a waiting room full of people.
A second reason has nothing to do with regulation at all. Any backup an intruder can reach is destroyed before the encryption starts, since a practice able to prove a clean restore point has no reason to negotiate. A copy sitting on a network share behind the same credentials as the systems it covers was never a recovery plan. It is a second victim.
The four lines that protect computers.
The machine lines run on N-able Cove, which also carries the Microsoft 365 line further down and the restore testing at the end. One platform across workstations, servers, and the tenant means one storage pool, one console, and one set of restore mechanics to learn rather than three.
Practice File Protection covers working documents on Windows machines: office files, vector images, database files, and similar working material, captured twice a day, with any version from the last 28 days recoverable in seconds. It is the inexpensive line for the everyday case, which is a file somebody overwrote before lunch.
Full Workstation Recovery protects the whole machine on Windows, macOS, and Linux, with fully customizable selection and scheduling, an optional local copy alongside the cloud copy, and bare-metal recovery on Windows. It includes 500 GB of pooled storage.
Server Recovery and Virtual Server Recovery apply the same approach to physical and virtual servers, including native support for SQL, Oracle, MySQL, Exchange, and SharePoint, and each includes 2,000 GB of pooled storage. Recovery is granular down to a single file or complete to bare metal.
Pooled storage is worth understanding: the allowance is aggregated across the subscription rather than fixed per device, so a large server and a small one balance each other instead of requiring separate calculations.
The four lines that protect cloud tenancy.
Microsoft and Google guarantee that their platforms remain available. Retaining and recovering the contents is your side of the agreement, and it is the sentence most often discovered after a deletion rather than before one.
Two platforms divide these four lines. Cove extends its SaaS protection to Microsoft 365, which keeps the tenant on the same platform as your machines and servers. Dropsuite carries Google Workspace, QuickBooks Online, and the directory line. Either way these are API-level connectors rather than agents, so nothing is installed anywhere; you authorize a connection and the copying begins.
Microsoft 365 Retention, on Cove, reaches Exchange, SharePoint, OneDrive, and Teams. Mail is held for seven years; the other three for one. Shared mailboxes carry no charge, which matters more here than elsewhere, since referrals, statements, and prior authorizations tend to collect in exactly those addresses. Storage runs at one terabyte a head, pooled across the tenant.
Google Workspace Retention, on Dropsuite, reaches mail, personal and shared drives, and the contact, calendar, and task records beside them. Cadence differs by type: mail twelve times daily, drives three, the rest once. Recovery goes as fine as a single message. AES-256 applies throughout, with transport protected as well.
QuickBooks Online Retention, also Dropsuite, protects the accounting file continuously, with one-click restore and unlimited storage, priced per company. Intuit does not guarantee that your data is recoverable, which is the whole argument for this line.
Entra ID Configuration Recovery is the third Dropsuite line, protecting directory configuration with unlimited retention, well past the thirty-day window Microsoft provides natively. It monitors changes in real time against last-known-good values and rolls back unwanted changes in seconds. Directory objects and conditional access policy are the control plane sitting underneath every other cloud line here.
The contingency plan standard, taken clause by clause
The data backup plan asks for retrievable exact copies of electronic protected health information. That is the machine and platform lines, running on a published cadence against systems you nominate in scoping.
The disaster recovery plan and emergency mode operation plan ask for procedures to restore lost data and to continue critical processes while operating in emergency mode. Bare-metal recovery, granular restore, and documented recovery paths are the technical half of both; the procedural half, including who declares an emergency and how care continues on paper, is yours to write.
Testing and revision procedures is the clause organizations fail. Automated restore testing runs weekly or monthly and returns proof that a recovery succeeded, which converts an estimate into a measured result with a date on it. Applications and data criticality analysis is your decision about what matters most, and the coverage you select here is the record of that decision.
Anything we retain for you carries AES-256 while stored and TLS while moving, on infrastructure that is not the infrastructure being protected. That answers the encryption specifications along with the data backup and storage element of device and media controls.
The line that turns a plan into a fact.
Tested Restore Evidence is the Cove recovery testing capability, running rehearsals against a weekly or monthly schedule and handing back evidence that the restore worked. It is priced per protected system and is the only line here that produces no protection of its own.
What it produces instead is the artifact. A dated report showing that a specific system was recovered successfully on a specific day is the difference between asserting a contingency plan exists and demonstrating that it works. It is also, bluntly, the cheapest way to discover that a job has been silently failing since March, which is a thing that happens to organizations that never test.
Apply it to the systems whose loss would stop care: the practice management server, the imaging store, the file server holding scanned records. Testing everything is possible and usually unnecessary.
How long things take, honestly.
- One file from version history: under a minute, and the most common request by a wide margin.
- A mailbox, a drive, or a company file: minutes, restored into the live tenant or exported out.
- A directory configuration rollback: seconds, against last-known-good values.
- A dead server rebuilt from bare metal onto fresh hardware: hours, set by how much data there is and how fast the link is. Hours you budgeted for beat hours you found out about, and the testing line is how the real figure gets known in advance.
What we keep sits well away from the estate it covers: separate platform, separate credentials, separate administrative boundary. An account taken over inside your environment can wreck a great deal of it. Nothing reaches across into material that was never stored there.
| Platforms | N-able Cove for workstations, servers, virtual machines, Microsoft 365 and restore testing; Dropsuite for Google Workspace, QuickBooks Online and the directory line |
|---|---|
| Practice files | Windows only, twice-daily capture, any version from the last 28 days |
| Full workstation | Windows, macOS, Linux, full system, bare-metal recovery on Windows, 500 GB pooled |
| Physical server | Full system, SQL, Oracle, MySQL, Exchange and SharePoint support, bare-metal recovery, 2,000 GB pooled |
| Virtual server | As physical server, applied to virtual machines, 2,000 GB pooled |
| Storage locations | Cloud, with an optional local copy on the machine lines |
| Microsoft 365 | Exchange, SharePoint, OneDrive, Teams; seven-year Exchange retention, one year for the rest; shared mailboxes free; 1 TB per user pooled |
| Google Workspace | Mail 12 times a day, drives 3 times a day, contacts, calendars and tasks once a day; granular restore to a single message |
| QuickBooks Online | Continuous, one-click restore, unlimited storage, per company |
| Entra ID | Unlimited configuration retention, real-time change monitoring, rollback to last-known-good |
| Restore testing | Weekly or monthly, with proof of successful restore returned |
| Encryption | 256-bit AES at rest, TLS in transit |
| Custody | Infrastructure separate from the systems and credentials being protected |
| Billing unit | Per workstation, server, virtual server, licensed user, company file, tenant, or protected system, per month |
Where these lines stop
Backup is not medical record retention. How long you must keep a designated record set is set by state law and by payer and accreditation requirements, and those periods commonly exceed the retention windows published here. Retention policy is a legal determination for your organization; we operate the windows you select.
Restoring data is not validating it. We return the file, mailbox, database, or machine as captured. Confirming that a restored clinical application is internally consistent and fit for use is work for you and your application vendor.
Storage allowances are pooled, not unlimited. Each line publishes its allowance and it aggregates across the subscription. Estates well past their pooled allowance are quoted directly rather than surprised on an invoice.
Recovery time depends on physics. A bare-metal rebuild is bounded by data volume and available bandwidth. Any vendor quoting a fixed recovery time without knowing either is guessing.
The testing line protects nothing on its own. It verifies coverage that already exists. Bought alone it has nothing to test.
How we describe this work
There is no such thing as a HIPAA certified product, and no vendor can place your organization in compliance. Compliance is a program you own: your risk analysis, your policies, your workforce training, your documentation. What we supply are technical services and the evidence they generate, mapped to the safeguards in the HIPAA Security Rule so your compliance team can point at something concrete.
Nothing described on this site guarantees a compliance outcome, an audit result, or immunity from a breach. Determinations about your obligations belong to your privacy officer and your counsel. Fortify 24x7 executes a Business Associate Agreement before enabling any service that may create, receive, maintain, or transmit protected health information on your behalf.
Heads up: card statements show FORTIFY 24X7 - MediShield IT is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.