A Fortify 24x7 brand. Security and continuity services for healthcare organizations across the United States.Client sign inContact
MediShield IT
Home / Services / Email Defense and Workforce Training
Service family · Email defense

Email Defense and Workforce Training

Filtering at the gateway and preparation for the people behind it, aimed at the delivery route that opens most healthcare incidents.

Lines in this family Published monthly rates, billed in advance
Email Gateway and TrainingFortify-FES+SAT · per mailbox

Filtering, link rewriting, attachment detonation, impersonation defense, and message recall, bundled with awareness training for the same person.

LoadingQTY
Workforce Awareness TrainingFortify-SAT · per staff member

Simulated phishing, short lessons, benchmarking, and reporting for practices whose gateway is already in place elsewhere.

LoadingQTY
01The route

Email is the only system that connects your workforce to strangers by design.

Every other application in a practice is closed. The practice management system talks to staff. The imaging archive talks to modalities. The clearinghouse talks to payers. Email talks to anybody in the world who knows an address, and in healthcare those addresses are published on the website, printed on the referral pad, and listed in the payer directory.

Two patterns dominate. Credential harvesting presents a convincing sign-in page for Microsoft 365 or the portal your staff use daily, and it succeeds because the page is a perfect copy and the person is between patients. Business email compromise skips malware entirely: a message from a real, already compromised mailbox asks the practice manager to update remittance details, or asks payroll to redirect a deposit. Nothing malicious is attached, because nothing needs to be.

Billing companies feel this hardest, because they sit between many providers and many payers and a plausible request for a banking change is indistinguishable from a Tuesday.

02The gateway

What is stopped before anyone has to decide.

These lines are built on Ironscales, which sits inside the mailbox rather than only in front of it. The practical consequence is the one that matters during an incident: a message already sitting in forty inboxes can still be reached and removed, because the platform never stopped having access to it. Mail is inspected before delivery and acted upon afterwards.

  • Anti-spam and anti-virus filtering, with custom content rules for the phrasing your organization sees most.
  • Imposter email protection and advanced detection for business email compromise, which look at relationship and display-name patterns rather than attachments, because these messages carry none.
  • URL defense, including predictive evaluation: links are rewritten and assessed at the moment of the click, not only at the moment of delivery. A page that is harmless when the message arrives and hostile forty minutes later is the standard technique, and delivery-time scanning alone misses it by design.
  • Attachment defense by reputation and by sandbox detonation, where a file is opened in isolation and watched before it reaches a workstation.
  • Warning tags on the message itself, so the person reading it sees that it came from outside or resembles a known contact without being one.
  • One-click message pull, which retracts a delivered message from every mailbox that received it. This is the control that limits an incident that has already begun.
  • Outbound filtering, which catches the compromised mailbox in your own organization sending to your patient list.
HIPAA Security Rule

Reminders you can date, and malicious software protection you can point at

The Security Rule names security reminders and protection from malicious software as implementation specifications under the security awareness and training standard. Both are addressable, which does not mean optional: it means you must assess whether each is reasonable and appropriate and document what you decided.

Training produces the record that decision requires. Simulated phishing, short recurring lessons, completion reporting, and benchmarking against comparable organizations create dated, per-person evidence that the workforce was reminded and what happened when it was tested. An assertion that staff are trained is not evidence. A report with names and dates is.

The gateway is the technical half of the same pairing, and the reported-message workflow feeds your incident procedures: a message a staff member reports with the alert button becomes an item somebody actually triages.

45 CFR 164.308(a)(5)(ii)(A)45 CFR 164.308(a)(5)(ii)(B)45 CFR 164.308(a)(6)(ii)
03The training

Preparation that produces paperwork on purpose.

Ironscales carries the training alongside the filtering, which is the reason these two halves are bundled on one line. The same platform that saw a person click also schedules what they are shown afterwards. Training is included with the gateway line and is also sold on its own for organizations whose filtering already sits elsewhere.

  • Unlimited simulated phishing, so the exercise can be run at a cadence that matches your risk rather than a licensing limit.
  • Automated campaigns and short recurring lessons, delivered without anyone having to schedule them each quarter.
  • A reporting button inside the mail client, with reply tracking so a staff member who answered a simulation is coached rather than embarrassed.
  • Directory integration, so joiners and leavers do not have to be maintained by hand in a second place.
  • Industry benchmarking and a monthly exposure check of the addresses belonging to your organization that are visible externally.
  • Social engineering indicators, which annotate a simulation after the fact to show the person exactly which signals were present.

The measure that matters is the trend in your own click rate over quarters, not a single result. We report it that way.

04Buying

Two lines, and how they combine.

Email Gateway and Training is priced per mailbox and covers both halves for the same person. It is the usual choice, because filtering and preparation address the same message from opposite directions.

Workforce Awareness Training is priced per staff member and exists for organizations that already run a gateway they are satisfied with, or whose parent organization supplies one. It can also cover people who need training but hold no mailbox of their own, which is common with per-diem and clinical support staff.

Shared and departmental mailboxes are counted as mailboxes for the gateway line, since messages are filtered by destination. Staff who share one address are counted individually for training, since preparation is a property of a person.

Technical specificationTwo lines · gateway and training
PlatformIronscales, operating inside the mailbox rather than only ahead of it
FilteringAnti-spam, anti-virus, and custom content rules
ImpersonationImposter email protection and advanced business email compromise detection
LinksURL defense with predictive evaluation, assessed at click time
AttachmentsReputation checks and sandbox detonation before delivery
RecallOne-click message pull from every mailbox that received a message
OutboundFiltering on mail leaving your organization
Visual cuesWarning tags applied to the message itself
TrainingUnlimited simulated phishing, automated campaigns, recurring lessons
ReportingPer-person completion records, click-rate trend, industry benchmarking, monthly email exposure check
IntegrationActive Directory synchronization, in-client phish alert button, reply tracking
Billing unitPer mailbox for the gateway line; per staff member for training

Where these lines stop

This is inbound and outbound filtering, not patient messaging. Sending protected health information to a patient securely is a function of your practice management system, your patient portal, or a dedicated secure messaging product. It is not what a gateway does, and we will not describe it as though it were.

Training evidences preparation, not competence. A completion record shows the lesson was delivered and the simulation was run. It does not promise that the next message will be reported, and no honest vendor will tell you otherwise.

The training-only line leaves the gateway wherever it is. If that gateway is the default filtering included with a mail subscription, say so during scoping so the gap is recorded rather than assumed away.

Message pull works on mailboxes we filter. A message forwarded to a personal address before recall has left the boundary, which is a policy problem rather than a technical one.

How we describe this work

There is no such thing as a HIPAA certified product, and no vendor can place your organization in compliance. Compliance is a program you own: your risk analysis, your policies, your workforce training, your documentation. What we supply are technical services and the evidence they generate, mapped to the safeguards in the HIPAA Security Rule so your compliance team can point at something concrete.

Nothing described on this site guarantees a compliance outcome, an audit result, or immunity from a breach. Determinations about your obligations belong to your privacy officer and your counsel. Fortify 24x7 executes a Business Associate Agreement before enabling any service that may create, receive, maintain, or transmit protected health information on your behalf.

FORTIFY 24X7

Heads up: card statements show FORTIFY 24X7 - MediShield IT is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.

Managed DetectionZero Trust AllowlistingEndpoint ManagementPHI Data ProtectionBackup & Continuity