A Fortify 24x7 brand. Security and continuity services for healthcare organizations across the United States.Client sign inContact
MediShield IT
Home / Services / Managed Endpoint Hygiene
Service family · Endpoint management

Managed Endpoint Hygiene

Patch state, inventory, web control, Apple fleet configuration, and mobile defense: the unglamorous record an auditor asks you to produce first.

Lines in this family Published monthly rates, billed in advance
Managed Endpoint HygieneFortify-RMM · per managed device

N-sight reports health, inventory, and patch state across Windows, macOS, and Linux, with mobile device management for tablets and phones.

LoadingQTY
Web Protection and FilteringFortify-RMM-DNS · per managed device

Category filtering, reputation blocking, and full visibility of browser activity, private sessions included, on the devices we manage.

LoadingQTY
Apple Fleet ManagementFortify-Control · per Apple device

Addigy enforces configuration, deploys software, and runs automated compliance checks on the iPads and Macs that have spread through clinical areas.

LoadingQTY
Mobile Device DefenseFortify-Mobile · per phone or tablet

Zimperium runs behavioral protection on the handset itself against mobile malware, phishing, hostile wireless, and rooted or jailbroken devices.

LoadingQTY
01The register

You cannot protect, patch, or dispose of a device you have not written down.

Ask a practice how many computers it has and the answer is usually confident and wrong. The count omits the laptop the departing associate still holds, the machine in the sterilization corridor that runs one instrument, the iPad the hygienist uses for intake forms, and the tablet in the van used for home visits.

This matters beyond tidiness. Every other safeguard is scoped by this list. Your risk analysis is bounded by it. Your disposal procedure applies to it. Your encryption assertion is only true of the devices on it. A device nobody recorded is a device nobody patched, and the first time anyone learns it existed is usually the worst possible time.

The four lines here maintain that register and act on it, across the four device populations a healthcare organization actually has: general computers, the web they reach, Apple hardware, and phones.

02The lines

What each one does.

Three platforms sit behind these four lines, each chosen because it is genuinely good at one population of devices rather than adequate across all of them.

Managed Endpoint Hygiene runs on N-able N-sight, placing an agent on Windows, macOS, and Linux machines and reporting health, hardware and software inventory, and patch status. It also carries mobile device management for tablets and phones, which is the enrollment and configuration layer rather than the threat layer.

Web Protection and Filtering is the N-sight DNS and web filtering module, adding category filtering, site reputation blocking, and bandwidth visibility on the machines we manage. Its visibility extends to private browsing sessions, which is worth knowing before you deploy it, and worth stating in your acceptable use policy.

Apple Fleet Management runs on Addigy, which handles macOS and iOS properly rather than as an afterthought bolted onto a Windows tool: configuration enforcement, software deployment, security baselines, inventory, remote remediation, and automated compliance checks. Apple hardware has spread quietly through clinical areas, and treating it as an exception is how unmanaged devices accumulate.

Mobile Device Defense is Zimperium, and it is protection rather than administration. Its behavioral models run on the handset itself and detect mobile malware and phishing without waiting on a cloud lookup, which means a phone on a hospital guest network or roaming abroad keeps full protection. It also detects jailbroken and rooted devices, man-in-the-middle conditions including rogue wireless and tampered secure communications, and risky applications installed from either official store.

HIPAA Security Rule

Risk management, device controls, and the evidence underneath both

Risk management requires security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level. Patch state is the plainest possible expression of that requirement, and a patch report with dates is the plainest possible evidence of it.

The device and media controls standard governs hardware and media holding electronic protected health information as they move into, out of, and around your facility. Its specifications cover disposal, media re-use, accountability for movement, and data backup before equipment is moved. Every one of those begins with a current inventory, which is what these lines maintain.

Configuration management also carries part of the access control standard in practice: enforced screen lock and timeout profiles pushed to managed devices are how the automatic logoff specification gets implemented on real hardware rather than asserted in a policy document.

45 CFR 164.308(a)(1)(ii)(B)45 CFR 164.310(d)(1)45 CFR 164.310(d)(2)(i) and (iii)45 CFR 164.312(a)(2)(iii)
03Mobile

Why the phone is treated separately.

Clinicians read messages on phones. That is not a policy failure to be corrected, it is how care coordination works, and pretending otherwise produces a policy nobody follows.

Two different things are needed and they are frequently confused. Management, which N-sight provides, enrolls the device, applies a configuration, and can remove organizational data. Defense detects that the device itself is under attack. Management is included with the hygiene line. Defense is the Zimperium line, and it addresses conditions management cannot see: a rogue access point in a waiting room, an application requesting permissions far beyond its function, a handset that has been rooted, or a phishing page opened in a messaging app rather than a browser.

Because Zimperium evaluates on the handset, it continues to work where healthcare staff actually are: in a hospital with no signal, on a guest network, or on a plane.

04Deployment

How this usually rolls out.

N-sight first, because it produces the register everything else depends on. Web protection follows once the acceptable use policy has been updated to describe the monitoring honestly. Addigy is deployed alongside, since the Apple estate is usually the least documented part of it.

Mobile defense is normally the last line added and the first one that surprises people, because the first report tends to find at least one handset in a state nobody expected. Quantities are adjusted from the portal as devices join and leave, and changes apply to the following invoice.

Technical specificationFour lines · per device
PlatformsN-able N-sight for computers and web filtering, Addigy for Apple hardware, Zimperium for mobile threat defense
Platforms managedWindows, macOS, and Linux, with mobile device management for tablets and phones
ReportedDevice health, hardware and software inventory, and patch status
Web controlCategory filtering, site reputation blocking, and bandwidth visibility
Browsing visibilityIncludes private and incognito sessions on managed devices
Apple managementConfiguration enforcement, software deployment, security baselines, inventory, remote remediation, automated compliance checks
Mobile defenseOn-device behavioral detection of mobile malware and phishing, with no dependence on cloud connectivity
Mobile conditions detectedJailbroken and rooted devices, man-in-the-middle and rogue wireless, tampered secure communications, risky applications from either official store
Evidence producedDevice register, patch state history, configuration compliance reporting
Billing unitPer managed device, per Apple device, or per phone or tablet, per month

Where these lines stop

Management is not detection. These lines maintain hygiene and configuration on computers. They do not monitor for intrusion, which is the managed detection family. An estate with excellent patch state and no detection is well maintained and unwatched.

Web filtering sees browsing, and that has policy consequences. Visibility extends to private sessions. Disclose it in your acceptable use policy before deployment, not afterwards, and involve whoever owns employment policy in your organization.

Personally owned phones raise questions this line cannot answer for you. Enrollment on a device an employee owns needs a written policy covering what the organization can see, what it can erase, and what happens at separation. We will configure to your policy; we cannot write it.

Patching depends on vendors shipping patches. Clinical applications pinned to an unsupported operating system by their vendor cannot be brought current by any tool. Those cases are compensating-control conversations, and we would rather have them during scoping.

How we describe this work

There is no such thing as a HIPAA certified product, and no vendor can place your organization in compliance. Compliance is a program you own: your risk analysis, your policies, your workforce training, your documentation. What we supply are technical services and the evidence they generate, mapped to the safeguards in the HIPAA Security Rule so your compliance team can point at something concrete.

Nothing described on this site guarantees a compliance outcome, an audit result, or immunity from a breach. Determinations about your obligations belong to your privacy officer and your counsel. Fortify 24x7 executes a Business Associate Agreement before enabling any service that may create, receive, maintain, or transmit protected health information on your behalf.

FORTIFY 24X7

Heads up: card statements show FORTIFY 24X7 - MediShield IT is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.

Managed DetectionEmail DefenseZero Trust AllowlistingPHI Data ProtectionBackup & Continuity