A Fortify 24x7 brand. Security and continuity services for healthcare organizations across the United States.Client sign inContact
MediShield IT
Home / Services / HIPAA safeguard map
Reference · Security Rule correspondence

The HIPAA Safeguard Map

Every service we operate, set against the standard or implementation specification it supports, with the limits of that support stated plainly.

Read this first

Nothing in the table below places your organization in compliance. The HIPAA Security Rule assigns obligations to covered entities and business associates, not to products. A vendor can supply a technical measure and the evidence it generates. Whether that measure is reasonable and appropriate for your organization is a determination you make, document, and revisit, informed by your own risk analysis.

The rule also distinguishes required from addressable implementation specifications. Addressable does not mean optional. It means you assess whether the specification is reasonable and appropriate in your circumstances and, where it is not, document why and implement an equivalent alternative if one is reasonable. Several of the strongest controls listed here sit under addressable specifications for exactly that reason.

We have kept this map conservative. Where a service only partially supports a specification, the wording says so. Where the obligation is contractual rather than technical, no service is claimed.

Correspondence table 21 standards and implementation specifications
CitationStandard or specificationType What we contributeService family
45 CFR 164.308(a)(1)(ii)(A)Risk analysisRequiredLocating protected health information across endpoints so the assessment is based on where data actually isPHI Data Protection
45 CFR 164.308(a)(1)(ii)(B)Risk managementRequiredPatch state, configuration baselines, application control, and endpoint defense as the measures that reduce identified riskEndpoint Management Zero Trust Allowlisting Managed Detection
45 CFR 164.308(a)(1)(ii)(D)Information system activity reviewRequiredDetections examined continuously by analysts, with the review itself recordedManaged Detection
45 CFR 164.308(a)(5)(ii)(A)Security remindersAddressableRecurring lessons and simulated phishing producing dated, per-person recordsEmail Defense
45 CFR 164.308(a)(5)(ii)(B)Protection from malicious softwareAddressableGateway filtering, attachment detonation, default-deny application control, and behavioral endpoint agentsEmail Defense Zero Trust Allowlisting Managed Detection Endpoint Management
45 CFR 164.308(a)(6)(ii)Response and reportingRequiredAnalyst-performed containment on the remediation lines, with a timestamped case record as the documentationManaged Detection Email Defense
45 CFR 164.308(a)(7)(ii)(A)Data backup planRequiredRetrievable copies of nominated systems, machines, mailboxes, drives, company files and directory configurationBackup & Continuity
45 CFR 164.308(a)(7)(ii)(B)Disaster recovery planRequiredGranular and bare-metal recovery paths, documented per lineBackup & Continuity
45 CFR 164.308(a)(7)(ii)(C)Emergency mode operation planRequiredRecovery copies held outside the affected estate so operations can be resumed from unaffected infrastructureBackup & Continuity
45 CFR 164.308(a)(7)(ii)(D)Testing and revision proceduresAddressableAutomated weekly or monthly restore testing returning proof that a recovery succeededBackup & Continuity
45 CFR 164.308(a)(7)(ii)(E)Applications and data criticality analysisAddressableThe coverage you select and the systems you nominate for testing are the record of that analysisBackup & Continuity
45 CFR 164.310(d)(1)Device and media controlsStandardA maintained register of devices across Windows, macOS, Linux, Apple hardware and mobileEndpoint Management
45 CFR 164.310(d)(2)(iv)Data backup and storageAddressableA retrievable copy taken before equipment is moved or retiredBackup & Continuity Endpoint Management
45 CFR 164.312(a)(1)Access controlStandardRestricting which programs may execute narrows the same question from the execution sideZero Trust Allowlisting
45 CFR 164.312(a)(2)(iii)Automatic logoffAddressableScreen lock and timeout profiles enforced on managed devices rather than asserted in policyEndpoint Management
45 CFR 164.312(a)(2)(iv)Encryption and decryptionAddressable256-bit AES on everything held for you, and dynamic file encryption on the enforcement lineBackup & Continuity PHI Data Protection
45 CFR 164.312(b)Audit controlsRequiredEndpoint agents recording and examining activity, with the examination performed by peopleManaged Detection
45 CFR 164.312(c)(1)IntegrityStandardIndependent copies that make improper alteration or destruction detectable and reversibleBackup & Continuity
45 CFR 164.312(e)(1)Transmission securityStandardTLS in transit on everything we carry, plus channel control over how secured files may leaveBackup & Continuity PHI Data Protection
45 CFR 164.312(e)(2)(ii)Encryption in transitAddressableTransport encryption on every backup and platform connectorBackup & Continuity
45 CFR 164.308(b)(1)Business associate contractsStandardFortify 24x7 executes a Business Associate Agreement before enabling any service that may touch protected health informationContractual, not technical
01Coverage

How the 24 lines divide.

Lines are bought individually. There is no bundle, no seat minimum, and no annual commitment, so a program can begin with the two or three safeguards your last risk analysis flagged and grow from there.

The parts we do not sell

Safeguards that stay with you, whatever you buy here.

An honest map has to name its own edges. The following are your obligations, and no service on this site discharges them.

Administrative. Assigning a security official, workforce clearance and termination procedures, authorization and supervision, sanction policy, and the risk analysis and risk management process itself. We produce input to your risk analysis; we do not perform it.

Physical. Facility access controls, workstation use and security policy, and the physical disposal of media. We can report which devices exist; we cannot control who walks past them.

Technical, in part. Unique user identification, emergency access procedures, and person or entity authentication are configured in your clinical and productivity systems, not in ours.

Privacy Rule obligations entirely. Notice of privacy practices, minimum necessary, patient rights of access and amendment, accounting of disclosures, and authorizations sit outside the Security Rule and outside this catalog. Discovery output can inform a minimum necessary review, but the review is yours.

How we describe this work

There is no such thing as a HIPAA certified product, and no vendor can place your organization in compliance. Compliance is a program you own: your risk analysis, your policies, your workforce training, your documentation. What we supply are technical services and the evidence they generate, mapped to the safeguards in the HIPAA Security Rule so your compliance team can point at something concrete.

Nothing described on this site guarantees a compliance outcome, an audit result, or immunity from a breach. Determinations about your obligations belong to your privacy officer and your counsel. Fortify 24x7 executes a Business Associate Agreement before enabling any service that may create, receive, maintain, or transmit protected health information on your behalf.

FORTIFY 24X7

Heads up: card statements show FORTIFY 24X7 - MediShield IT is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.

Managed DetectionEmail DefenseZero Trust AllowlistingEndpoint ManagementPHI Data ProtectionBackup & Continuity