Read this first
Nothing in the table below places your organization in compliance. The HIPAA Security Rule assigns obligations to covered entities and business associates, not to products. A vendor can supply a technical measure and the evidence it generates. Whether that measure is reasonable and appropriate for your organization is a determination you make, document, and revisit, informed by your own risk analysis.
The rule also distinguishes required from addressable implementation specifications. Addressable does not mean optional. It means you assess whether the specification is reasonable and appropriate in your circumstances and, where it is not, document why and implement an equivalent alternative if one is reasonable. Several of the strongest controls listed here sit under addressable specifications for exactly that reason.
We have kept this map conservative. Where a service only partially supports a specification, the wording says so. Where the obligation is contractual rather than technical, no service is claimed.
| Citation | Standard or specification | Type | What we contribute | Service family |
|---|---|---|---|---|
| 45 CFR 164.308(a)(1)(ii)(A) | Risk analysis | Required | Locating protected health information across endpoints so the assessment is based on where data actually is | PHI Data Protection |
| 45 CFR 164.308(a)(1)(ii)(B) | Risk management | Required | Patch state, configuration baselines, application control, and endpoint defense as the measures that reduce identified risk | Endpoint Management Zero Trust Allowlisting Managed Detection |
| 45 CFR 164.308(a)(1)(ii)(D) | Information system activity review | Required | Detections examined continuously by analysts, with the review itself recorded | Managed Detection |
| 45 CFR 164.308(a)(5)(ii)(A) | Security reminders | Addressable | Recurring lessons and simulated phishing producing dated, per-person records | Email Defense |
| 45 CFR 164.308(a)(5)(ii)(B) | Protection from malicious software | Addressable | Gateway filtering, attachment detonation, default-deny application control, and behavioral endpoint agents | Email Defense Zero Trust Allowlisting Managed Detection Endpoint Management |
| 45 CFR 164.308(a)(6)(ii) | Response and reporting | Required | Analyst-performed containment on the remediation lines, with a timestamped case record as the documentation | Managed Detection Email Defense |
| 45 CFR 164.308(a)(7)(ii)(A) | Data backup plan | Required | Retrievable copies of nominated systems, machines, mailboxes, drives, company files and directory configuration | Backup & Continuity |
| 45 CFR 164.308(a)(7)(ii)(B) | Disaster recovery plan | Required | Granular and bare-metal recovery paths, documented per line | Backup & Continuity |
| 45 CFR 164.308(a)(7)(ii)(C) | Emergency mode operation plan | Required | Recovery copies held outside the affected estate so operations can be resumed from unaffected infrastructure | Backup & Continuity |
| 45 CFR 164.308(a)(7)(ii)(D) | Testing and revision procedures | Addressable | Automated weekly or monthly restore testing returning proof that a recovery succeeded | Backup & Continuity |
| 45 CFR 164.308(a)(7)(ii)(E) | Applications and data criticality analysis | Addressable | The coverage you select and the systems you nominate for testing are the record of that analysis | Backup & Continuity |
| 45 CFR 164.310(d)(1) | Device and media controls | Standard | A maintained register of devices across Windows, macOS, Linux, Apple hardware and mobile | Endpoint Management |
| 45 CFR 164.310(d)(2)(iv) | Data backup and storage | Addressable | A retrievable copy taken before equipment is moved or retired | Backup & Continuity Endpoint Management |
| 45 CFR 164.312(a)(1) | Access control | Standard | Restricting which programs may execute narrows the same question from the execution side | Zero Trust Allowlisting |
| 45 CFR 164.312(a)(2)(iii) | Automatic logoff | Addressable | Screen lock and timeout profiles enforced on managed devices rather than asserted in policy | Endpoint Management |
| 45 CFR 164.312(a)(2)(iv) | Encryption and decryption | Addressable | 256-bit AES on everything held for you, and dynamic file encryption on the enforcement line | Backup & Continuity PHI Data Protection |
| 45 CFR 164.312(b) | Audit controls | Required | Endpoint agents recording and examining activity, with the examination performed by people | Managed Detection |
| 45 CFR 164.312(c)(1) | Integrity | Standard | Independent copies that make improper alteration or destruction detectable and reversible | Backup & Continuity |
| 45 CFR 164.312(e)(1) | Transmission security | Standard | TLS in transit on everything we carry, plus channel control over how secured files may leave | Backup & Continuity PHI Data Protection |
| 45 CFR 164.312(e)(2)(ii) | Encryption in transit | Addressable | Transport encryption on every backup and platform connector | Backup & Continuity |
| 45 CFR 164.308(b)(1) | Business associate contracts | Standard | Fortify 24x7 executes a Business Associate Agreement before enabling any service that may touch protected health information | Contractual, not technical |
How the 24 lines divide.
- Managed Detection covers 6 of the 24 lines, built on SentinelOne, with Fluency analytics.
- Email Defense covers 2 of the 24 lines, built on Ironscales.
- Zero Trust Allowlisting covers 1 of the 24 lines, built on ThreatLocker.
- Endpoint Management covers 4 of the 24 lines, built on N-able N-sight, Addigy, and Zimperium.
- PHI Data Protection covers 2 of the 24 lines, built on Actifile.
- Backup & Continuity covers 9 of the 24 lines, built on N-able Cove and Dropsuite.
Lines are bought individually. There is no bundle, no seat minimum, and no annual commitment, so a program can begin with the two or three safeguards your last risk analysis flagged and grow from there.
Safeguards that stay with you, whatever you buy here.
An honest map has to name its own edges. The following are your obligations, and no service on this site discharges them.
Administrative. Assigning a security official, workforce clearance and termination procedures, authorization and supervision, sanction policy, and the risk analysis and risk management process itself. We produce input to your risk analysis; we do not perform it.
Physical. Facility access controls, workstation use and security policy, and the physical disposal of media. We can report which devices exist; we cannot control who walks past them.
Technical, in part. Unique user identification, emergency access procedures, and person or entity authentication are configured in your clinical and productivity systems, not in ours.
Privacy Rule obligations entirely. Notice of privacy practices, minimum necessary, patient rights of access and amendment, accounting of disclosures, and authorizations sit outside the Security Rule and outside this catalog. Discovery output can inform a minimum necessary review, but the review is yours.
How we describe this work
There is no such thing as a HIPAA certified product, and no vendor can place your organization in compliance. Compliance is a program you own: your risk analysis, your policies, your workforce training, your documentation. What we supply are technical services and the evidence they generate, mapped to the safeguards in the HIPAA Security Rule so your compliance team can point at something concrete.
Nothing described on this site guarantees a compliance outcome, an audit result, or immunity from a breach. Determinations about your obligations belong to your privacy officer and your counsel. Fortify 24x7 executes a Business Associate Agreement before enabling any service that may create, receive, maintain, or transmit protected health information on your behalf.
Heads up: card statements show FORTIFY 24X7 - MediShield IT is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.