Twenty-four hour SOC monitoring on the workstation or server, with a SentinelOne agent doing the detection on the device itself.
Detection widened past the endpoint to email, servers, cloud workloads, and directory activity, correlated in one place by the SOC.
Cross-layer detection where our analysts perform the containment and cleanup themselves instead of handing you a ticket.
The same monitored coverage for containerized workloads, for groups running interface engines, imaging pipelines, or analytics on Kubernetes.
Cross-layer detection for container hosts, with SOC remediation of confirmed events included rather than quoted separately.
Analyst-performed remediation extended to Kubernetes nodes, for estates where clinical services run on containers.
Prevention fails quietly, and the quiet is the problem.
Nobody buys detection because prevention is worthless. They buy it because prevention is silent when it loses. An intruder who arrives through a reused password or a signed remote access tool has not triggered anything: no file was dropped, no signature matched, and the tooling in front of them is behaving exactly as designed.
What follows in a healthcare environment is unusually methodical. Credentials are collected, the directory is enumerated, and the intruder moves toward the shares that hold scanned referrals, remittance advice, and imaging exports. Encryption, if it comes, comes last, after the useful material has already left. The interval between arrival and encryption is the only period in which anything can still be done cheaply, and it is measured in days, not months.
Closing that interval requires two things a product alone cannot supply: detection based on behavior rather than known-bad indicators, and a human being who is paid to look at what it produces at the hour it appears.
The agent decides locally. The analyst decides what it meant.
Every line in this family installs a SentinelOne agent on the protected machine. Detection is evaluated on the device itself, which matters more in this sector than in most: a laptop taken to a satellite clinic, a home office, or a conference keeps its full protection with no dependence on reaching a cloud service first.
What the agent produces flows into Fluency, the analytics and correlation layer we operate behind these lines. Fluency is where a single endpoint detection stops being an isolated alert and becomes part of a picture: the same account seen authenticating somewhere unusual, the same destination contacted from a second machine, the mailbox rule created twenty minutes earlier. From there it reaches the Fortify 24x7 security operations desk, which runs continuously. Analysts triage the detection, determine whether it represents activity a person actually performed, and escalate to your named contacts when it does not. Every step is recorded with a timestamp and an author, which is the part your documentation obligations care about.
- The MDR lines deliver monitoring, alerting, and the endpoint agent. Your team performs the remediation, with our analysts advising.
- The XDR lines widen the telemetry SentinelOne and Fluency see past the endpoint to email, servers, cloud workloads on AWS, Azure, and Google Cloud, network traffic, and Active Directory, and correlate it in one place. The integrated modules are next-generation antivirus, endpoint detection and response, user and entity behavior analytics, network traffic analysis, cloud workload protection, and a security information and event management layer.
- The plus lines add direct remediation: our analysts carry out the containment and cleanup on every identified event rather than handing your practice manager a ticket at nine on a Saturday.
- The Kubernetes variants apply the same coverage to container nodes, which is where interface engines, imaging pipelines, and analytics workloads increasingly run in larger groups.
What this family evidences, and what it does not
The Security Rule asks you to regularly review records of information system activity and to implement hardware, software, or procedural mechanisms that record and examine activity in systems containing electronic protected health information. A console that logs faithfully and is opened twice a year satisfies the first half of that sentence and fails the second. The review is the control.
It also asks you to identify and respond to suspected or known security incidents, mitigate their harmful effects, and document both the incident and its outcome. On the remediation lines our analysts perform the mitigation themselves, and the case record they leave behind is the documentation half of that requirement, already written.
None of this decides whether an incident was a reportable breach. That determination runs through the risk assessment in the Breach Notification Rule and belongs to your privacy officer and your counsel. What we supply is the factual record they will need in order to make it.
Which line belongs on which machine.
Most organizations do not run one line across the whole estate, and they should not. The question is what a given machine touches and who is available to act when something happens on it.
- MDR suits an estate with in-house technical staff who can act on an escalation during business hours, on machines that hold or reach protected health information but are not the center of the practice.
- XDR suits organizations that also want mailbox, server, cloud, and directory activity correlated with the endpoint, which is where account takeover and business email compromise become visible as one story rather than four unrelated alerts.
- XDR with SOC remediation suits practices, clinics, and dental and behavioral health groups with no security staff of their own, where the honest answer to who contains an incident at midnight is nobody.
- Kubernetes lines are priced per node and belong on container hosts, not on the workstations that talk to them.
Mixing lines across one estate is normal and carries no penalty. Quantities are adjusted from the portal as machines are added or retired, and a change applies to the following invoice.
What an escalation actually looks like.
A billing coordinator opens an attachment that launches a signed scripting host, which reaches out to an address nobody in your organization has ever contacted. The agent scores the behavior, not the file, and halts the process tree on the workstation.
Within minutes an analyst has the sequence assembled in Fluency: the parent process, the network destination, the credentials in use, and whether the same pattern appeared anywhere else in your estate in the preceding hours. On a remediation line the machine is isolated and cleaned before anyone in the practice has finished reading the email that started it. On a monitoring line the same package reaches your team with a recommendation attached.
Either way you end the day with a dated record of what happened, what was done, and what was ruled out. That artifact is worth as much as the containment, because it is the thing you are asked to produce six months later.
| Platform | SentinelOne on the endpoint, Fluency for analytics, operated on your behalf by Fortify 24x7 |
|---|---|
| Detection engine | SentinelOne agent, evaluated on the device rather than in a cloud lookup |
| Analytics layer | Fluency, correlating endpoint detections with account, mail, and network activity across the estate |
| Monitoring | Fortify 24x7 security operations desk, continuous |
| MDR coverage | Endpoint detection, SOC monitoring and alerting |
| XDR coverage | Endpoints, email, servers, cloud workloads on AWS, Azure and Google Cloud, network traffic, and Active Directory |
| XDR modules | NGAV · EDR · UEBA · NTA · Cloud workload protection · SIEM |
| Remediation | Advisory on the MDR and XDR lines; performed by our analysts on the plus lines |
| Container support | Kubernetes agent on the K8 lines, priced per node |
| Detection basis | Behavioral models and machine learning, aimed at fileless techniques, credential theft, ransomware staging, and lateral movement |
| Evidence produced | Timestamped detection, triage and action records available through your account |
| Billing unit | Per endpoint, or per Kubernetes node, per month |
Where these lines stop
This family detects and responds. It does not administer your access controls. Unique user identification, emergency access procedures, automatic logoff, and the authorization decisions behind them remain yours to configure and to document.
An agent has to be installable. Imaging modalities, infusion pumps, laboratory analyzers, and similar embedded clinical equipment frequently run vendor-locked operating systems that accept no third-party software. Those devices are protected by network segmentation and vendor maintenance agreements, which are engineering work outside this catalog. Tell us where they are during scoping so nobody records coverage that does not exist.
Personally owned devices are not covered unless enrolled. A clinician reading mail on an unmanaged phone sits outside this family entirely.
Monitoring lines do not include remediation. If nobody on your side is available to contain an incident out of hours, the honest choice is a plus line rather than a monitoring line and an intention.
How we describe this work
There is no such thing as a HIPAA certified product, and no vendor can place your organization in compliance. Compliance is a program you own: your risk analysis, your policies, your workforce training, your documentation. What we supply are technical services and the evidence they generate, mapped to the safeguards in the HIPAA Security Rule so your compliance team can point at something concrete.
Nothing described on this site guarantees a compliance outcome, an audit result, or immunity from a breach. Determinations about your obligations belong to your privacy officer and your counsel. Fortify 24x7 executes a Business Associate Agreement before enabling any service that may create, receive, maintain, or transmit protected health information on your behalf.
Heads up: card statements show FORTIFY 24X7 - MediShield IT is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.