A Fortify 24x7 brand. Security and continuity services for healthcare organizations across the United States.Client sign inContact
MediShield IT
Home / Services / PHI Discovery and Egress Control
Service family · PHI data protection

PHI Discovery and Egress Control

Find where protected health information has quietly accumulated across your endpoints, then control the ways it can leave.

Lines in this family Published monthly rates, billed in advance
PHI Discovery and Risk BaselineFortify-DLP-Classify · per endpoint

Actifile scans endpoints for identifiers and payment card data, then produces a per-device breakdown of where sensitive material is sitting unprotected.

LoadingQTY
PHI Egress ControlFortify-DLP-Enforce · per endpoint

Everything discovery does, plus dynamic file encryption, multiple compliance profiles, and control over the applications and channels data may leave by.

LoadingQTY
01The sprawl

Health information migrates, and nobody signs for it.

Protected health information is supposed to live in the clinical system. In practice it also lives in a scan folder full of referral faxes, an eligibility export somebody saved to a laptop before a meeting, a spreadsheet of record numbers built for a recall campaign in 2019, and a statement run sitting in a shared mailbox nobody has opened since.

None of that was misconduct. Every one of those files was created by somebody doing their job with the tools they had. But each one widens the surface your risk analysis has to account for, and none of them appear in the system inventory, because they are not systems. They are files.

The first honest question in a risk analysis is where the information actually is, and most organizations answer it from memory. Discovery replaces the memory with a list.

02Discovery

What the baseline line produces.

Both lines are built on Actifile, which scans Windows, macOS, and Linux endpoints for personally identifying information and payment card data and returns findings by device rather than as a single aggregate number. Reporting by device is the detail that makes the output actionable: an aggregate figure starts an argument, whereas a named machine starts a task.

  • A data breach risk baseline, which is the starting measurement everything afterwards is compared against.
  • A per-device breakdown of insecure data, so remediation can be assigned to a machine and an owner instead of discussed in the abstract.
  • Vulnerability scanning with trend reporting, so the direction of travel is visible over quarters. A board or a compliance committee understands a trend line better than a snapshot, and the trend is the more honest artifact.

The output is deliberately uncomfortable the first time it runs. That is the point of it. A baseline that reports nothing has almost certainly been scoped too narrowly.

HIPAA Security Rule

Input to the risk analysis, and the encryption behind the safe harbor

Risk analysis is the first required implementation specification in the Security Rule: an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by your organization. The words that carry the weight are accurate and held by. You cannot be accurate about information you have not located, and discovery output is evidence toward that accuracy. It is an input to your analysis; it is not the analysis, and no scan can be.

The enforcement line adds encryption and decryption at the file level, which is an addressable specification under access control, and supports the transmission security standard where files leave by controlled channels.

Encryption carries one further consequence worth stating precisely. Under the Breach Notification Rule, a breach concerns unsecured protected health information, meaning information not rendered unusable, unreadable, or indecipherable to unauthorized persons through a method specified in guidance from the Department of Health and Human Services. Properly encrypted information that meets that guidance falls outside the definition. This is a narrow technical point, not a promise that an encrypted organization never notifies, and whether it applies to a particular incident is a determination for your privacy officer and your counsel.

45 CFR 164.308(a)(1)(ii)(A)45 CFR 164.312(a)(2)(iv)45 CFR 164.312(e)(1)45 CFR 164.402
03Enforcement

From knowing to controlling.

The enforcement line is the same Actifile agent with its controlling half switched on. It includes everything discovery does and adds three capabilities.

  • Dynamic encryption and decryption of files, applied on the endpoint so protection travels with the file rather than with the folder it happened to be sitting in.
  • Multiple compliance profiles, which matters for organizations subject to more than one regime at once: a practice that also takes card payments, or a group operating in a state whose health privacy statute reaches further than the federal floor.
  • Application and channel allowlisting for secured data, which defines the routes by which protected material may leave: which applications may open it, and which channels may carry it.

The usual sequence is discovery first for a quarter, then enforcement once you know what enforcement will actually catch. Turning on controls before you know where the data is produces a wave of interruptions and a policy that gets switched off.

04Reading it

What to do with the first report.

Expect three categories. Material that should never have been there is deleted, and the process that created it is corrected. Material that belongs somewhere else is moved into the clinical system where the existing controls already apply. Material that genuinely has to live on an endpoint is the residue, and it is the case for the enforcement line.

Work the largest concentrations first rather than the longest list. One export holding thousands of records is a more urgent finding than four hundred files holding one apiece, and the report is ordered to make that visible.

Technical specificationTwo lines · per endpoint
PlatformActifile, operated on your behalf by Fortify 24x7
PlatformsWindows, macOS, and Linux endpoints
DiscoveredPersonally identifying information and payment card data
BaselineA data breach risk baseline with per-device breakdowns of insecure data
ScanningVulnerability scanning with trend reporting over time
EncryptionDynamic encryption and decryption of files on the enforcement line
Compliance profilesMultiple concurrent profiles on the enforcement line
Channel controlApplication and channel allowlisting for secured data
Evidence producedDated discovery reports, risk trend history, per-device findings
Billing unitPer endpoint, per month

Where these lines stop

Pattern matching is not comprehension. Discovery finds structured identifiers and card data by pattern. It will report findings that turn out to be harmless, and it will miss health information expressed as free clinical narrative with no identifier beside it. Treat the output as a lead list a person reviews, never as a verdict.

Images are the known gap. A scanned referral saved as an image carries no extractable text, so pattern matching does not reach it. Where scanned documents are a large part of your estate, say so during scoping and we will describe honestly what will and will not be seen.

Endpoints, not servers or cloud platforms. These lines scan endpoints. Information inside the clinical database, the imaging archive, or a cloud platform is governed by the controls of those systems and by the backup family here, not by this one.

Encryption does not defeat an authorized user. Someone entitled to open a file can read it, and dynamic encryption does not change that. Deliberate misuse by an authorized person is an access-management and audit problem, which is why this family is bought alongside detection rather than instead of it.

How we describe this work

There is no such thing as a HIPAA certified product, and no vendor can place your organization in compliance. Compliance is a program you own: your risk analysis, your policies, your workforce training, your documentation. What we supply are technical services and the evidence they generate, mapped to the safeguards in the HIPAA Security Rule so your compliance team can point at something concrete.

Nothing described on this site guarantees a compliance outcome, an audit result, or immunity from a breach. Determinations about your obligations belong to your privacy officer and your counsel. Fortify 24x7 executes a Business Associate Agreement before enabling any service that may create, receive, maintain, or transmit protected health information on your behalf.

FORTIFY 24X7

Heads up: card statements show FORTIFY 24X7 - MediShield IT is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.

Managed DetectionEmail DefenseZero Trust AllowlistingEndpoint ManagementBackup & Continuity