A Fortify 24x7 brand. Security run the way a triage station runs: sorted, tagged, and watched.Sign inRaise a consult
MediDefense IT
Station note B / Admissions

Nothing runs on that machine unless somebody admitted it first.

Detection asks whether a thing looks wrong. Admissions asks something shorter: was this on the list. Across hardware touching charts, images and claims, naming what may start beats trusting a scanner to recognise next month's novelty.

ThreatLockerDeny unless admittedApprovals worked around the clock
One line, default deny, approvals worked by people
Lines here1
KitThreatLocker
Counted byEndpoint
Standing positionDeny unless admitted

Why a roster beats recognition

Recognising harmful software means being correct about something never encountered before, on every attempt, on a PC also running an imaging client from 2013. That is a losing structure, and no amount of engineering fixes the structure. Admissions turns the question around. Your practice's real software gets on the list. Everything absent is refused, and no judgement about how suspicious it looked is required.

Nobody writes the list up front. A watching period records what a clinic genuinely uses, invariably odder than any supplier documentation suggests, and the roster gets assembled out of that. Supplier releases get followed separately, so reception is never staring at a frozen scheduling client while somebody hunts down an approval.

The roster comes out of what your practice genuinely uses, which is always odder than the vendor documentation implies.

What it feels like during a clinic day

The fair objection is interruption. It happens, on the day something genuinely new needs to run, and the answer is where the request goes. It reaches a staffed desk, an engineer reads what was asked for, and it is either admitted or explained. Either way the exchange is on the record.

Ringfencing is the underrated half. Software can be completely legitimate and still have no business opening a folder of referrals or reaching an address in another country. Ringfencing fixes the boundaries of what an admitted program may touch, which is what keeps the damage small on the day a legitimate tool is turned against your practice.

Lines at this station

The lines themselves

Rates come live from billing. Anything tagged waits on the chart while you carry on reading.

Fortify-ZeroTrustLine specification

Execution Control

ThreatLocker · nothing starts unless it is on the roster

One list of what may start, and a flat refusal for anything absent from it. Across hardware that opens charts, images and claims, that position holds up far better than trusting a scanner to recognise next month's novelty.

  • A watching period assembles the list from software your clinic genuinely uses.
  • Supplier releases get tracked, so reception is not locked out on a Tuesday.
  • Ringfencing bounds the files, processes and addresses an admitted program reaches.
Fitted toWindows and macOS endpoints that will accept an agent
WatchesEach attempt to start, and where an admitted program goes afterwards
Kept forA trail of admissions, refusals and requests for elevated rights
Escalates toA request at our desk, which is staffed at every hour
Reviewed byAn engineer, on each request, ahead of anything joining the list
Readingper endpoint
charged monthly, up front
QTY
Referred out

Handed back at this station

Each station has an edge to it, and clinics get caught out by suppliers who pretend otherwise. Below is where this one stops, set down so a practice can work out what else it needs and who else has to supply it.

  • Sealed equipment is out of reach. Where a manufacturer forbids outside software on a device, this line goes nowhere near it. Expect a plain list of which equipment sits in that group, and what we would put around it instead.
  • Approvals need answering. Our desk is staffed, and the opening fortnight still generates more requests than the months after it. A practice unable to absorb any interruption over that stretch should raise it at intake, not once the roster is learning.
  • An admitted program can still be turned. The list refuses unapproved code. What it cannot do is stop somebody using approved software for something they should not be doing at all. Access control and supervision answer that, and both live inside your practice.
  • Patching is a different job. Refusing unknown code does nothing about a flaw in code you deliberately admitted. That work sits at the Rounds station, and there is a reason the two get bought together.
  • It supports a safeguard without certifying one. Execution control is evidence towards the malicious software and access control expectations in a HIPAA security program. Your own risk analysis still has to make that argument, in your own words.
NOTE 01

Heads up: card statements show FORTIFY 24X7 - MediDefense IT is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.