A Fortify 24x7 brand. Lock work for practices, clinics, and the offices that bill for them.Client sign inAsk a locksmith
Health Lock Solutions
Keyway 02 / What is allowed to run

A deadbolt does not negotiate with what is on the other side.

Detection asks whether something looks wrong. Allowlisting asks a shorter question: was this approved. On a machine that opens patient records, the shorter question is usually the better one, because it has an answer before anything has run.

ThreatLockerLearning period firstWe hold the elevation queue
1 line / default deny / one bench holding the approvals
Lines on this keyway1
PlatformThreatLocker
Counted byEndpoint
ApprovalsHeld at our bench

Why the shorter question wins

Practices run a small, knowable set of software. A practice management system, an imaging viewer, a clearinghouse client, a browser, an office suite, a handful of utilities. That is a list somebody can write down. Once it is written down, everything outside it can be refused without a debate, and the ransomware payload delivered in an attachment simply never executes.

The catch is that a badly run allowlist is worse than none, because staff learn to work around it and eventually somebody is given permanent administrator rights to make the problem stop. So the line begins with a learning period against your real estate, and the approval queue is worked by our engineers rather than dropped on whoever answers the phone at your front desk.

A badly run allowlist is worse than none, because staff learn to work around it.

What happens when a vendor ships an update

Clinical software updates whenever it feels like it and rarely warns a soul. ThreatLocker follows those releases, so an ordinary patch does not shut a hygienist out of the imaging viewer at nine on a Monday, and where something genuinely new shows up the request arrives with us instead of stalling.

Elevation is handled the same way. A member of staff who needs to run something once asks for it, our bench reviews the request, and the decision is recorded. Nobody ends up holding standing administrator rights because it was the fastest way to get through a Tuesday.

Cut cards

One cut card, with a live rate.

The figure below comes straight out of billing. Add it here and it waits on the keyring while you read the rest.

Fortify-ZeroTrustCut card

Execution Control

ThreatLocker, learning first and then holding

A deadbolt does not negotiate with whatever is on the other side of the door. Allowlisting behaves the same way. Software your practice actually uses runs, and everything else is refused before it gets a chance to argue its case.

  • Approvals and elevation requests are worked by our bench, not dropped on your office manager.
  • Vendor releases are followed, which stops an ordinary patch from shutting a clinician out of a tool halfway down a list.
  • A learning period comes first, so the list reflects the software your practice genuinely runs.
P11P22P34P45P55
Cut forEndpoints where the software list ought to be fixed, known and small
Turns onThreatLocker
Held inPolicy and approval history in the ThreatLocker tenant raised for you
RekeyedApprovals worked continuously; the ruleset reviewed as your software changes
Master levelFortify 24x7 holds elevation requests and escalation
Readingper endpoint
billed monthly, in advance
QTY
Honest scope

What this cut does not open

Refusing everything unapproved is a powerful control of a very particular shape. Below is the edge of its reach.

  • It does not replace detection. An approved program can still be misused, and a signed tool already on your allowlist can be turned to somebody else's purpose. Allowlisting narrows what is possible; it does not watch what the survivors are doing. That is the detection keyway.
  • Devices you do not manage stay outside. Somebody's own laptop, a contractor's machine, or a tablet bought for the waiting room cannot be held to this policy while it stays unenrolled. Off the line means outside the cover.
  • Locked clinical hardware is out of reach. Imaging and diagnostic systems under manufacturer control routinely prohibit extra software. Nothing gets installed onto them by us, no pretence is made that it does, and during fitting you are told exactly which of your machines belong in that category.
  • The first fortnight is noisier than the rest. Learning mode has to see your real working pattern before it can be trusted, and the weeks immediately after it are when the odd exception surfaces. Plan for a few conversations rather than a silent switch.
  • Your cloud tenants are none of its business. This line governs what executes on an endpoint. What happens inside Microsoft 365 or Google Workspace is a different problem, addressed by the mail and identity work elsewhere in this catalog.
STAMP 01

Heads up: card statements show FORTIFY 24X7 - Health Lock Solutions is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.