Fortress MSP

Fortress MSP Grow fearlessly. Focus on what you do best and scale your business without tech holding you back. We manage the hackers so you can focus on growth.

We protect AZ & OH businesses, CPAs, and law firms from costly downtime and compliance headaches.

Patient data does not have to be leaked to be exposed. If it lives in a personal inbox, the problem is already there.A l...
06/18/2026

Patient data does not have to be leaked to be exposed. If it lives in a personal inbox, the problem is already there.
A lot of medical practices that I have been meeting with lately are built on a personal email account. A Gmail address set up in the early days because it was free and it worked. A front desk that uses a Yahoo or Hotmail address nobody ever stopped to question. It carried the practice through the first year, then the fifth, and it never seemed worth changing.

Nothing about that feels wrong. You are a clinician, not an IT director, and you did what almost every small practice does. This is not a story about carelessness. It is about a gap that has been sitting quietly in the background and one fact that surprises most owners when they hear it. The risk here does not wait for a breach. If patient information is moving through a personal email account, the problem is already present.

The one piece of jargon worth knowing
There is a single term in HIPAA worth understanding, because the rest of this hangs on it. It is called a Business Associate Agreement, usually shortened to BAA.

In plain terms, it is a contract between your practice and any outside company that handles patient information for you. In it, that company formally promises to protect the data to HIPAA standards and to take responsibility for its part. HIPAA requires you to have one with every vendor that touches patient information.

Here is the catch. The free, personal versions of Gmail, Yahoo, and Outlook will not sign one. The paid business versions will. No signed agreement means the company has made no promise and your practice has no coverage. Because there is no agreement standing behind a personal email account, it's not a gray area; it's as black and white as it's going to get.

You do not need a breach to be exposed
Most owners measure their risk by whether something bad has happened yet. No breach, no problem. But the gap is not the breach. The gap is the patient information sitting in an account that no agreement covers and that the practice does not control. That exposure exists right now, on an ordinary Tuesday, with nothing going wrong.

And here is the part that catches people off guard. You might assume that only charts, lab results, and diagnoses count as protected information. In the hands of a medical practice, far less than that is protected. A patient's name sitting next to their email address is protected because the fact that this person is your patient is itself private health information. It reveals they came to you for care. So the simple list of patient contacts in a personal inbox is already the thing HIPAA asks you to protect. Whether a specific item counts in your situation is a question for your compliance advisor. The point worth sitting with is that the line is far lower than most people assume.

You cannot fully control your own inbox
When patient information lives in a personal inbox, it lives outside your practice. You cannot see who has opened it. You cannot require the strong sign-in protections that business systems can enforce. You cannot keep records the way the rule expects. And when the front desk person who used that account leaves, a year of patient messages can walk out the door on their personal phone, with nothing you can do to pull it back.

It runs the other way too, and this is the part practices rarely think about. You cannot stop a patient from emailing you. Someone sends a message to the email address they have, describing their symptoms, attaching a photo, or asking about a prescription. You never asked for it. It does not matter. The moment it lands in an account you do not control, your practice is holding patient information in a place it should not be, and you had no way to prevent it. The exposure arrives in your inbox whether you invited it or not.

Free email was never built for this
Consumer email is also not built to keep messages private the way patient data requires. A message can travel between mail systems in a form that someone in the middle could read, and the copies sitting in the inbox are not necessarily protected either. The business versions of these platforms can be set up to close those gaps that the free versions were never designed to.

None of this means Gmail or Yahoo are bad. They are consumer products, built for personal life, doing a job they were never meant to do for a medical practice. The encouraging part is that the fix is smaller than most practices expect. Closing the gap is a short, concrete project:

Move patient information off personal and consumer email and onto a business platform that will sign that agreement. Set the platform up the way the rule expects, with strong sign-in, protected messages, controlled access, and proper records, because signing the agreement is only the first step, not the finish line. Then give your team one clear rule: patient information only moves through the approved, protected channels.

That is usually a few dollars per person each month and a migration measured in days, not months.

What good looks like
A practice that has implemented using a professional email service is not living in quiet worry about an audit. Patient information sits somewhere the practice owns and can account for. When a patient asks whether their information is safe with you, the answer is simple and true. When your malpractice carrier or an auditor asks how you protect it, you have something real to show them instead of a hopeful shrug.

The quieter alternative
The other version does not announce itself. The personal account falls into the wrong hands through one reused password. Or it is not a breach at all that starts the trouble but a single complaint from a frustrated patient or a former employee that brings a regulator's question. The first thing they ask for is your agreements and your records. "We use Gmail" is not an answer that survives that question.

We help practices make this move, the business email, the agreement, the setup, and the security program around it. What your specific obligations require, and whether any past situation needs reporting, is a conversation for your compliance advisor. Our job is to make the technical reality solid and provable.

If you are not sure where patient information actually lives in your practice today, that is where we start. Book Your Medical Practice Security Briefing at booking.fortressmsp.com, and we will find it together.

It was great to finally make it to a Marysville Business Association meeting today. A huge thank you to CoverLink Insura...
06/17/2026

It was great to finally make it to a Marysville Business Association meeting today. A huge thank you to CoverLink Insurance Marysville for the awesome raffle price that we won today. If you're a business in Union County, I highly recommend coming to their next event!

Buy-In Was Never Your Problem. Visibility Is the New Bar.Two-thirds of professional firms now rank cyberattacks as their...
06/15/2026

Buy-In Was Never Your Problem. Visibility Is the New Bar.

Two-thirds of professional firms now rank cyberattacks as their top business risk. That quietly changes the question every owner has to answer.
Something shifted this year, and it is worth your attention.

The Conference Board and the Business Council survey the chief executives of some of the world's largest companies every quarter. In the second quarter of 2026, 65% of them named cyberattacks their top business risk, up from 56% just one quarter earlier. Cyber now sits ahead of inflation, trade disruption, and geopolitical instability on the list of things that keep blue-chip CEOs up at night.

That alone would be easy to file under "interesting, but not about me." Except the same shift is showing up one tier down, right at your door. A 2026 survey of professional firms in legal, financial, and consulting services found 65% of them ranked cyberattacks as their number one concern, far ahead of economic pressure at 18%. The largest companies in the world and the small firm down the street landed on the same number.

For years, the people who work in security made one argument over and over. Cyber risk is a business problem, not just an IT problem. That argument is over. It won. And winning it created a new one.

The bar moved from caring to showing
When everyone agrees that cybersecurity matters, "we take security seriously" stops being a meaningful statement. Of course you do. So does everyone. The bar moved. It is no longer whether you care about protecting client data. It is whether you can show what you have decided, what you have put in place, what risks you have consciously accepted, and who owns each piece.

For a large company, that shift exposed a real gap, because their security teams were often building controls without documenting the decisions behind them. For your firm, the gap is different, and in some ways simpler. You never lacked the will. You are the owner. You already care, probably more than any hired executive would. What you most likely do not have is a written, defensible picture of your security that someone outside the firm could pick up and understand.

Why this is landing on your desk now
Here is the part that makes this urgent rather than theoretical. The new bar is reaching regulated firms through three doors, and none of them are waiting for you to be ready.

Your larger clients have started sending security questionnaires before they renew, because your firm is a link in their supply chain and their own risk teams are under the same pressure you are reading about here. Your cyber insurance renewal has quietly turned into an audit, with attestations you are signing whether or not you can back them up. And your regulator has been asking for this all along. The FTC Safeguards Rule expects a written information security program. HIPAA expects a documented risk analysis. The thing the Fortune 500 just woke up to is the thing your own rules required years ago.

In a regulated profession, doing the work is not enough
You already know this in every other part of your practice. A conclusion you cannot support is not worth much. A file with no workpapers behind it does not hold up. Security is no different now. The work has to exist, and it has to be visible. That is not bureaucracy. It is the same standard you hold yourself to everywhere else.

What showing your work actually takes
Closing this gap has two halves, and they work together.

The first is the technical controls. The industry has largely converged on a clear direction: deny by default, grant the least access necessary, and verify identity with more than a password. We implement these exact controls for the firms we protect, scaled to a firm your size rather than a global enterprise. Done right, they shrink the number of ways an attacker can get in to a small fraction of what most firms leave open.

The second half is the part most firms miss. A documented security program that records what is protected, what decisions have been made, what risks have been knowingly accepted, what is still in progress, and who owns each one. The kind of record you can hand to a client's procurement team, an insurer, or a regulator and have it answer their questions for you. Someone has to own that visibility. For a firm that does not want to hire a full-time security executive, and most firms your size neither need nor want that cost, owning it does not have to mean a six-figure addition to your payroll.

We build and operate the controls and keep that documentation current. What your specific obligations require, the legal and regulatory interpretation, stays with your counsel. We make sure the technical reality behind it is real and provable.

What good looks like
A firm that has done this work is not more anxious than yours. It is calmer. The questionnaire arrives, and it is an hour of work, not a week of dread. The insurance renewal is straightforward, and the premium reflects it. The larger client's risk team asks how you protect their data, and you send them something real. The rising tide of attention becomes the thing that wins you work, because you can show what your competitor only claims.

The alternative
The other version is quieter and more common. The questionnaire arrives, and you stall. "We're working on it." The renewal asks a question you cannot answer cleanly. A larger client moves to a competitor who could show their work, and you never learn that was the reason. Or the gap surfaces during an actual incident, which is the most expensive possible moment to find it.

The trend is real, and it is reaching you. The good news is that you were never short on the hard part, which is caring. What is left is making it visible, and that is a finite, doable project with a clear beginning.

If you want a straight answer to "where do we actually stand," that is where we start. Book your Operational Resilience Briefing at booking.fortressmsp.com, and we will find what you have, document what matters, and make sure your answer is ready before someone asks for it.

May the 4th be with you, and may your SOC be with you, too. (Yes, that's a Security Operations Center joke. Yes, I'm tha...
05/04/2026

May the 4th be with you, and may your SOC be with you, too.
(Yes, that's a Security Operations Center joke. Yes, I'm that guy) 😅

Attention Central Ohio Financial Advisors and RIAs: You’re currently fighting a two-front war. 🛡️On one side, cybercrimi...
04/23/2026

Attention Central Ohio Financial Advisors and RIAs: You’re currently fighting a two-front war. 🛡️

On one side, cybercriminals are bypassing the big Wall Street banks to target independent wealth managers. On the other side, the SEC is dropping a strict new Regulation S-P compliance deadline on June 3, 2026.

It’s easy to feel overwhelmed, but here is the good news: You don't need a multi-million dollar corporate IT budget to protect your clients' wealth or satisfy the auditors.

In our latest LinkedIn article, we break down the 3 simple, executive-level guardrails you can implement right now to lock down your firm and get back to doing what you do best.

Read "The Hackers Are Coming. The SEC Auditors Are Right Behind Them." and learn how to secure your firm so you can Grow Fearlessly. 👇

https://lnkd.in/g5RA7YpB

We had a great time at our donut meet-and-greet at Brick House Blue earlier this morning.It was great connecting with fe...
04/22/2026

We had a great time at our donut meet-and-greet at Brick House Blue earlier this morning.

It was great connecting with fellow local businesses, and even better realizing some of the people we met are also neighbors. We love when community and business overlap in the best way.

At Fortress MSP, we’re proud to help local businesses stay secure, supported, and running smoothly.

If you run a business and have IT support or cybersecurity questions, feel free to reach out.

"Our cloud software is HIPAA/CMMC compliant, so our data is covered."As an MSSP, this is one of the most common, and pro...
04/16/2026

"Our cloud software is HIPAA/CMMC compliant, so our data is covered."

As an MSSP, this is one of the most common, and probably most dangerous misconceptions I hear from business leaders operating in regulated industries (healthcare, defense, finance, etc.).

Here is the harsh truth: Compliant software cannot protect you from an unmanaged device. If your team is accessing sensitive patient data, financial records, or government contracts from their personal, unmanaged iPhones/Android phones or home laptops, you are likely failing your compliance requirements.

Think of it like buying a state-of-the-art titanium bank vault door but installing it on a canvas tent.

You might have the most secure SaaS platform on the market, but when you allow unmanaged personal devices to access that regulated data:

You lack visibility: You have no way of knowing if that employee's personal device is already infected with malware or running an outdated, vulnerable operating system.

You lack control: If an employee quits or loses their phone in a coffee shop, you cannot remotely wipe your company's regulated data off of it.

You fail the audit: Regulators (whether the FTC, DoD, or HHS) don't just care where your data is stored; they care exactly how it is accessed, who has access, and how you control the endpoints.

You don't own the device, which means you don't control the data.
The solution isn't to ban remote work or force everyone to carry two phones. The solution is implementing Mobile Device Management (MDM). It creates a secure, encrypted, and wipeable corporate "sandbox" on your team's personal devices, satisfying regulators without invading your employees' personal privacy.

Don't let a $600 personal smartphone be the reason your business fails a six-figure compliance audit. Secure the endpoints.

Schedule a brief compliance consultation today at booking.fortressmsp.com

The creators of Claude just built an AI so good at hacking, they locked it in a vault and called their biggest rivals, A...
04/09/2026

The creators of Claude just built an AI so good at hacking, they locked it in a vault and called their biggest rivals, Apple, Google, and Microsoft, to form an emergency defense coalition.

If Big Tech is hitting the panic button, where does that leave your business?
It’s easy to read the headlines and feel outgunned. But you don't need a billion-dollar budget to defend your network against next-gen threats. You just need to upgrade your management playbook.

Stop letting cyber threats dictate your strategy. Read our latest article to learn the 3 simple steps every CEO can take today to protect their team and Grow Fearlessly.

The creators of one of the world's most advanced AIs just built a hacking tool so dangerous they refuse to release it, prompting fierce competitors to form an emergency alliance. Where does that leave your business? As a business leader, your primary job is to push your company forward.

If you're a defense contractor in Tucson, CMMC 2.0 can decide whether you stay in the game. Our latest article breaks do...
04/06/2026

If you're a defense contractor in Tucson, CMMC 2.0 can decide whether you stay in the game. Our latest article breaks down what small suppliers need to know and how to start preparing without getting buried in the details.

If you support work around Davis–Monthan, CMMC now decides who keeps their contracts. You built your company by solving real problems for the defense community in and around Tucson.

Not an April Fools joke: Hackers just poisoned the digital supply chain behind tools like OpenClaw.Here are the three pl...
04/01/2026

Not an April Fools joke: Hackers just poisoned the digital supply chain behind tools like OpenClaw.
Here are the three plain-English questions every CEO needs to ask their tech team today:

If someone told you that one of the most trusted building blocks of the internet, a tool downloaded 100 million times a week, suddenly started installing remote-control malware on corporate servers, you’d assume it was a terrible prank. Yesterday, it became a harsh reality.

Address

6500 Emerald Pkwy, STE 100
Dublin, OH
43016

Opening Hours

Monday 8am - 5pm
Tuesday 8am - 5pm
Wednesday 8am - 5pm
Thursday 8am - 5pm
Friday 8am - 5pm

Telephone

+16143792250

Alerts

Be the first to know and let us send you an email when Fortress MSP posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Share