Frequently Asked Questions

Use Cases & Customer Success

How did Franciscan Health achieve visibility across 96,000+ medical devices and IoT endpoints?

Franciscan Health used Ordr's automated device discovery and classification technology to identify and catalog over 96,000 medical devices and IoT endpoints across 14 hospitals and 350+ facilities. This approach eliminated manual inventory processes and closed visibility gaps common in multi-hospital health systems. Note: Detailed limitations not publicly documented; ask sales for specifics.

What are the risks of not having complete visibility into medical device inventories in healthcare?

Incomplete device visibility creates attack surface gaps where unmanaged endpoints can become entry points for cyber threats. Without comprehensive visibility, healthcare organizations may overlook shadow IT devices, legacy equipment, and IoT endpoints that pose security risks. Ordr helps identify these assets and enables appropriate monitoring controls. Note: Ordr's effectiveness depends on integration with existing infrastructure; limitations may exist in highly customized environments.

How does Ordr enable continuous security monitoring for medical devices at enterprise scale?

Ordr enables continuous monitoring protocols that track the security posture of IoT and medical endpoints across large, distributed environments. This automated approach allows health systems to move beyond one-time audits to ongoing device behavior analysis and risk assessment, reducing the burden on IT teams. Note: For highly dynamic or non-standard device environments, additional configuration may be required.

What operational strategies did Franciscan Health use to reduce attack surface risk?

Franciscan Health implemented automated device discovery, eliminated visibility gaps, and established ongoing monitoring using Ordr. These strategies enabled the health system to identify unmanaged devices and reduce the risk of cyber threats across 14 hospitals and 350+ facilities. Note: The success of these strategies depends on the accuracy of device classification and integration with existing security tools.

Features & Capabilities

What features does Ordr offer for healthcare and large enterprises?

Ordr provides comprehensive asset discovery, AI-driven device classification, risk-based vulnerability management, automated policy enforcement, real-time threat detection and containment, and continuous compliance monitoring. The platform integrates with over 130 security, networking, and IT tools, including firewalls, NAC, SIEM, and ITSM platforms. Note: Some advanced features may require integration with specific third-party systems; check compatibility before deployment.

Does Ordr support integration with existing security and IT infrastructure?

Yes, Ordr supports over 130 out-of-the-box integrations, including firewalls (Cisco, Palo Alto Networks, Fortinet, Check Point), NAC (Cisco ISE, Aruba ClearPass, Forescout), SIEM/SOAR (Splunk, IBM QRadar, Microsoft Sentinel), ITSM (ServiceNow, BMC Remedy), clinical systems (Epic, Cerner), and vulnerability scanners (Tenable, Qualys, Rapid7). For a full list, visit Ordr's integrations page. Note: Integration depth may vary by vendor; verify specific requirements for your environment.

How quickly can Ordr be deployed and provide value?

Ordr is designed for rapid deployment. Initial device discovery and visibility can be achieved within 24–48 hours of deployment. Enforcement policies can be deployed in just a few days, compared to industry norms of 12–24 months. Note: Actual timelines may vary based on network complexity and integration needs.

Does Ordr provide an API and technical documentation?

Yes, Ordr provides a comprehensive API and technical documentation for all products. These resources are available through the Ordr support portal to help customers integrate and manage the platform effectively. Access requires a support portal login: Ordr support portal. Note: API access may require appropriate licensing or permissions.

Security & Compliance

What security and compliance certifications does Ordr have?

Ordr is SOC 2 Type II certified, demonstrating independently audited controls for Security, Availability, and Confidentiality over a 12-month period. Ordr is also compliant with GDPR and CCPA, and is evaluating ISO 27001 certification as part of its compliance roadmap. For more details, visit Ordr's Trust Center. Note: ISO 27001 certification is not yet complete as of June 2024.

Business Impact & Outcomes

What measurable business impact can organizations expect from Ordr?

Organizations using Ordr have reported improved security posture, up to 90 person-hours saved weekly through workflow automation, reduced threat dwell time from 270 days to as little as 48 hours, and up to 25% reduction in device count by eliminating duplicates. Ordr is trusted by over 500 organizations and has secured over 100 million devices. Note: Results may vary depending on deployment scope and organizational readiness.

Pricing & Plans

How is Ordr priced?

Ordr's pricing is tailored to each organization's specific needs and environment. For detailed pricing information, contact the Ordr team directly or request a quote via the demo request page. Note: Exact pricing details are not published publicly and may vary based on deployment size and feature requirements.

Support & Implementation

What support and training resources are available for Ordr customers?

Ordr offers 24/7 customer support, onboarding assistance, technical guidance, and access to Ordr University for training modules. Customers can also access product documentation, knowledge base articles, and case management tools via the support portal. Note: Some resources may require a support login or active subscription.

Competition & Comparison

How does Ordr compare to visibility-only platforms?

Visibility-only platforms typically offer basic asset discovery limited to IT devices and use static policy templates. Ordr provides real-time, automated asset discovery across IT, IoT, OT, and medical devices, with AI-driven behavioral fingerprinting for deeper insights and dynamic, AI-generated policies that adapt to changing environments. Note: Ordr may require more initial configuration than basic visibility tools; best fit for organizations needing advanced automation and enforcement.

How does Ordr differ from traditional vulnerability management tools?

Traditional vulnerability management tools often rely on static assessments and manual risk prioritization. Ordr automates risk prioritization based on operational impact, uses AI-driven continuous learning for proactive mitigation, and integrates with vulnerability scanners like Tenable, Qualys, and Rapid7. Note: Organizations seeking only vulnerability scanning without automated enforcement may prefer traditional tools.

How does Ordr compare to compliance-only solutions?

Compliance-only solutions focus on manual evidence collection and are often limited to specific frameworks. Ordr provides continuous compliance monitoring and audit-ready reporting for multiple frameworks (HIPAA, PCI DSS, FERPA), with automated workflows that reduce audit preparation time. Note: Organizations with highly specialized compliance needs may require additional customization.

Customer Proof & Testimonials

What feedback have customers given about Ordr's ease of use?

Customers such as University Hospital Southampton and Richmond upon Thames College have highlighted Ordr's intuitive design, quick deployment, and immediate delivery of actionable insights. For example, University Hospital Southampton reported, "It's very intuitive and quick to install (even on a network of this size) and it instantly started cataloging and risk profiling every single device on our network." Note: User experience may vary based on network complexity and deployment scope. See more customer stories.

Which industries and organizations have successfully used Ordr?

Ordr is used by over 500 organizations across healthcare (Cleveland Clinic, CHRISTUS Health, Beebe Healthcare, University Hospital Southampton), higher education (Richmond upon Thames College), and financial services (Veritex Community Bank). These organizations have achieved outcomes such as real-time inventory, accelerated segmentation, and improved compliance. Note: Success stories are based on published case studies; results may vary. See detailed case studies.

Resource Library
Case StudiesVisibilityRiskFebruary 15, 2024

Franciscan Health Case Study

CASE STUDY

Franciscan Health Utilizes Fortinet Security Fabric Solutions to Immunize IoT Medical Devices Against Attack

Following the Roman Catholic tradition of caring for those in need, Franciscan Health is committed to providing high-quality and compassionate healthcare. The company runs 14 hospitals and more than 350 satellite locations, including physician practices, imaging centers, urgent care centers, and other facilities across Indiana and Illinois.

In monitoring patient health and providing appropriate medical services, Franciscan Health’s 29,000 employees rely on a wide array of medical equipment. However, these machines increase the corporate network’s vulnerability to cyberattack.

“We have a significant attack surface, as all healthcare companies do,” explains Chuck Christian, Vice President of Technology and CTO. “We have about 96,000 endpoints connected to our corporate network, including clinical engineering systems, IoT [Internet-of-Things] gear, and medical equipment. That does not include the separate guest network that we maintain for patients and visitors. It is crucial for my team to block unauthorized access to the corporate network—and to know immediately if someone gets past our edge security.”

“The bad actors keep getting smarter, and we need to be as smart as they are. We need to make sure the business partners we have chosen will work with us to support our security goals. We get that with Fortinet and ORDR.”

— Chuck Christian, Vice President of Technology and CTO, Franciscan Health

Details

Customer: Franciscan Health

Fortinet Fabric Ready Partner: ORDR

Industry: Healthcare

Headquarters: Mishawaka, IN

Business Impact

• Near-real-time visibility into emerging threats and attacks improves efficacy of security environment

• Time savings for IT staff

Products and Solutions

• FortiGate Next-Generation Firewall

• FortiManager

• FortiNAC

An Eye on IoT

Three years ago, Franciscan Health deployed the ORDR connected device security solution for asset inventory and to better track its disparate devices. ORDR is a Fortinet Fabric-Ready Partner whose ORDR Systems Control Engine (SCE) solution discovers and classifies every connected device, including IoT and other unmanaged devices throughout a network, then profiles each device’s behavior and risks. Through the Fabric-Ready Partnership, ORDR and Fortinet collaborate to develop validated, end-to-end security solutions.

When Franciscan Health first deployed ORDR SCE, “it was eye-opening to see how many devices connect to our network,” Christian says. “The data visualization in ORDR gives us a huge amount of information. We have visibility into the risk profile of every piece of equipment.” This is important, he adds, because some devices could be leveraged as an attack vector into the corporate network: “The healthcare industry is very good about squeezing the last bit of juice out of any equipment. We have systems that are 15 years old, whose embedded operating systems have not been upgraded in that time, due to manufacturer requirements.”

This new visibility into risk led Franciscan Health to begin deploying FortiGate Next-Generation Firewalls (NGFWs). The close engineering relationship between Fortinet and ORDR means that the FortiGate NGFWs integrate tightly with ORDR’s asset management solution via open application programming interfaces (APIs). Christian’s team has configured the solutions so that ORDR notifies the firewalls if it notices a specific situation or event.

“When we put in medical equipment, especially devices that we cannot manage or patch, they go behind the FortiGate firewalls,” Christian says. “We are still in conversation about how the firewalls should act on those notifications—whether they should cut off a device’s access to the network or alert a human who can determine whether it is a true threat or a false positive.”

Wrapping the Network in the Fortinet Security Fabric

Since first starting to deploy FortiGate NGFWs, Franciscan Health has expanded its investments in solutions that integrate into the Fortinet Security Fabric. Christian’s team implemented FortiManager to streamline deployment of new firewalls and leveraged threat intelligence from FortiGuard Labs.

“The ability to centrally manage our security environment through the FortiManager system is really helpful,” Christian says. “When the Log4j vulnerability came to light, FortiGuard Labs provided us with information about the threat signatures. We put that information into the FortiManager solution, which sent it out to the NGFWs; they were then able to watch for the threat. We were prepared in case a Log4j attack got into the building.

“Fortinet enabled us to be proactive rather than reactive,” he says. “I prefer to avoid spilling the glass of milk, instead of having to clean it up after the fact.”

Next, the team started segmenting their internal network, building dynamic rules within the FortiGate NGFWs to protect specific healthcare devices. “Our goal is to use east, west, north, and south segmentation,” Christian says. “The Fortinet solutions use the information from ORDR to understand what behaviors are normal, and they alert us when a device behaves abnormally. For example, if we have a CT scanner that usually talks only to the EMR [electronic medical record] system, and all of a sudden it starts trying to connect to a foreign IP address that we have geoblocked, then the FortiGate firewalls tell us that something has gone wrong.”

The microsegmentation reflects an organizational emphasis on leveraging the benefits of technology integrations. “We have a new strategy that revolves around the Fortinet Security Fabric,” Christian says. “Rather than just connecting everything and running traffic, our networking strategy involves leveraging the hardware to turn the network into more of a security tool.”

To that end, Christian’s team recently launched a network access control (NAC) initiative. “The combination of microsegmentation and NAC policies means no equipment will be able to access anything of value to the organization unless it is supposed to,” he says.

Dynamic, Integrated, and Secure NAC

The need for a NAC was clear, and the FortiNAC solution was the obvious choice. “As we begin to move toward zero-trust networking, we need to prevent devices from connecting to our network if we do not explicitly want to allow them,” Christian explains. “I tasked my team with finding the best NAC. We talked to Gartner analysts, then did a deep dive into the FortiNAC solution. We found that it played well with the equipment we already had in place, so it made sense.” His team is currently rolling out the FortiNAC product throughout the Franciscan Health organization.

“There are a lot of different choices we can make in terms of response in case an unknown device tries to plug into the Franciscan Health network,” Christian says. “If we are completely unaware of the equipment, we can just deny it access. Or we can shunt it off to another network that has access only to the internet, or we can display a splash screen.”

“Integration between FortiNAC and FortiManager enables us to ensure that configurations follow individual devices throughout our network, rather than staying fixed to a specific port.”

— Chuck Christian, Vice President of Technology and CTO, Franciscan Health

ORDR is already passing data on to the FortiNAC system via API for device visibility. Eventually, ORDR will also feed the FortiGate firewalls “proofed” rule suggestions. This intelligence sharing throughout the Fortinet Security Fabric will support microsegmentation at Franciscan Health by enabling network access policies to be applied at a more granular level. Anytime a new device connects to the network—whether it is an MRI machine, a video surveillance camera, or any of the hundreds of other devices that might connect—it will receive a network profile. Then, every access-policy change that affects the subset of devices defined by that profile will be pushed out to the new device as well.

At the same time, the FortiNAC-FortiManager combination substantially improves the efficiency of network security. “In our legacy environment, if something happens—say, a port goes bad—and we need to move a device to another port, then one of the network engineers has to go into the configuration of the switch and move those configurations to a new port. Integration between FortiNAC and FortiManager will enable us to ensure that configurations follow individual devices throughout our network, rather than staying fixed to a specific port.”

Playing Chicken with Prospective Attackers

Having Fortinet solutions that are receiving information from a data source as strong as ORDR enables Christian “to future-proof our network security,” he says. “I am very impressed with some of the forward-thinking actions Fortinet is taking to improve intelligence around threat management.

“Our goal is to make our network impenetrable,” he continues. “The bad actors keep getting smarter, and we need to be as smart as they are. We need to continue to learn, and we need to make sure the business partners we have chosen will work with us to support our security goals. We get that with ORDR and Fortinet. Together, these solution providers help us to potentially stay ahead of bad actors, which will be very important into the future, because I am greatly concerned that the next generation of shape-shifting threats will be able to evade a lot of security systems.”

Christian concludes with an analogy: “My father always told me, ‘You are going to have 12 problems racing down the road at you. Most of them will veer off into the ditch. Your job is to figure out which one or two will actually run you over if you do not react to them.’ The Fortinet Security Fabric solutions and ORDR help us discern and understand which types of threats we need to address.”

—————

www.fortinet.com

Copyright © 2025 Fortinet, Inc. All rights reserved. Fortinet®, FortiGate®, FortiCare® and FortiGuard®, and certain other marks are registered trademarks of Fortinet, Inc., and other Fortinet names herein may also be registered and/or common law trademarks of Fortinet. All other product or company names may be trademarks of their respective owners. Performance and other metrics contained herein were attained in internal lab tests under ideal conditions, and actual performance and other results may vary. Network variables, different network environments and other conditions may affect performance results. Nothing herein represents any binding commitment by Fortinet, and Fortinet disclaims all warranties, whether express or implied, except to the extent Fortinet enters a binding written contract, signed by Fortinet’s SVP Legal and above, with a purchaser that expressly warrants that the identified product will perform according to certain expressly-identified performance metrics and, in such event, only the specific performance metrics expressly identified in such binding written contract shall be binding on Fortinet. For absolute clarity, any such warranty will be limited to performance in the same ideal conditions as in Fortinet’s internal lab tests. Fortinet disclaims in full any covenants, representations, and guarantees pursuant hereto, whether express or implied. Fortinet reserves the right to change, modify, transfer, or otherwise revise this publication without notice, and the most current version of the publication shall be applicable.


Frequently asked questions
How can healthcare systems discover and classify medical devices across multiple hospital locations?
ORDR uses automated device discovery and classification technology that works across distributed healthcare facilities without requiring manual inventory processes. Franciscan Health successfully identified and cataloged 96,000+ medical devices spanning 14 hospitals and 350+ facilities, eliminating visibility gaps that typically exist in multi-hospital health systems.
What are the key risks of not having complete visibility into medical device inventories?
Incomplete device visibility creates critical attack surface gaps where unmanaged endpoints can become entry points for cyber threats. By establishing comprehensive visibility, healthcare organizations can identify shadow IT devices, legacy equipment, and IoT endpoints that pose security risks and implement appropriate monitoring controls.
How do you maintain continuous security monitoring for medical devices at enterprise scale?
ORDR enables continuous monitoring protocols that track the security posture of IoT and medical endpoints across large distributed environments. This automated approach allows health systems to move beyond one-time audits to ongoing device behavior analysis and risk assessment without overwhelming IT teams.

This resource is published by ORDR, the connected asset security company. ORDR delivers AI-powered visibility, risk assessment, and automated protection for IoT, OT, and IoMT devices across healthcare, manufacturing, government, and financial environments. Browse all resources →