Skip to main content

CCMR3 Took SFTP Administration In-House With Files.com—Without Taking On the Server

A managed SFTP endpoint let one operations analyst provision regulated client and law-firm portfolios when requests arrived, with a HIPAA BAA in place from day one.
BHG Financial / CCMR3Files.com

CCMR3 is an accounts-receivable management firm handling third-party debt collection and collections litigation support. A subsidiary of BHG Financial, it works with clients and outside law firms on portfolios across the United States. Some of its work involves healthcare receivables, which means medical accounts and protected health information.

That work runs portfolio by portfolio. A client places a portfolio of accounts, and CCMR3 exchanges batch files with that client, and with the outside law firms litigating those accounts, for as long as the engagement runs. Those files can carry consumer PII and, on medical accounts, PHI. File exchange sits at the front of CCMR3’s client relationships.

Adding a User Meant Filing a Work Order With Another Company

For years, that exchange ran on an on-prem SFTP server that CCMR3 neither hosted nor administered. The server belonged to a broader infrastructure stack operated by an outside managed-service provider, and every basic administrative task went through that vendor. Adding a user meant filing a work order and waiting.

The cost landed at the start of every engagement. Onboarding a new client portfolio, or giving a partner law firm a login, was the first thing a new relationship asked for, and it sat in another company’s ticket queue. CCMR3’s team had no way to create users or share logins on its own timeline. Meanwhile, files carrying PII and PHI moved through infrastructure the firm did not operate, under a compliance posture it did not directly control.

The problem persisted because the SFTP server was not a standalone system anyone could swap out. It was embedded in the vendor-supported stack, so fixing file transfer meant pulling the workload out of the MSP relationship entirely. And any replacement had a hard floor: it had to carry regulated data, including PHI under a HIPAA business associate agreement, from its first day in production.

What the fix had to do was specific. An SFTP endpoint CCMR3 could administer itself: users created, logins shared, and per-portfolio folder structures stood up the moment a request arrived. Separation between clients and law firms, portfolio by portfolio. A HIPAA BAA covering the medical accounts. And none of it could mean CCMR3 taking on the hosting and operating of a file transfer server. The firm wanted to own the administration, not the machine.

CCMR3 selected Files.com as that endpoint.

An SFTP Site CCMR3 Administers Itself

Files.com gave CCMR3 a managed SFTP platform where the administration belongs to the customer and the infrastructure belongs to Files.com. The BAA was in place from the outset, covering PHI on the medical accounts.

The structure mirrors how the business works. Each external party, whether a client or a partner law firm, has a portfolio-scoped folder structure, with users permissioned only to their own portfolios. Files move in both directions over SFTP, so counterparties connect with whatever standard client they already use, and CCMR3’s own staff work through the Files.com web client alongside their desktop SFTP tools.

Provisioning is the part that changed hands. CCMR3’s team creates users, sets up directories, and manages permissions directly in the Files.com web client. The whole configuration was built and is maintained in-house by a single operations analyst. Internal staff sign in through Microsoft Entra ID SSO, so identity for CCMR3’s own users comes from the directory the firm already manages.

In 2024, the Rest of the SFTP Workload Followed

The first wave replaced the MSP-hosted server. The second came in 2024, when CCMR3 migrated off its hosted infrastructure vendor and rebuilt its infrastructure in-house. It did not stand up its own SFTP server as part of that build. It cut the vendor’s remaining SFTP workload over to Files.com wholesale, and the change was immediately visible on the account: a step change in users, directories, and files moved.

From Ticket-and-Wait to Handling Requests In-House

With the Files.com endpoint in production, CCMR3 replaced an administration cycle routed through an outside vendor’s ticket queue with access handled by its own team when the request arrives.

  • Onboarding a new client portfolio or a law-firm login is handled by CCMR3’s own staff when the request arrives. No work order leaves the building.
  • PHI on medical accounts moves under a HIPAA BAA that has been in place from the start and held continuously through the BHG Financial acquisition.
  • The roster of client, law-firm, and internal logins has nearly doubled since provisioning came in-house, absorbed by the same team, with the configuration still maintained by one operations analyst.
  • File transfer is no longer tied to any vendor’s infrastructure. When CCMR3 rebuilt its stack in-house, the transfer layer consolidated onto Files.com instead of becoming one more system to host.
Now we have the ability to go into Files.com and do whatever we want.
Colton Sergeant, Director of IT / Operations and Project Management, CCMR3

Owning the Administration, Not the Server

CCMR3 never needed to run an SFTP server. It needed to control who could reach one: which clients, which law firms, which portfolios, under what compliance posture. Files.com separated those two things. The administration came in-house, down to a single analyst maintaining the entire configuration, while the server stayed somebody else’s job. When the firm later brought the rest of its infrastructure in-house, file transfer was the one workload it chose not to take back, because the part worth owning, it already owned.