Skip to main content

CCMR3 Automated Hosted CRM Report Delivery Under a HIPAA BAA

Files.com became the governed SFTP meeting point between CCMR3’s vendor-hosted CRM and internal systems, creating a pattern the firm could reuse for Azure Virtual Desktop.
BHG Financial / CCMR3Files.com

CCMR3 is an accounts-receivable management firm licensed in all 50 states. It recovers delinquent receivables for enterprise clients and supports collections litigation alongside outside law firms. Its portfolio includes healthcare receivables, which means the files moving through the business carry protected health information alongside the personal data every collections file holds. The work is regulated at every layer: FDCPA rules on the collections side, HIPAA on the medical accounts.

The operational record of that work lived in a cloud-hosted collections CRM run by an outside vendor. Every report the platform produced sat inside a system the firm did not operate. The software and internal drives that needed that data ran on CCMR3's side of the line. Between the two, there was no path.

Report Data Stranded Inside a Vendor's Platform

Nothing about that boundary could be fixed from inside the CRM. The platform belonged to a vendor, and its behavior was the vendor's to change, not CCMR3's. The data itself ruled out casual workarounds: debt-collection and litigation files carry PII, and the medical accounts carry PHI, so any intermediary had to be a system CCMR3 could place regulated data on.

The fix had a clear specification. It had to give the hosted CRM a destination it could reach over standard SFTP, and give CCMR3's internal software a directory it could watch and collect from. It had to run unattended, on a schedule, with nobody in the loop. And it had to carry PHI under a BAA. CCMR3 selected Files.com to be that staging layer, with a HIPAA BAA in place from the outset.

An SFTP Landing Zone Between the Hosted CRM and Internal Drives

Files.com became the meeting point for two systems that could not reach each other.

CCMR3 stood up a landing directory on its Files.com site and pointed the CRM's report exports at it over SFTP, a protocol the hosted platform could already speak. On the internal side, monitoring software the firm wrote itself watches that directory. When an export lands, the software picks it up, processes the data, and loads it to internal drives. An Apache NiFi service account drives scheduled transfers into and out of the Files.com site, so the movement runs on a clock rather than on a person's memory.

The transfers run through non-interactive service accounts. When CCMR3 scoped an MFA requirement for its site administrators, it exempted the bot accounts, so security requirements for humans do not interrupt machine-run transfers.

Collections Data That Arrives With Nobody in the Loop

With the pipeline in production, CCMR3 replaced a boundary its data could not cross with a scheduled feed that crosses it unattended.

  • Report data that used to stop at the CRM's edge now lands on Files.com, gets processed, and loads to internal drives on a schedule, with nobody touching a file.
  • The exchange is part of the firm's compliance posture rather than a workaround: PII and PHI move under a BAA, through directories and accounts CCMR3 configures and maintains itself.
  • The pattern generalized. The same Files.com site now bridges CCMR3's Azure Virtual Desktop environment and local endpoints, staging data out of AVD sessions for pickup on local machines and back again. A second environment with no direct path to local machines got the same fix.

That last point is the compounding result. Once a governed intermediary exists, the next environment that cannot reach local machines does not need a new integration project. It needs a directory on the same Files.com site and a service account to move the files.

A Standing Path Out of Platforms CCMR3 Does Not Control

Before Files.com, there was no version of this feed. The firm's operational record was produced inside a vendor's platform, and the internal systems built to work on that record could not receive it. Today the boundary is routine: the hosted environment pushes to Files.com, CCMR3's own software collects from it, and the schedule does the rest.

CCMR3 never needed to control the CRM to integrate with it. It needed a governed place both sides could reach, and Files.com is that place.