Skip to main content

CAN Community Health Replaces WinSCP and Batch Scripts With a HIPAA Exchange on Files.com

An outbound-only architecture turned bespoke partner builds into repeatable configuration—including several new partner servers in a single day.
CAN Community HealthFiles.com

CAN Community Health is a nonprofit provider of HIV, hepatitis C, and STI care, operating clinics across multiple US locations alongside a federal 340B pharmacy program.

Very little of that care runs inside a single system. Prescriptions flow through partner pharmacies, claims through a clearinghouse to payers, clinical reports out of hosted EMRs, reconciliation files back from a claims processor. Every one of those flows is HIPAA-protected patient data moving between CAN and an outside company, and the moving itself was the problem.

Every Partner Connection Was Built and Run by Hand

Until 2023, CAN had no hosted SFTP capability of its own. Files sat in folders on on-premises servers, and getting them to a partner meant a separate hand-built process for each connection, every one maintained by hand. Every new partner was a small engineering project, and every running connection was one more script to check and keep alive.

Two constraints kept the obvious fixes off the table. CAN's team would not open inbound firewall ports to let outside systems reach its on-prem servers, so no partner could ever simply connect in. And because every file in scope carries protected health information, anything CAN adopted had to operate under a HIPAA Business Associate Agreement, with data held in the United States. That disqualified consumer sync tools before the conversation started.

Meanwhile, CAN already knew more partners were coming, and each new endpoint would bring its own protocols, naming conventions, and encryption requirements. One national pharmacy chain alone would eventually need a long list of distinct CSV file patterns, each encrypted before transmission. A process built one batch script at a time was not going to carry that.

What CAN needed was a hosted SFTP platform that could pick files up from on-prem folders without an inbound firewall port, deliver them to each partner's endpoint in the format and encryption that partner required, repeat that pattern for every partner after, and do all of it under a BAA with data held in the US. CAN selected Files.com to provide that exchange layer.

An Exchange Hub That Reaches On-Prem Without Opening a Port

Files.com sits between CAN's on-prem servers and every partner endpoint, so neither side had to change how it works.

On the inside, Files.com Agents run within CAN's network, including one on a headless server. Each Agent makes only an outbound, encrypted connection to the platform, so nothing on the internet ever reaches into CAN's environment. The firewall work for the entire exchange came down to dedicated IP addresses on CAN's own domain.

On the outside, remote server integrations deliver files to each partner's endpoint over the protocol that partner requires, encrypted with PGP before transmission. Partners connect to an SFTP address on CAN's own domain, backed by dedicated IPs each partner can whitelist, so what a pharmacy chain sees is CAN, not a third-party tool.

Between the two, Files.com Syncs pull files from on-prem folders into the platform and push them out to each partner. Files.com Automations handle each partner's requirements, including the pharmacy chain's many CSV patterns, PGP encryption and automatic retries when a remote system fails to answer. Files.com retains each file on the audit record so CAN can resend any transfer.

The exchange runs inbound as well. Report outputs from CAN's eCW and CureMD EMRs arrive over SFTP into a folder whose credentials can deposit files but not read them back, and an automation moves each arrival straight to a secured location and routes selected outputs onward. EDI claims files for a new clearinghouse, covering claims submissions, payments, and adjustments, move automatically and land on-prem for processing and reporting.

The whole site runs with HIPAA enabled under a Business Associate Agreement, with data pinned to US storage regions and logins restricted to US addresses. CAN's IT infrastructure and security manager configured all of it himself, moving the estate over workload by workload through 2023 and 2024 and keeping each legacy script running beside its replacement until the new sync proved out.

Every Partner Connection, Run From One Platform

  • The entire partner exchange runs from one platform, with no batch scripts to maintain and no manual transfer sessions to run.
  • Partner connections have been in continuous operation since 2023, spanning national pharmacy chains, pharmacy program vendors, both EMRs, a patient-survey platform, and the claims clearinghouse.
  • Treasury claims files are pulled from the claims processor's SFTP on a schedule and synced down to an on-prem folder, so the accounting team gets its files without ever logging into the platform.
  • Adding a partner became configuration rather than a project. In one build-out, several new partner servers were configured in a single day.

The Next Partner Is a Remote Server, Not a Script

What changed at CAN is not any one transfer. It is how the organization takes on a data partner at all. A new pharmacy program, clearinghouse, or EMR used to mean someone writing a script against an unfamiliar endpoint and then keeping it alive indefinitely. Today it means adding a remote server and a sync inside a Files.com site that is already under the BAA, already pinned to US storage, and already logging every transfer. The infrastructure manager who once ran every connection by hand now configures them instead, and the files move whether or not he is watching.

Get The File Orchestration Platform Today

4,000+ organizations trust Files.com for mission-critical file operations. Start your free trial now and build your first flow in 60 seconds.

No credit card required • 7-day free trial • Live in minutes