Skip to main content

Connexure Replaced Secure-Email PHI Intake With Expiring Client Logins on Files.com

A branded, client-isolated Files.com portal gave account managers a defensible way to open access for an engagement without leaving standing credentials behind.
Connexure (formerly Young Consulting)Files.com

Connexure builds the software the medical stop-loss market runs on. Founded in 1995 as Young Consulting, the Atlanta-based company serves carriers, MGUs, brokers, and third-party administrators across the United States, and its core underwriting platform is the dominant system among direct writers and MGUs in employer stop-loss. Its client base of roughly 120 organizations includes some of the largest national health insurers in the country.

That business model has a consequence built into it. Onboarding a client means taking in that client's data: database backups, onboarding materials, and files dense with protected health information. And the clients sending that data are healthcare payers who audit their vendors, arriving with security and risk questionnaires that ask exactly how a file gets from their systems into Connexure's. Connexure's business guaranteed that regulated data would flow inbound, and guaranteed that its clients would demand proof the path was secure.

Secure Email That Broke Its Own Rules

There was no such path. Clients who wanted to send files had nowhere safe to put them. The careful clients reached for secure-email links, and that mechanism defeated itself: to open the link, Connexure's customer solutions team had to receive a password shared through some other channel.

They will send it via a secure email, but in order to view the information, we have to share a password.
Cate Hearn, Manager, Customer Solutions, Connexure

The diagnosis was that the intake path undermined the security it existed to provide. A credential traveled out of band with no control over how it got there, and there was no audit log of what had been uploaded or downloaded. For a company whose clients send security questionnaires for a living, that was an intake process it could not defend to the people it most needed to defend it to.

Access for the Engagement, Not for Good

The obvious fix, a standing file account for every client, was the wrong one. Connexure did not want clients holding open-ended access to its environment. A client needed a way in while an engagement was live, and no way in afterward. But issuing and revoking credentials by hand does not scale across roughly 120 client organizations, and revocation by hand is exactly the step that gets forgotten.

So the requirements were specific before any product entered the picture. The intake point had to carry Connexure's own name, because a payer sending a database backup is judging the vendor by what it sees. Every client had to be walled off from every other client, with no shared space to wander into. Logins had to expire on their own, on a window an account manager could set without opening a ticket. Large database backups needed a protocol path, not a browser upload. And every upload and download had to land in an audit trail, on a platform that could sign a HIPAA business associate agreement and show SOC 2. Connexure selected Files.com to be that client intake layer.

A Branded Portal Where Logins Expire on Their Own

Connexure stood up a client portal on its own secure subdomain, pointed at Files.com through a DNS CNAME and carrying Connexure's logo and colors. A client uploading a backup sees Connexure, not a third-party tool.

Behind the domain, Connexure prepared a folder for each organization across its client base, with Files.com folder permissions blocking any cross-visibility. A client's login reaches that client's folder and nothing else. The exchange runs in both directions: the customer success team collects database backups, documents, and onboarding materials from new clients, and sensitive deliverables for statement-of-work engagements go back out through the same per-client folders. The largest transfers, client database backups during new-client setup, run over SFTP.

The mechanism that changed the model is the access expiration date Files.com puts on a user account. An account manager enables a client's login for the window an engagement is live, down to a matter of hours. Kevin Blount, VP of Cloud Engineering & Cybersecurity, described the working pattern as handing the customer success team a payer's login that is good for the next four hours. When the window closes, the platform closes the access; nobody has to remember to. Accounts carry two-factor authentication, and every upload and download is written to the Files.com audit log.

What Changed for Client Intake

With the portal in production, Connexure replaced an intake process built on secure-email links and out-of-band passwords with a governed exchange it can put its own name on.

  • Password-sharing is gone from client PHI intake. Clients upload to their own folder on Connexure's branded portal; there is no credential to smuggle across a second channel.
  • Client access is time-boxed by the platform. A login exists for the hours an engagement runs and expires on its own, so there is no standing account waiting for someone to disable it.
  • Enabling a client is an account manager's action, not an IT project. The person who owns the engagement grants the access, scoped to that client's folder and window.
  • Every upload and download is on the record. When a payer's security questionnaire asks how files move and who touched them, the answer is a log, not a reconstruction.

The compounding result sits underneath those. Bringing the next client onto the portal is a folder and a credential with an expiration date, so the intake model holds at 120 clients the same way it holds at one.

Credentials as Engagement Artifacts

The deeper change is in what a client credential is. Connexure stopped treating client access as a standing account someone has to remember to shut off and started treating it as an engagement artifact: issued for the hours the work is live, expired by Files.com, and defensible to clients who audit vendors for a living.