A Dental and Vision Insurer Holds Its 834 Enrollment SFTP Endpoint in Its Own Name on Files.com
A US dental and vision benefits insurer operates as one unit of a larger parent organization.
Coverage starts with enrollment, and enrollment arrives as data. Agents, producers, and EDI vendor groups send ANSI X12 834 enrollment files, the standard EDI format for membership enrollment, into the insurer, where a dedicated team receives, validates, and processes them. Each sender runs its own automation against the insurer's intake point, on its own schedule, under its own security policy.
For a company whose partners connect to it by machine, every day, the question of who holds that connection point is not abstract. The insurer wanted its exchange point held under its own agreement, in its own name, on infrastructure no other part of the company runs.
Every Partner Automates Against One Address
For years, the exchange point for all of that partner traffic was an internal file server running PGP encryption, operated on infrastructure elsewhere in the company. Moving off it meant moving every connection: partner accounts, encryption keys, IP restrictions, and, on the far side, the automation each agent and vendor group runs against the insurer's endpoint. None of that automation belonged to the insurer, so each partner had to be moved individually.
What the insurer needed was an exchange point it holds in its own name, so the address partners automate against never has to move again. It had to sit under its own agreement rather than inside any other unit's infrastructure, speak the SFTP its partners already automate against, carry the insurer's own brand, satisfy each vendor's security mandate, and be covered by a HIPAA business associate agreement. The insurer selected Files.com to be that platform.
An SFTP Endpoint Held in the Insurer's Own Name
The insurer's own EDI specialist ran the cutover onto Files.com-hosted SFTP, at an address carrying the insurer's own brand, so partners connect to the insurer rather than to a third-party tool. The agreement sits with the insurer itself, with a HIPAA business associate agreement and encryption processes in place from the start in 2016.
Partner connections were rebuilt incrementally, and the insurer runs the onboarding itself. The insurer scripted the account side against the Files.com REST API and .NET SDK years ago, so user creation and folder provisioning for each new group run as code; the insurer then applies whatever notifications, keys, or IP restrictions that partner requires.
One Endpoint, a Different Security Posture for Every Partner
On the old server, PGP was the server's feature. On Files.com, it became one option among several, applied partner by partner as each vendor's policy demands.
When one EDI vendor mandated encrypted exchange, the insurer turned it on through Files.com's GPG support, and files that vendor encrypts are decrypted inside the Files.com folder they land in, ready for processing. When another vendor's policy ruled out password access, the insurer switched that connection to SSH key authentication. IP whitelists restrict each account to the addresses a partner actually sends from, and per-vendor email notifications tell the insurer's team when files arrive. Each mandate was met with configuration on a platform the insurer already ran, not with a new project.
Dozens of Groups a Day, and a Fourth-Quarter Surge
With the cutover behind it, the insurer moved from an internal server to an intake point it holds in its own name. The exchange has run in production on Files.com for years.
- Dozens of vendor groups a day deliver 834 enrollment files through the single SFTP intake, most over their own automation.
- Onboarding the next partner is configuration the insurer performs itself: an account, a folder, a key or an IP whitelist, a notification. Steady growth as more groups move to electronic transfer, and the open-enrollment surge every fourth quarter, land on the platform rather than on new infrastructure.
- A vendor's security mandate no longer starts a project, because encryption, key-based access, and IP restrictions are already on the platform waiting to be applied.
- Encrypted exchange has become part of how the insurer sells, offered as an option in new growth opportunities.
An Endpoint That Has Not Moved
The exchange point sits under the insurer's own agreement, and the endpoint its agents, producers, and vendor groups connect to has not moved.
A partner-facing endpoint is only as stable as the agreement it sits under. By putting partner exchange on Files.com in its own name, the insurer made its most partner-facing system independent of any infrastructure it does not run. Today, the address every trading partner connects to is the insurer's to keep, whatever changes around it.
Related Customer Stories
A Reverse-Logistics Provider Moved Its Partner File Exchange to Files.com Without Re-Integrating a Single Partner
Every partner account was recreated on Files.com as an encrypted FTPS account, so partners kept the clients and automations they already ran and changed only the address they pointed at.
Read The Story
An Insurance Group Runs Hospital SFTP Intake on Files.com Through Its Azure Migration
A child site, SFTP, and an outbound-only Agent gave 15 hospital partners one fixed endpoint, with every file’s history recorded from arrival while the processing environment behind it moved to Azure.
Read The Story
An Insurance Holding Company Met a File-Level Encryption Mandate on Files.com Instead of an Emergency SFTP Upgrade
An existing regulated partner hub let the insurer onboard business its on-premises environment could not support without upgrades coordinated across outside organizations.
Read The Story
Get The File Orchestration Platform Today
4,000+ organizations trust Files.com for mission-critical file operations. Start your free trial now and build your first flow in 60 seconds.
No credit card required • 7-day free trial • Live in minutes