Skip to main content

An Insurance Group Runs Hospital SFTP Intake on Files.com Through Its Azure Migration

A child site, SFTP, and an outbound-only Agent gave 15 hospital partners one fixed endpoint, with every file’s history recorded from arrival while the processing environment behind it moved to Azure.

A specialty insurance group is organized around deliberately decentralized operating companies, each a specialist in its market with decision-making placed close to the customer and the risk. A shared-services organization inside the group provides IT and corporate services to those operating companies.

The group launched a new underwriting subsidiary focused on employer stop-loss coverage that protects self-funded employers against catastrophic or higher-than-expected medical claims. That business runs on healthcare data. Hospital partners send the subsidiary the files its underwriting and claims work depends on, and those files carry PHI regulated under HIPAA. For this subsidiary, taking in regulated files from outside partners was never a side channel. It was the front door of the business. The shared-services team would use Files.com as a fixed, governed SFTP perimeter for hospital PHI while the processing environment behind it moved from on-prem to Azure.

A Front Door for Hospital Files

The intake path the subsidiary started with was a manual relay: hospital partners delivered files to a drop point, and staff moved each one by hand onto the on-prem drive where the actual processing happened.

The shared-services team wanted one governed path for that intake. It wanted custody of every file recorded from the moment it arrives, the record tied to the file wherever it goes next, and no person as the mechanism moving files between the drop point and the processing environment. For a division whose entire intake is regulated hospital data, the intake path is the business, and the team wanted it governed from the first file.

A New IT Department and an Estate Already in Motion

The obvious fix, modernizing the infrastructure that received the files, was already underway and could not be rushed. The shared-services organization had stood up its own independent IT department in mid-2024, and the estate it inherited was entirely on-prem and co-located, in the middle of a migration to Azure. Waiting for that migration to finish meant leaving the manual relay in place in the meantime. Building an interim path on the on-prem estate meant asking 15 hospital partners to adopt something that would be torn out again before the migration was done.

What the fix had to do was clear. It had to give hospitals a governed place to send regulated files right away: covered by a HIPAA business associate agreement, reachable over SFTP so partners could use the transfer clients they already run, recording custody of every file from the moment of arrival, and able to deliver files onward to the on-prem systems doing the work today without tying the design to that infrastructure. The team selected Files.com to be that governed intake layer.

A Fixed Intake Point in Front of a Moving Estate

Files.com became the perimeter for the subsidiary's regulated files: the fixed point hospitals connect to, independent of the storage behind it.

The team stood up a dedicated Files.com child site for the subsidiary, giving the division an appropriately bounded environment with administrative credentials that extended no further than necessary.

Hospitals connect over SFTP, the protocol their systems already speak. The team piloted the intake with a single hospital partner, then widened it to all 15. On the delivery side, the team used the Files.com Agent inside its own environment to move inbound files onward to the on-prem systems over an outbound-only connection, with no inbound firewall changes required. And because hospitals connect to Files.com rather than to the storage behind it, the intake endpoint holds still while the infrastructure behind it moves to Azure.

Every file that arrives carries its history with it. Files.com records each upload, move, and delivery in an audit trail tied to the file, under a HIPAA BAA, from the moment a hospital's transfer lands.

Custody of Every File

With the Files.com intake in production, the subsidiary replaced a manual relay with a governed SFTP path that holds custody of every file from arrival.

  • Regulated files have a complete custody and audit history. Who owns a file, where it sits, and who has touched it is a lookup in the log.
  • The manual relay is gone. No one at the subsidiary carries files between a drop point and the processing drive; files arrive over SFTP and are delivered onward automatically.
  • All 15 hospital partners send through the same governed path, moving hundreds of gigabytes a month and growing.
  • Adding the next hospital partner is a credential and a folder on the same site, not a new workflow.

The Perimeter Went In First

When an intake sits in front of infrastructure that is already moving, the instinct is to finish the infrastructure first and the intake second. The insurance group did it in the other order. Files.com went in as the governed perimeter while the on-prem-to-Azure migration continued behind it, and the hospitals never had to care which side of that migration their files landed on. Today, an analyst at the subsidiary starts work on a hospital file that arrived with its custody history already attached, and when anyone asks where a regulated file went, the answer comes out of the Files.com log. The backend did not have to finish moving before the regulated intake could go in. The perimeter went first, and the estate keeps moving behind it.

Get The File Orchestration Platform Today

4,000+ organizations trust Files.com for mission-critical file operations. Start your free trial now and build your first flow in 60 seconds.

No credit card required • 7-day free trial • Live in minutes