Hospital Security Reviews Become a Document Request After ITx Companies Replaces Fortra's GoAnywhere

ITx Companies is a US healthcare revenue cycle management firm that works only with healthcare clients. Operating as an extended business office for hospital systems and physician groups, ITx takes over the patient accounts its clients hand it and manages them across the full lifecycle, from billing follow-up to delinquent balance recovery.
The company's operating model is built on letting clients watch. Hospitals get at-will access to real-time account activity, down to the conversations ITx staff are having with their patients and insurance companies. Every engagement begins with a hospital sending ITx new patient accounts, which means protected health information crossing from a covered entity to a business associate. Under HIPAA, ITx's security is part of each hospital's own security, and hospital security teams treat it exactly that way.
Hospital Clients Gate File Connections on Security Evidence
As a HIPAA business associate, ITx faced recurring vendor security due diligence from its own clients. The scrutiny concentrated on one layer: file transfer, because that was where patient data crossed the boundary between the hospital and ITx.
That layer had been Fortra's GoAnywhere, an MFT platform ITx operated itself, which meant every piece of security evidence for it was ITx's to commission and keep current. Audit reports, penetration test results, and cyber insurance evidence all went into a hospital's vendor file before data started to move.
The cost landed at the worst possible moment: onboarding. In April 2024, a hospital client preparing to connect to ITx over SFTP requested security documentation before the connection went ahead. The immediate need was a penetration test report, within a day or two, along with a SOC 2 audit report. A connection the hospital was ready to open sat on paperwork, and the client relationship waited with it.
The bar was rising from inside as well: ITx was pursuing its own SOC 2 certification, and the file transfer platform had to be accounted for in its control environment.
What ITx needed was a transfer layer that arrived already attested: independent audit and test evidence it could hand a hospital on demand, and per-client controls that would stand up to the review those documents invite. ITx selected Files.com to be that layer.
A Transfer Layer That Arrives Already Audited
Today, the daily exchange with roughly 35 hospitals and vendors runs on Files.com.
The deployment was built to be reviewed. Each hospital client works inside its own folder structure, with group-based permissions scoping what that client's users can reach and nothing more. SFTP accounts use SSH keys, while IP whitelisting restricts where each account can connect from. Between Files.com and ITx's on-premise processing system, the Files.com Agent moves files over an outbound connection from inside ITx's network.
Each hospital is isolated to its authorized files, connections are restricted, and ITx can move data without opening an inbound connection.
A Hospital SFTP Onboarding Cleared, and ITx's SOC 2 Work Moved Forward
With Files.com carrying the exchange, ITx replaced security evidence it had to produce for infrastructure it ran itself with attestations it requests from its platform.
- The hospital's SFTP onboarding went ahead: its security requirements were answered with Files.com's penetration test report and SOC 2 audit report, delivered within the hospital's timeline.
- ITx's own SOC 2 certification drew on Files.com's SOC 2 Type 2 documentation, so the layer that moves PHI entered ITx's control environment already independently audited.
- The next review has a standing answer: the same current reports cover every client connection on the platform, so a new hospital's due diligence starts a document request, not an evidence project.
The Layer Under Scrutiny Now Answers for Itself
Nothing about the scrutiny has changed. Hospitals still audit the vendors that touch their patients' data, and the file connection still draws the closest look. What changed is who produces the answer. For a business built on letting hospitals see exactly how their accounts are handled, the layer where their data crosses now comes with the same quality of proof.
Related Customer Stories
Health & Life Sciences
Nestlé Health Science Moves 10 TB of Regulated Acquisition Data in One Month with Files.com
A repeatable SFTP staging and verification workflow keeps multi-terabyte GxP data moving without waiting six months to a year for internal infrastructure.
Read story →
Health & Life Sciences
Abcam Retired Its Self-Hosted FTP Servers With Files.com at MuleSoft’s Transfer Edge
A UK-locked landing zone now handles machine traffic from FTP-only counterparties while MuleSoft continues to orchestrate the integrations behind it.
Read story →
Health & Life Sciences
Everly Health Solutions Configures 40 Health Plan SFTP Connections in Files.com, Not Custom Code
Files.com Remote Servers and automations now move regulated clinical reports from AWS to payer-owned endpoints while operations staff handle routine delivery.
Read story →