Skip to main content

Hospital Security Reviews Become a Document Request After ITx Companies Replaces Fortra's GoAnywhere

Files.com supplied the independent SOC 2 and penetration test evidence ITx needed to keep hospital SFTP onboarding and its own compliance work moving.
ITx CompaniesFiles.com

ITx Companies is a US healthcare revenue cycle management firm that works only with healthcare clients. Operating as an extended business office for hospital systems and physician groups, ITx takes over the patient accounts its clients hand it and manages them across the full lifecycle, from billing follow-up to delinquent balance recovery.

The company's operating model is built on letting clients watch. Hospitals get at-will access to real-time account activity, down to the conversations ITx staff are having with their patients and insurance companies. Every engagement begins with a hospital sending ITx new patient accounts, which means protected health information crossing from a covered entity to a business associate. Under HIPAA, ITx's security is part of each hospital's own security, and hospital security teams treat it exactly that way.

Hospital Clients Gate File Connections on Security Evidence

As a HIPAA business associate, ITx faced recurring vendor security due diligence from its own clients. The scrutiny concentrated on one layer: file transfer, because that was where patient data crossed the boundary between the hospital and ITx.

That layer had been Fortra's GoAnywhere, an MFT platform ITx operated itself, which meant every piece of security evidence for it was ITx's to commission and keep current. Audit reports, penetration test results, and cyber insurance evidence all went into a hospital's vendor file before data started to move.

The cost landed at the worst possible moment: onboarding. In April 2024, a hospital client preparing to connect to ITx over SFTP requested security documentation before the connection went ahead. The immediate need was a penetration test report, within a day or two, along with a SOC 2 audit report. A connection the hospital was ready to open sat on paperwork, and the client relationship waited with it.

The bar was rising from inside as well: ITx was pursuing its own SOC 2 certification, and the file transfer platform had to be accounted for in its control environment.

What ITx needed was a transfer layer that arrived already attested: independent audit and test evidence it could hand a hospital on demand, and per-client controls that would stand up to the review those documents invite. ITx selected Files.com to be that layer.

A Transfer Layer That Arrives Already Audited

Today, the daily exchange with roughly 35 hospitals and vendors runs on Files.com.

The deployment was built to be reviewed. Each hospital client works inside its own folder structure, with group-based permissions scoping what that client's users can reach and nothing more. SFTP accounts use SSH keys, while IP whitelisting restricts where each account can connect from. Between Files.com and ITx's on-premise processing system, the Files.com Agent moves files over an outbound connection from inside ITx's network.

Each hospital is isolated to its authorized files, connections are restricted, and ITx can move data without opening an inbound connection.

A Hospital SFTP Onboarding Cleared, and ITx's SOC 2 Work Moved Forward

With Files.com carrying the exchange, ITx replaced security evidence it had to produce for infrastructure it ran itself with attestations it requests from its platform.

  • The hospital's SFTP onboarding went ahead: its security requirements were answered with Files.com's penetration test report and SOC 2 audit report, delivered within the hospital's timeline.
  • ITx's own SOC 2 certification drew on Files.com's SOC 2 Type 2 documentation, so the layer that moves PHI entered ITx's control environment already independently audited.
  • The next review has a standing answer: the same current reports cover every client connection on the platform, so a new hospital's due diligence starts a document request, not an evidence project.

The Layer Under Scrutiny Now Answers for Itself

Nothing about the scrutiny has changed. Hospitals still audit the vendors that touch their patients' data, and the file connection still draws the closest look. What changed is who produces the answer. For a business built on letting hospitals see exactly how their accounts are handled, the layer where their data crosses now comes with the same quality of proof.