Skip to main content

ITx Replaced Fortra's GoAnywhere With Files.com and Took People Out of Daily Hospital PHI Transfers

A scripted migration rebuilt the client estate, reached an internal processing server without opening inbound firewall ports, and turned manual PHI handling into an end-to-end automated pipeline.
ITx CompaniesFiles.com

ITx Companies runs an extended business office for hospitals and physician groups. Client hospitals hand over their patient receivables, and ITx works the accounts on their behalf: resolving patient balances, sending statements by program, and managing bad-debt recovery. The company takes only healthcare clients, serves everything from multi-hospital systems to growing practices, and made the 2023 Inc. 5000 as one of the fastest-growing revenue cycle management firms in the country.

That business model has file exchange built into its foundation. A hospital that outsources its receivables has to send ITx new patient accounts, and ITx has to send results back. Roughly 35 hospitals and vendors transact with ITx this way, every day, and every one of those files carries protected health information and billing data governed by HIPAA. Some clients run sophisticated IT operations and some do not, and all of them have to be served on the same day, on the same schedule.

A Manual Hop in the Middle of Every Day's PHI Exchange

ITx ran that exchange on GoAnywhere by Fortra. The platform held the client-facing side: per-client folder trees, group configurations, and the transfer workflows for every hospital and vendor. What it did not do was carry a file all the way through. Files that hospitals dropped off had to be moved by hand between the transfer platform and the processing server inside ITx's own environment, and processed deliverables moved back out the same way. The most sensitive traffic in the business had people as its transport layer, and the handling repeated for every client, every day.

ITx had outgrown that arrangement. CIO Jeffery Keller's team needed a secure, encrypted import and export process with real automation and configurable per-user security, and the incumbent platform was not delivering it. Leaving was its own problem, in two ways. First, the estate was large and bespoke, with per-client folder structures, 69 permission groups, and 40 clients each exchanging four distinct file types, and all of that configuration lived inside GoAnywhere. Second, the processing server sat behind ITx's firewall, and the team did not want to open inbound firewall ports or write and maintain its own scheduled sync scripts just to let a cloud platform reach it.

So the replacement had to do specific things: automate import and export end to end, encrypt the exchange, give each hospital its own scoped credentials over SFTP, reach the internal processing server without exposing it to the internet, and be buildable from the estate GoAnywhere already held rather than reconstructed from memory. ITx selected Files.com to replace GoAnywhere as that layer.

Rebuilt by Script From GoAnywhere's Own Export Data

The rebuild started from GoAnywhere's own export data. Using the Files.com CLI, ITx's systems architects generated 69 groups by script directly from the exported configuration and built the folder structure to mirror the layout hospitals already used, so clients did not have to relearn where anything lived. User accounts were bulk-imported by CSV with group assignments and IP whitelisting already applied, and SSH keys were generated as clients needed them. Every hospital and vendor connects the same way, over SFTP into its own scoped folder, whatever its technical sophistication.

The migration did not depend on anyone's recollection of how the old platform had been configured. The old platform's export became the new platform's build input.

An Outbound-Only Path to the Processing Server Behind the Firewall

To connect the client-facing side to the processing side, ITx installed the Files.com Agent inside its own environment. The Agent made an outbound-only, encrypted connection to Files.com, so the processing server was never exposed to the internet and no inbound firewall port was opened. Through that connection, more than 70 one-way sync behaviors were configured to carry files in both directions: a hospital's upload synced from its Files.com folder into the processing system, and processed deliverables synced back out to the client's folder for pickup.

On top of the pipeline, ITx built more than 240 Files.com Automations, 44 moving outbound deliverables and over 200 filing inbound documents. Each one matched filename patterns that identified the client and the file type, across 40 clients with four file types apiece, so originals, completed work, and rejected records would all land in per-client archive folders on their own.

The cutover was deliberate. Every sync and automation was created in a disabled state and enabled selectively, starting with smaller clients. Before the switch, the team verified the migration independently in FileZilla: file counts and total size matched exactly between GoAnywhere and Files.com. The move was proven, not assumed.

Daily Transfers With 35 Hospitals Now Run Without a Person in the Path

With the Files.com pipeline in production, ITx retired GoAnywhere and replaced a daily workflow that had people at its center with one that runs on its own.

  • Daily business-to-business file transfer with roughly 35 hospitals and vendors runs on Files.com, and GoAnywhere is gone.
  • No one at ITx moves a client file by hand anymore. Uploads sync into the processing system, deliverables sync back to each client's folder, and the archive automations file matching documents by client and type.
  • PHI now travels an encrypted, credentialed, automated path from the hospital's folder to the processor and back, instead of being carried between platforms by a person.
  • Onboarding the next hospital is a script run, not a build. The per-client pattern of folders, group, users, syncs, and pattern-matched automations is generated the same way the original 69 groups were, so each new client is incremental volume on a design that already exists.

A Legacy MFT Estate Rebuilt Without a Leap of Faith

The way ITx got there is the part worth carrying away: a legacy MFT estate with hundreds of per-client workflows did not have to be untangled by hand or cut over on a leap of faith. GoAnywhere's own export data became the input to the Files.com build, the workflows went live one client at a time, and the numbers were checked before anything switched.