Skip to main content

Lexitas Automates Partner-Mandated PGP-over-SFTP Exchange With Insurers and Hospitals on Files.com

Files.com let Lexitas conform to each counterparty's supplied key, SFTP endpoint, and schedule while retiring its own transfer servers.
LexitasFiles.com

Lexitas is a national litigation services provider headquartered in Houston. It has grown from court reporting into a full litigation support operation, including record retrieval, process service, and legal staffing for law firms, insurers, and corporate clients across the country. Its medical-records operations also put the company alongside healthcare organizations handling sensitive data.

Those records do not stay at Lexitas. The business sits between the hospitals and custodians who hold records and the insurance carriers, third-party administrators, and law firms who need them. Every retrieved record has to move to or from a counterparty, and the institutions on the other end set their own terms for how.

The challenge was to meet each institution's mandate without keeping a person—or a Lexitas-run transfer server—in the middle.

The Counterparties Dictate the Protocol and Supply the Keys

Hospitals and insurance carriers still ask for SFTP. Many go further and require that files be PGP-encrypted to keys they supply, delivered to SFTP endpoints they run. On these exchanges, Lexitas does not choose the protocol, the encryption key, or the destination. The client does, and each client's setup has its own quirks.

Before Files.com, meeting those terms was manual work, partner by partner. Medical records, court reporting records, and subpoenaed records were pulled from client endpoints and placed by hand. The exchanges ran on transfer servers that Lexitas's own IT team had to stand up, patch, and support. Each exchange had a person in the loop, and the clients on the other end included major insurance carriers, where getting an exchange wrong was never a small mistake.

The problem was structural, not just operational. This is not work a file-sharing portal can absorb, because the counterparty will not change how it operates: a carrier that mandates PGP over SFTP expects encrypted files to arrive at its own server, on its own schedule. Whatever handled the exchange had to conform to each partner's terms while taking the person out of the middle of it.

What the Exchange Layer Had to Do

Lexitas wanted out of the transfer-server business entirely. Files.com became the replacement exchange layer, handling partner-mandated SFTP transfers and encryption without requiring Lexitas to operate the underlying servers.

I don't want to stand up a server on my own. That's the reason we went to you guys, so I could decommission that old system.
James Malek, Vice President, IT Infrastructure, Lexitas

Encryption Per Partner, Enforced by the Folder

On Files.com, each counterparty's terms became configuration rather than a person's job.

Each client's supplied public key was loaded into the Files.com GPG Key Manager and attached at the folder level. Files that landed in a client's outbound folder were encrypted to that client's key automatically before they went anywhere. Encrypted files arriving from partners were decrypted on arrival, so the records teams downstream received usable files. The folder enforced a separate encryption boundary per partner, and nobody at Lexitas ran an encryption step by hand.

Delivery conformed to the partner too. Files.com remote server connections reached out to each client's own SFTP endpoint, so carriers kept receiving files exactly where and how they always had. Lexitas asked none of them to change anything.

The movement itself was scheduled. Scheduled jobs moved the files, and source files were deleted as pulls completed. Each file was handled once, without lingering in a partner's outbox to be processed again.

Years on the Same Key, With No One in the Loop

With the exchange running on Files.com, Lexitas replaced one-at-a-time manual transfers with a per-partner pattern that runs on a schedule. For one major insurance carrier, the encrypted exchange has run for years on the same client-supplied key, with scheduled jobs, automatic encryption, and no manual handling.

The transfer servers Lexitas once ran itself were decommissioned, and no server has stood back up in the years since.

Taking on the next counterparty mandate now means configuring a folder with that client's key, an outbound connection to its endpoint, and a scheduled job. The same pattern applies again instead of being rebuilt per client.

A Counterparty's Mandate Is Now Standard Work

Today, when a hospital or an insurance carrier hands Lexitas a public key and an SFTP host, nobody inherits a standing manual chore. The key goes into Files.com, the folder enforces the encryption, the connection reaches the client's endpoint, and the schedule does the moving. The counterparties have not changed how they work. What changed is what it costs Lexitas to meet them: an exchange that once depended on a person pulling, encrypting, and placing files by hand is now a pattern Files.com runs on its own, set up once per partner and repeated every day after that.