Skip to main content

Lexitas Keeps SFTP for Hospitals and Insurers Without Running Transfer Servers

Files.com preserved the connection pattern Lexitas’s regulated counterparties already used while moving the underlying endpoint off self-maintained infrastructure.
LexitasFiles.com

Lexitas is a leading technology-enabled litigation services provider. From its Houston headquarters, its more than 1,300 team members deliver court reporting and depositions, record retrieval, process service, and legal staffing to law firms, insurers, corporations, and third-party administrators across the United States. The record retrieval operation alone runs on over 4 million provider and custodian relationships, with a 98% record completion rate, inside a HIPAA-compliant framework for storing and transmitting medical records.

Nearly everything Lexitas sells ends with a file changing hands. A deposition transcript goes to counsel. A medical record comes out of a hospital and goes to an insurance carrier. A subpoenaed record moves between parties who are, by definition, careful about how it moves. Exchanging regulated files with regulated counterparties is not a side effect of the business. It is the business. Hospitals and insurers still expected SFTP, and someone in IT had to run the machinery behind it.

The Transfer Servers Nobody Wanted to Own

For years, that machinery was Lexitas's own. The IT organization stood up, patched, and supported its own on-premises SFTP and FTP servers to move legal and medical records with clients and partners. That meant more than uptime work. It meant owning the security of self-maintained transfer infrastructure carrying medical records — the patching, the hardening, the support queue — for a team whose actual job was serving a litigation business.

The diagnosis was simple: Lexitas was in the transfer-server business, and it never wanted to be.

The Hospitals and Insurers Ask for SFTP

The servers could not simply be switched off. Live client and partner exchange depended on them, so any replacement had to absorb those workloads first — and it had to speak the protocol the counterparties demand. Lexitas already ran file-sharing and collaboration platforms, with BAAs in place. None of them answered the actual requirement, because the hospitals and insurance carriers on the other side of a records exchange do not ask for a portal. They ask for SFTP.

A lot of these hospitals and insurance companies still want to use SFTP.
James Malek, Vice President, IT Infrastructure, Lexitas

So the replacement had a clear specification: a hosted SFTP and FTP endpoint that partners could connect to exactly as before, sturdy enough for regulated legal and medical records, able to grow with the user base — and operated by someone other than Lexitas. Lexitas selected Files.com to be that endpoint.

I don't want to stand up a server on my own. That's the reason we went to you guys, so I could decommission that old system.
James Malek, Vice President, IT Infrastructure, Lexitas

An SFTP Endpoint Lexitas Doesn't Operate

Lexitas moved its transfer workloads and internal users onto Files.com and made the platform the endpoint it presents to the outside world. Hospitals, insurers, and law-firm clients connect over SFTP — the protocol they were already asking for — with FTP available where a counterparty needs it. Nothing about the exchange pattern changed for the partners. What changed is that no Lexitas server sits behind it.

Identity followed the same principle. Lexitas connected Files.com to its single sign-on from the start, and as adoption spread, layered on Files.com SCIM provisioning: accounts are created and updated from the company directory, and access is cut automatically when someone leaves. The IT team stopped creating and retiring file-transfer users by hand, the same way it stopped patching the servers they logged into.

The Old Servers Never Came Back

With the workloads moved, Lexitas decommissioned its on-premises transfer infrastructure — and the state it wanted turned out to be permanent.

  • The self-hosted SFTP and FTP servers are gone, and in the years since the cutover, no transfer server has stood back up.
  • The risk of carrying regulated legal and medical records on self-maintained infrastructure went with them, along with the patching and support work that infrastructure demanded.
  • Adoption grew roughly fivefold over about three years, absorbed without building or buying anything — new users are provisioned from the directory, and the endpoint scaled without a capacity project.
  • Hospitals and insurers still get the SFTP they require.

Out of the Server Business, Still an SFTP Counterparty

The protocol survived; the servers did not.