Skip to main content

Momentm Technologies Turned One Files.com Site Into a Private PHI Exchange for Every Client

Files.com gave internal teams and outside clients different access paths, enforced regional isolation, and created the audit trail Momentm needed without an in-house build.
Momentm TechnologiesFiles.com

Momentm Technologies builds the software that runs non-emergency medical transportation across North America. Its NovusMED platform handles scheduling, dispatch, billing, and compliance for the organizations that move patients to medical care when an ambulance is too much and an ordinary ride is not enough: Medicaid and Medicare Advantage plans, managed care organizations, brokers, PACE programs, and large-scale transportation providers. The company describes its software as managing every step of the NEMT journey, from eligibility verification through reimbursement.

Every step of that journey is health data. A trip record ties a person to a place and a medical appointment. A claims file prices it. Both are protected health information under HIPAA, and both flow constantly between Momentm and its client organizations: clients send trip and claims files to Momentm's customer care and support teams, and those teams send files back. File exchange is not incidental to this business. It is how the business runs.

Momentm needed one branded, multi-tenant portal that could act as a separate, controlled exchange for every client without becoming a product its engineers had to build.

Trip and Claims Files Were Traveling by Email

The channel for that exchange was ordinary email. A client's staff attached a PHI-bearing file and sent it in; Momentm's staff replied the same way.

The cost of that was legal before it was operational. Email keeps no client's data apart from any other's. It enforces nothing about who authenticates or how. No business associate agreement covered the PHI sitting in those attachments, which HIPAA requires of any arrangement that handles it. And email leaves no record the company controls. Momentm's General Manager framed the stakes in exactly those terms: if the company's handling of PHI were ever challenged in court, it would need to produce a record of what happened and when. Email produces no such record.

One Secure Inbox Would Not Have Fixed It

The obvious fix, a single secure drop point, did not match the shape of the problem. Momentm exchanges files with many independent client organizations at once, and its VP of Security and Compliance set out what the replacement had to do. Each client's technical staff, one person or several, had to reach their own folder and nothing else. Momentm's staff had to see every client folder. Internal staff had to authenticate through the company's Azure Active Directory, with single sign-on and two-factor authentication; client users, who have no place in that directory, needed two-factor authentication of their own. The whole thing had to run under Momentm's name, not a vendor's. And there was a jurisdictional axis on top: most clients' data had to stay in the United States, while a small number had to be restricted to Canada, in separate folders.

That was not a transfer tool. That was a multi-tenant client portal, with tenancy, two authentication regimes, a folder-level permission model, the protocols clients already use, residency controls, and logging. Built in-house, it would have been a product in itself, competing for engineering time with the software Momentm actually sells, and it would still have needed a HIPAA business associate agreement behind whatever it ran on.

Momentm selected Files.com to be that exchange: one multi-tenant site under Momentm's own brand, covered by an executed Files.com HIPAA BAA.

One Site That Acts as a Separate Exchange for Every Client

Files.com became Momentm's branded client file exchange. To Momentm it is one site with one set of controls. To each client organization it looks like a private exchange of their own.

Each client gets a folder and its own logins, and Files.com folder-level permissions make the isolation structural. A client's technical staff see their folder and nothing beyond it, while Momentm's customer care and support staff see every client folder and move trip and claims files in both directions.

Internal staff sign in through Azure Active Directory single sign-on with two-factor authentication. Client users authenticate outside that directory, with two-factor authentication enforced by Files.com, and can connect using SFTP, FTPS, WebDAV, or the web interface.

The site answers on Momentm's own domain, so the exchange a client sees carries Momentm's name end to end. It also means the endpoint lives inside Momentm's own security posture: the security team tracks it through SecurityScorecard, the third-party rating service it uses across its estate, and holds it to the same expectations as everything else it operates.

Within the same site, regional restrictions keep US and Canadian client data in the required regions and separate folders. Files.com retention rules expire files after 60 days, and every login and file action lands in the site's audit log.

PHI Off Email, With a Record Momentm Can Produce

With the exchange in production, Momentm replaced an email habit with a repeatable pattern: clients are directed away from email and given a folder and a login on the company's own address.

  • Client PHI no longer travels by email. Trip and claims files move through per-client folders under a HIPAA BAA.
  • The record exists before anyone asks for it. Every login and file action is logged, so the account of what happened and when comes from the platform instead of being reconstructed from inboxes.
  • Onboarding the next NEMT client is a folder and a login inside controls that already exist—no development and no new channel for the security team to review.

The Client Portal Momentm Never Had to Build

Today a client's technical staff drop a claims file into their own folder, on an address that carries Momentm's name, using the transfer client they already run, and Momentm's care team picks it up from the other side. Nobody decides whether an attachment is safe to send, because there is no attachment; the safe path is the only path a client is given.

What Momentm's requirement described was a product: multi-tenant, branded, dual-authentication, region-aware, auditable. What it stood up instead was a configuration of Files.com, and its engineering stayed on the transportation software it sells.