Skip to main content

HRI Dental & Vision Made Its 834 Enrollment Endpoint Independent of Divestitures With Files.com

When a sold business unit took the old file server with it, HRI had to rebuild every partner connection on an SFTP endpoint held in its own name.
ProMedica Health System / HRI Dental & VisionFiles.com

HRI Dental & Vision provides dental and vision benefits to roughly 250,000 members. It operates as part of ProMedica Health System.

Coverage starts with enrollment, and enrollment arrives as data. Agents, producers, and EDI vendor groups send ANSI X12 834 enrollment files, the standard EDI format for membership enrollment, into HRI, where a dedicated team receives, validates, and processes them. Each sender runs its own automation against HRI's intake point, on its own schedule, under its own security policy.

HRI also lives inside a corporate structure that moves. For a company whose partners connect to it by machine, every day, the question of who actually owns that connection point is not abstract. A divestiture forced HRI to rebuild every connection once; its answer was to make sure the exchange point would no longer move with a business unit.

The File Server Belonged to a Business Unit That Was Sold

For years, the exchange point for all of that partner traffic was an internal file server running PGP encryption, owned and operated inside one of the company's business units. Then that unit was sold, and the server went with it. The infrastructure every trading partner connected to was leaving the company.

Every connection had to be rebuilt somewhere else: partner accounts, encryption keys, IP restrictions, and, on the far side, the automation each agent and vendor group runs against HRI's endpoint. None of that automation belonged to HRI. Each partner had to be moved individually, and the deadline came from a corporate transaction, not from the EDI team's readiness.

The deeper problem was structural. Any replacement server standing inside another business unit would carry the same exposure. A transfer point that lives in one unit's data center is only as durable as that unit's place in the portfolio, and the portfolio is decided far above the team that runs the files.

What HRI needed was an exchange point no transaction could reach: held under HRI's own agreement rather than any unit's infrastructure, speaking the SFTP its partners already automate against, carrying HRI's own brand, able to satisfy each vendor's security mandate, and covered by a HIPAA business associate agreement. HRI selected Files.com to be that platform.

An SFTP Endpoint Held in HRI's Own Name

HRI's own EDI specialist ran the cutover onto Files.com-hosted SFTP, at an address carrying HRI's own brand, so partners connect to HRI rather than to a third-party tool. The agreement sits with HRI itself, with a HIPAA business associate agreement and encryption processes in place from the start in 2016.

Partner connections were rebuilt incrementally, and HRI runs the onboarding itself. HRI scripted the account side against the Files.com REST API and .NET SDK years ago, so user creation and folder provisioning for each new group run as code; HRI then applies whatever notifications, keys, or IP restrictions that partner requires.

One Endpoint, a Different Security Posture for Every Partner

On the old server, PGP was the server's feature. On Files.com, it became one option among several, applied partner by partner as each vendor's policy demands.

When one EDI vendor mandated encrypted exchange, HRI turned it on through Files.com's GPG support, and files that vendor encrypts are decrypted inside the Files.com folder they land in, ready for processing. When another vendor's policy ruled out password access, HRI switched that connection to SSH key authentication. IP whitelists restrict each account to the addresses a partner actually sends from, and per-vendor email notifications tell HRI's team when files arrive. Each mandate was met with configuration on a platform HRI already ran, not with a new project.

Fifty Groups a Day, and a Fourth-Quarter Surge

With the cutover behind it, HRI traded a server it happened to share a company with for an intake point it holds in its own name. The exchange has run in production on Files.com since 2016.

  • About 50 vendor groups a day, on a weekly average, deliver 834 enrollment files through the single SFTP intake, most over their own automation.
  • Onboarding the next partner is configuration HRI performs itself: an account, a folder, a key or an IP whitelist, a notification. Steady growth as more groups move to electronic transfer, and the open-enrollment surge every fourth quarter, land on the platform rather than on new infrastructure.
  • A vendor's security mandate no longer starts a project, because encryption, key-based access, and IP restrictions are already on the platform waiting to be applied.
  • Encrypted exchange has become part of how HRI sells, offered as an option in new growth opportunities.

The Next Transaction Is Not a Migration

Since the migration, the exchange point has remained under HRI's own agreement rather than inside a business unit that could be sold. The endpoint its agents, producers, and vendor groups connect to has not moved since 2016.

The server we were using was part of one of our business units that sold, so it was a big migration process. If something happens, we don't have to rely on that. We can rely on what you guys have.
Mike Pulsfort, EDI Dental/Vision Specialist, HRI Dental & Vision

File transfer infrastructure that lives inside one business unit is exposed to every transaction its parent makes. By putting partner exchange on Files.com, HRI took its most partner-facing system out of that blast radius entirely. Today, a corporate sale is a line in a deal memo, not a coordinated cutover across every trading partner the company has.