Hospital Security Reviews Become a Document Request After a Revenue Cycle Firm Replaces Fortra's GoAnywhere
A US healthcare revenue cycle management firm works only with healthcare clients. Operating as an extended business office for hospital systems and physician groups, the firm takes over the patient accounts its clients hand it and manages them across the full lifecycle, from billing follow-up to delinquent balance recovery.
The company's operating model is built on letting clients watch. Hospitals get at-will access to real-time account activity, down to the conversations the firm's staff are having with their patients and insurers. Every engagement begins with a hospital sending the firm new patient accounts, which means protected health information crossing from a covered entity to a business associate. Under HIPAA, the firm's security is part of each hospital's own security, and hospital security teams treat it exactly that way.
Hospital Clients Gate File Connections on Security Evidence
As a HIPAA business associate, the firm faced recurring vendor security due diligence from its own clients. The scrutiny concentrated on one layer: file transfer, because that was where patient data crossed the boundary between the hospital and the firm.
That layer had been Fortra's GoAnywhere, an MFT platform the firm operated itself, which meant every piece of security evidence for it was the firm's own to commission. Audit reports, penetration test results, and cyber insurance evidence all go into a hospital's vendor file before data starts to move.
The requests arrive at onboarding. A hospital preparing to connect to the firm over SFTP asks for security documentation before the connection goes ahead, and the ask is specific: a penetration test report and a SOC 2 audit report, on the hospital's timeline. The firm wanted that evidence ready to hand over the moment a hospital asked.
The file transfer platform also had to be accounted for in the firm's own SOC 2 control environment.
What the firm needed was a transfer layer that arrived already attested: independent audit and test evidence it could hand a hospital on demand, and per-client controls that would stand up to the review those documents invite. The firm selected Files.com to be that layer.
A Transfer Layer That Arrives Already Audited
Today, the daily exchange with dozens of hospitals and vendors runs on Files.com.
The deployment was built to be reviewed. Each hospital client works inside its own folder structure, with group-based permissions scoping what that client's users can reach and nothing more. SFTP accounts use SSH keys, while IP whitelisting restricts where each account can connect from. Between Files.com and the firm's on-premise processing system, the Files.com Agent moves files over an outbound connection from inside the firm's network.
Each hospital is isolated to its authorized files, connections are restricted, and the firm can move data without opening an inbound connection.
Standing Evidence for Every Hospital Connection
With Files.com carrying the exchange, the firm replaced security evidence it had to produce for infrastructure it ran itself with attestations it requests from its platform.
- Hospital SFTP onboardings go ahead on the hospital's timeline: the security requirements are answered with Files.com's penetration test report and SOC 2 audit report.
- The firm's own SOC 2 control environment draws on Files.com's SOC 2 Type 2 documentation, so the layer that moves PHI enters it already independently audited.
- The next review has a standing answer: the same current reports cover every client connection on the platform, so a new hospital's due diligence starts a document request, not an evidence project.
The Layer Under Scrutiny Now Answers for Itself
Nothing about the scrutiny has changed. Hospitals still audit the vendors that touch their patients' data, and the file connection still draws the closest look. What changed is who produces the answer. For a business built on letting hospitals see exactly how their accounts are handled, the layer where their data crosses now comes with the same quality of proof.
Related Customer Stories
A Pharmaceutical Company Verifies and Forwards Terabytes of GxP Acquisition Data With Files.com
A repeatable SFTP staging and verification workflow receives each counterparty’s data, reconciles it against the manifest by MD5 hash, and forwards it to Box and Veeva Vault on the deal’s deadline.
Read The Story
A Life-Sciences Supplier Retired Its Self-Hosted FTP Servers With Files.com at MuleSoft’s Transfer Edge
A UK-locked landing zone now handles machine traffic from FTP-only counterparties while MuleSoft continues to orchestrate the integrations behind it.
Read The Story
A Digital Health Company Configures Dozens of Health Plan SFTP Connections in Files.com, Not Custom Code
Files.com Remote Servers and automations now move regulated clinical reports from AWS to payer-owned endpoints while operations staff handle routine delivery.
Read The Story
Get The File Orchestration Platform Today
4,000+ organizations trust Files.com for mission-critical file operations. Start your free trial now and build your first flow in 60 seconds.
No credit card required • 7-day free trial • Live in minutes