Skip to main content

Hospital Security Reviews Become a Document Request After a Revenue Cycle Firm Replaces Fortra's GoAnywhere

Files.com's SOC 2 Type 2 and penetration test reports answer each hospital's vendor due diligence on demand and fold into the firm's own control environment.

A US healthcare revenue cycle management firm works only with healthcare clients. Operating as an extended business office for hospital systems and physician groups, the firm takes over the patient accounts its clients hand it and manages them across the full lifecycle, from billing follow-up to delinquent balance recovery.

The company's operating model is built on letting clients watch. Hospitals get at-will access to real-time account activity, down to the conversations the firm's staff are having with their patients and insurers. Every engagement begins with a hospital sending the firm new patient accounts, which means protected health information crossing from a covered entity to a business associate. Under HIPAA, the firm's security is part of each hospital's own security, and hospital security teams treat it exactly that way.

Hospital Clients Gate File Connections on Security Evidence

As a HIPAA business associate, the firm faced recurring vendor security due diligence from its own clients. The scrutiny concentrated on one layer: file transfer, because that was where patient data crossed the boundary between the hospital and the firm.

That layer had been Fortra's GoAnywhere, an MFT platform the firm operated itself, which meant every piece of security evidence for it was the firm's own to commission. Audit reports, penetration test results, and cyber insurance evidence all go into a hospital's vendor file before data starts to move.

The requests arrive at onboarding. A hospital preparing to connect to the firm over SFTP asks for security documentation before the connection goes ahead, and the ask is specific: a penetration test report and a SOC 2 audit report, on the hospital's timeline. The firm wanted that evidence ready to hand over the moment a hospital asked.

The file transfer platform also had to be accounted for in the firm's own SOC 2 control environment.

What the firm needed was a transfer layer that arrived already attested: independent audit and test evidence it could hand a hospital on demand, and per-client controls that would stand up to the review those documents invite. The firm selected Files.com to be that layer.

A Transfer Layer That Arrives Already Audited

Today, the daily exchange with dozens of hospitals and vendors runs on Files.com.

The deployment was built to be reviewed. Each hospital client works inside its own folder structure, with group-based permissions scoping what that client's users can reach and nothing more. SFTP accounts use SSH keys, while IP whitelisting restricts where each account can connect from. Between Files.com and the firm's on-premise processing system, the Files.com Agent moves files over an outbound connection from inside the firm's network.

Each hospital is isolated to its authorized files, connections are restricted, and the firm can move data without opening an inbound connection.

Standing Evidence for Every Hospital Connection

With Files.com carrying the exchange, the firm replaced security evidence it had to produce for infrastructure it ran itself with attestations it requests from its platform.

  • Hospital SFTP onboardings go ahead on the hospital's timeline: the security requirements are answered with Files.com's penetration test report and SOC 2 audit report.
  • The firm's own SOC 2 control environment draws on Files.com's SOC 2 Type 2 documentation, so the layer that moves PHI enters it already independently audited.
  • The next review has a standing answer: the same current reports cover every client connection on the platform, so a new hospital's due diligence starts a document request, not an evidence project.

The Layer Under Scrutiny Now Answers for Itself

Nothing about the scrutiny has changed. Hospitals still audit the vendors that touch their patients' data, and the file connection still draws the closest look. What changed is who produces the answer. For a business built on letting hospitals see exactly how their accounts are handled, the layer where their data crosses now comes with the same quality of proof.

Get The File Orchestration Platform Today

4,000+ organizations trust Files.com for mission-critical file operations. Start your free trial now and build your first flow in 60 seconds.

No credit card required • 7-day free trial • Live in minutes