SlateRx Put a HIPAA-Governed Files.com Front Door on Its S3-to-Snowflake Pipeline
A benefits administrator runs on files other companies send. SlateRx administers pharmacy benefits for employer groups, unions, public-sector groups, and health systems across the United States. The company entered the market in January 2024 with compliance as part of its offering, backed by URAC accreditation for pharmacy benefit management and a completed SOC 2 audit.
Every employer client feeds SlateRx eligibility and claim data from systems SlateRx does not control, and nearly all of it is protected health information under HIPAA. Before the company could process claims at any scale, it needed a way for those files to arrive that it could stand behind. Rather than build and operate SFTP infrastructure or turn Snowflake into a file manager, SlateRx put Files.com between client connections and its existing S3-to-Snowflake pipeline before claims volume arrived.
Claim Data Arriving With No Security Guarantee
When SlateRx stood up its claims operation in late 2023, client claim data was arriving through transfer methods that carried no security guarantee, and moving each file into the processing pipeline was manual work. The files were eligibility and claims data, PHI in nearly every case. For a company selling compliance to plan sponsors, every file traveling an unguaranteed channel was regulatory and contractual exposure, carried daily. And the manual handling had a ceiling: SlateRx expected very high daily claim volumes from the start, across a client list built to grow.
The diagnosis was simple. SlateRx had launched a claims business without a governed front door for the data the business runs on.
The Warehouse Was Never Going to Manage Files
SlateRx controlled only one end of every exchange. Clients send from their own HR and payroll systems, at varying levels of technical sophistication, and SlateRx could not dictate what runs on the other side. On its own side, the pipeline was already designed: files land in an AWS S3 bucket, ETL prepares the data, and Snowflake consumes it. What was missing was the layer in between, something that takes files in securely from many senders and hands them to S3.
Pushing that job into the data stack was the wrong answer, as SlateRx’s data engineering lead put it plainly:
“Snowflake doesn’t really have a file management function.”
Building and operating hardened SFTP infrastructure in-house was the other answer, and it meant a second infrastructure project for a months-old company already building a pipeline. So the intake layer had a specification: speak SFTP so clients connect with tools they already have, keep every client’s data apart with its own credentials and folders, run under SlateRx’s own name, operate under a HIPAA Business Associate Agreement, and pass each file into S3 with no one in the loop.
SlateRx selected Files.com to be that intake perimeter.
SFTP in Front, S3 and Snowflake Behind
SlateRx stood up its Files.com site on its own branded domain, so clients connect to SlateRx, not to a third-party address. Each employer client got its own SFTP users, folders, and folder permissions, so no counterparty can see another’s data. A single client relationship, counting the brokers and vendors attached to it, can require ten or fifteen accounts.
From there the file never waits on a person. A claim file uploaded over SFTP lands in the sending client’s folder, and a Files.com Sync moves it into the S3 bucket where ETL runs; the prepared data then loads into Snowflake. Nobody at SlateRx downloads a file from one system and re-uploads it to another.
Two design choices round out the perimeter. Retention on the Files.com side is deliberately short-term: the platform is the exchange surface and S3 holds the durable archive, so the externally reachable layer never accumulates PHI. And for counterparties whose security teams pin connections to known addresses, SlateRx shares dedicated Files.com IP addresses and enforces IP whitelisting.
The Perimeter Came Before the Volume
With the Files.com perimeter in production, SlateRx replaced unguaranteed channels and manual handling with one governed path that every client uses. Every eligibility and claims file now arrives over SFTP, under a HIPAA BAA, into a folder scoped to the client that sent it, and reaches the S3-to-Snowflake pipeline with nobody moving it by hand.
Onboarding the next employer client repeats the pattern instead of restarting the project: new folders, credentials, and routing on the same site. That pattern now covers more than 100 employer-client folder structures, each with its own file-routing configuration.
SlateRx never built transfer infrastructure, and it never bent its warehouse into a file manager. It put Files.com in front of the pipeline it already had. For a company that entered the market with compliance as part of its pitch, the order mattered: the governed intake existed before the claim volume did, and the pipeline behind it never had to change to make room for it.
Related Customer Stories
Health & Life Sciences
Nestlé Health Science Moves 10 TB of Regulated Acquisition Data in One Month with Files.com
A repeatable SFTP staging and verification workflow keeps multi-terabyte GxP data moving without waiting six months to a year for internal infrastructure.
Read story →
Health & Life Sciences
Abcam Retired Its Self-Hosted FTP Servers With Files.com at MuleSoft’s Transfer Edge
A UK-locked landing zone now handles machine traffic from FTP-only counterparties while MuleSoft continues to orchestrate the integrations behind it.
Read story →
Health & Life Sciences
Everly Health Solutions Configures 40 Health Plan SFTP Connections in Files.com, Not Custom Code
Files.com Remote Servers and automations now move regulated clinical reports from AWS to payer-owned endpoints while operations staff handle routine delivery.
Read story →