Secure Vendor File Exchange: Reducing PHI Exposure
Most PHI leaving a hospital goes to a vendor, and most of it moves by whatever was easiest to set up. Replacing ad-hoc transfer with something governed, without breaking operations.
GuardsArm Team
Security Experts
More PHI leaves a hospital through routine vendor file transfer than through any breach. Billing extracts, claims files, transcription audio, research datasets, imaging for second opinion, population health feeds — all moving daily, most of it configured years ago by whoever needed it to work that afternoon.
Inventory first — you will find surprises
Nobody has a complete list. Build one by evidence rather than by asking:
- Firewall logs for outbound SFTP, FTP and HTTPS to non-standard destinations
- Email gateway reporting on large or frequent external attachments
- Interface engine outbound routes
- Scheduled jobs on servers that produce and push extracts
- Accounts payable — every vendor being paid is a candidate for a data flow
Record per flow: what data, which vendor, what method, how often, who owns it, whether a BAA exists, and whether anyone reviews it.
Rank the methods honestly
| Method | Verdict |
|---|---|
| Email attachment, unencrypted | Unacceptable for PHI |
| Email with portal-based encryption | Tolerable for one-off, ad-hoc exchange |
| Plain FTP | Unacceptable — credentials and data in clear text |
| SFTP with password authentication | Workable baseline |
| SFTP with key authentication, IP-restricted | Good |
| Managed file transfer platform | Best — governance, logging and retention built in |
| Vendor's own portal | Depends entirely on the vendor; assess it |
| API with OAuth and scoped access | Best for ongoing structured exchange |
Send less
The most effective control is not how the data moves but how much of it does.
Vendors routinely request full extracts because it is easier than specifying. Ask what they actually process. The reduction from "the whole patient record" to "these six fields for these dates" is usually available for the asking, and it shrinks the consequence of every future mistake.
Governance that keeps working
- A named owner per flow, on the business side, not IT
- A BAA in place before any PHI moves, verified rather than assumed
- Credential rotation on a schedule, including vendor-side keys
- Annual review: is this flow still needed, still minimal, still correct?
- Offboarding: when the vendor relationship ends, the transfer account and the data they hold both need explicit treatment
- Monitoring for volume anomalies — a transfer that suddenly triples is either a business change or a problem
That last point is the detection most often missing. These flows are so routine that nobody watches them, which makes them an attractive channel for exfiltration disguised as normal operation.
When the vendor is breached
Assume at least one of your vendors will be. What determines your exposure is decided long before the call comes.
| Prepared in advance | Why it matters on the day |
|---|---|
| You know exactly what data they hold | Otherwise scoping your own notification obligation takes weeks |
| You know the date range and field list | Determines how many individuals are affected |
| The BAA specifies a notification deadline to you | Vendors otherwise notify at their own pace |
| You can revoke their access in minutes | Limits continued exposure during their incident |
| You retain your own copy of what was sent | Lets you verify their account of the scope |
The first row is the one that hurts. A hospital that cannot say precisely what it sent a transcription vendor over three years ends up notifying conservatively — which means notifying more people, at greater cost and reputational damage, than the incident actually warranted.
Where to start
Search outbound firewall logs for FTP and SFTP over the last 90 days and list the destinations. Most hospitals find at least one active transfer nobody can immediately explain. That list is your inventory, and the unexplained entries are your first work.
This connects to contractor identity governance, since the accounts behind these transfers are frequently the oldest and least reviewed in the directory.
GuardsArm inventories and re-platforms vendor data flows for healthcare organisations, including minimisation review. Book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on “Secure Vendor File Exchange: Reducing PHI Exposure”
Talk to the GuardsArm team about how these services apply to your environment.


