Back to Blog
Data Protection
8 min read

Secure Vendor File Exchange: Reducing PHI Exposure

Most PHI leaving a hospital goes to a vendor, and most of it moves by whatever was easiest to set up. Replacing ad-hoc transfer with something governed, without breaking operations.

GuardsArm Team

Security Experts

December 23, 2025

Secure file exchange

More PHI leaves a hospital through routine vendor file transfer than through any breach. Billing extracts, claims files, transcription audio, research datasets, imaging for second opinion, population health feeds — all moving daily, most of it configured years ago by whoever needed it to work that afternoon.

Daily and invisible
Routine transfers are rarely inventoried or reviewed after setup
Ad-hoc by default
Email attachments and legacy FTP persist because they work
Your liability
A BAA allocates responsibility; it does not prevent the disclosure

Inventory first — you will find surprises

Nobody has a complete list. Build one by evidence rather than by asking:

  • Firewall logs for outbound SFTP, FTP and HTTPS to non-standard destinations
  • Email gateway reporting on large or frequent external attachments
  • Interface engine outbound routes
  • Scheduled jobs on servers that produce and push extracts
  • Accounts payable — every vendor being paid is a candidate for a data flow

Record per flow: what data, which vendor, what method, how often, who owns it, whether a BAA exists, and whether anyone reviews it.


Rank the methods honestly

MethodVerdict
Email attachment, unencryptedUnacceptable for PHI
Email with portal-based encryptionTolerable for one-off, ad-hoc exchange
Plain FTPUnacceptable — credentials and data in clear text
SFTP with password authenticationWorkable baseline
SFTP with key authentication, IP-restrictedGood
Managed file transfer platformBest — governance, logging and retention built in
Vendor's own portalDepends entirely on the vendor; assess it
API with OAuth and scoped accessBest for ongoing structured exchange
Legacy FTP outlives every migration project
It is the transfer method most likely to still be running years after it was scheduled for replacement, because it works and nobody owns it. Search your firewall logs for port 21 specifically — it is usually still there, usually carrying something sensitive.

Send less

The most effective control is not how the data moves but how much of it does.

Reduce before you protectEach step removes data from the transfer before transport security is considered, which reduces exposure more than any encryption choice.Do we need to send?often noMinimum fieldsnot the whole recordDe-identifywhere purpose allowsLimit windownot all historyThen secure ittransport
A vendor asking for a full extract frequently needs six fields and a date range.

Vendors routinely request full extracts because it is easier than specifying. Ask what they actually process. The reduction from "the whole patient record" to "these six fields for these dates" is usually available for the asking, and it shrinks the consequence of every future mistake.


Governance that keeps working

  • A named owner per flow, on the business side, not IT
  • A BAA in place before any PHI moves, verified rather than assumed
  • Credential rotation on a schedule, including vendor-side keys
  • Annual review: is this flow still needed, still minimal, still correct?
  • Offboarding: when the vendor relationship ends, the transfer account and the data they hold both need explicit treatment
  • Monitoring for volume anomalies — a transfer that suddenly triples is either a business change or a problem

That last point is the detection most often missing. These flows are so routine that nobody watches them, which makes them an attractive channel for exfiltration disguised as normal operation.


When the vendor is breached

Assume at least one of your vendors will be. What determines your exposure is decided long before the call comes.

Prepared in advanceWhy it matters on the day
You know exactly what data they holdOtherwise scoping your own notification obligation takes weeks
You know the date range and field listDetermines how many individuals are affected
The BAA specifies a notification deadline to youVendors otherwise notify at their own pace
You can revoke their access in minutesLimits continued exposure during their incident
You retain your own copy of what was sentLets you verify their account of the scope

The first row is the one that hurts. A hospital that cannot say precisely what it sent a transcription vendor over three years ends up notifying conservatively — which means notifying more people, at greater cost and reputational damage, than the incident actually warranted.

Keep a transfer manifest
Logging what was sent, when, and to whom — not the data itself, just the metadata — costs almost nothing and is the difference between a precise notification and a blanket one. Retain it for at least as long as the underlying records.

Where to start

Search outbound firewall logs for FTP and SFTP over the last 90 days and list the destinations. Most hospitals find at least one active transfer nobody can immediately explain. That list is your inventory, and the unexplained entries are your first work.

This connects to contractor identity governance, since the accounts behind these transfers are frequently the oldest and least reviewed in the directory.

GuardsArm inventories and re-platforms vendor data flows for healthcare organisations, including minimisation review. Book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on “Secure Vendor File Exchange: Reducing PHI Exposure”

Talk to the GuardsArm team about how these services apply to your environment.