HIPAA-Compliant SFTP and Storage for Healthcare ePHI
SFTP secures a file transfer over an encrypted SSH connection, but the protocol only governs the transfer itself. For healthcare organizations handling ePHI, there is still plenty to manage once the file arrives: where it's stored, who can access it, what happens to it next, and whether there is a reliable record of that activity.
Managed SFTP and managed file transfer (MFT) services extend well beyond a bare SFTP endpoint. They can combine secure cloud storage, user and directory controls, audit records, file automation, and integration options around the same file environment. Instead of treating SFTP as the whole solution, it becomes one secure way into and out of a wider managed service.
HIPAA doesn't prescribe SFTP or certify a particular transfer protocol as compliant. The HIPAA Security Rule applies to the ePHI an organization creates, receives, maintains, or transmits, so secure transport is only one part of the overall responsibility.
In practice, HIPAA-compliant SFTP is better understood as secure SFTP used within an environment that can support the wider controls and responsibilities around healthcare data. That’s why managed SFTP makes so much sense in this HIPAA context: it gives healthcare organizations a more complete environment of HIPAA-friendly controls around the transfer itself.
What does HIPAA-compliant SFTP actually mean?
SFTP, or SSH File Transfer Protocol, moves files through SSH. The connection is encrypted, and authentication can use passwords or SSH public keys, which makes SFTP well suited to controlled system-to-system exchange.
Those features, however useful, don't make an organization HIPAA compliant on their own. HIPAA also reaches into how ePHI is accessed, stored, monitored, retained, and handled by third parties. The Security Rule includes technical safeguards around access control, audit controls, integrity, authentication, and transmission security, while administrative and physical safeguards sit outside the transfer protocol entirely.
That’s especially relevant with managed cloud SFTP, where the service may also handle storage, access, monitoring, and file processing, supporting the HIPAA compliance process for file transfer and storage. Our 2026 HIPAA compliance checklist for PHI storage and transfer covers the wider responsibilities.
How do secure SFTP transfer and cloud storage work together?
In a managed cloud SFTP service, transfer and storage can stay in the same environment. Files may arrive over SFTP, HTTPS, or an S3 API, then remain in cloud storage until they’re accessed, processed, or moved again.
The protections differ by stage:
- SFTP encrypts transfers over SSH
- HTTPS and S3 API connections use TLS to protect data in transit
- Encryption at rest protects the stored copy
- PGP can encrypt the file itself, independently of the connection or storage platform
These controls do different jobs. Transport encryption doesn’t control who can access stored files, and encryption at rest doesn’t provide an audit trail or replace authentication. Storage also needs suitable availability, durability, and recovery so authorized users and systems can still reach files when needed.
Our SFTP encryption guide explains transport encryption in more detail. For storage, see HIPAA-compliant cloud storage for healthcare ePHI.
How should access and auditability work around healthcare SFTP?
Healthcare SFTP access should be limited to what each user or system actually needs. That's especially important when the same environment serves multiple departments, vendors, customers, or automated processes.
A practical setup should include controls like:
- Separate credentials for each user or system
- Home directories and permissions that limit file access
- SSH keys for automated SFTP connections
- MFA for human access through the web portal
- IP restrictions where connections come from known networks
Access controls should be backed by a clear audit trail. Administrators should be able to review uploads, downloads, deletions, successful and failed logins, and relevant administrative changes without combining records from several systems.
For organizations using centralized security monitoring, near-real-time audit-log streaming can send this activity to supported SIEM and observability platforms for further monitoring and response.
Together, these controls help limit unnecessary access while keeping a reliable record of how healthcare files are being used.
How do BAAs and shared responsibility fit into managed SFTP?
A Business Associate Agreement sets out the provider’s contractual responsibilities when it handles ePHI as a HIPAA business associate. It doesn't replace security controls, risk management, or the healthcare organization’s own compliance responsibilities.
HHS also makes clear that a cloud provider can still be a business associate even when it stores encrypted ePHI without holding the decryption key. Encryption alone therefore doesn't remove the need to assess the provider, the service, and the BAA.
In practice, responsibilities are shared:
Provider responsibilities may include:
- Operating and securing the managed service
- Protecting the infrastructure it controls
- Meeting the commitments made in its agreements and BAA
- Maintaining the security and availability of the service
- Incorporating existing and evolving controls into its feature set to support compliance
Customer responsibilities include:
- Controlling who receives credentials
- Setting appropriate access and permissions
- Removing access when it is no longer needed
- Reviewing logs and suspicious activity
- Configuring automations appropriately
- Managing how ePHI is used outside the MFT environment
Managed SFTP can remove much of the infrastructure burden, but it doesn't transfer the customer’s HIPAA responsibilities to the provider. Risk analysis, workforce policies, incident response, device security, retention decisions, and other administrative or physical safeguards still lie with the healthcare organization.
How can native MFT automation reduce unnecessary ePHI handling?
A large part of the work after an SFTP transfer is still basic file handling. Files may need to be moved, copied, renamed, encrypted, decrypted, deleted, or held until a scheduled step runs, and those operations don't necessarily require a separate script or integration platform.
Native file automations can run from file events or schedules and chain file actions such as:
- Move
- Copy
- Rename
- Delete
- PGP encryption and decryption
- Create file or folder
- Delay
- Email, Slack, and Microsoft Teams notifications
- Webhook requests
Keeping this kind of processing inside the MFT environment can reduce unnecessary file movement and lower the room for human error, making it easier to comply with HIPAA. A separate service won't have to retrieve sensitive data simply to rename it, encrypt it, or place it elsewhere in the same managed storage.
Once the workflow depends on information or logic from another application, the work belongs elsewhere. An API or webhook can hand control to an iPaaS platform, business application, database, or other system when the process needs to validate data, update records, apply billing logic, or run application-specific workflows.
Our secure file transfer automation for regulated workflows guide looks at this model in more depth, while healthcare SFTP automation using secure MFT and iPaaS workflow integration focuses on healthcare file flows specifically.
What should healthcare teams ask when comparing HIPAA-compliant SFTP providers?
Rather than comparing feature lists, test how each service would handle your actual healthcare file flow. Useful questions include:
- What happens to a file after the SFTP session ends? Ask where it's stored, how it's encrypted, and what availability and recovery measures apply.
- Can every external organization or automated system be isolated properly? Check how credentials, directories, permissions, SSH keys, MFA, and network restrictions work in practice.
- Can you reconstruct exactly what happened to a file? Confirm what is logged, how long records remain available, and whether activity can be streamed to your existing security tools.
- How much routine file processing can stay inside the MFT service? Moving, encrypting, decrypting, renaming, or deleting files shouldn't automatically require another platform or custom script.
- How does the service hand work over to other applications? Look for APIs and webhooks when workflows need to continue in an EHR, billing system, database, iPaaS, or other business application.
- Is a BAA available for the service and plan you intend to use? Confirm this before moving ePHI, rather than assuming it comes with every account.
These questions expose much more than whether a provider supports SFTP. They show how well the service can support the file before, during, and after the transfer.
How does SFTP To Go handle a managed healthcare file flow?
With SFTP To Go, a healthcare file can arrive through SFTP, FTPS, or HTTPS and remain in Amazon S3-backed storage within the same managed environment. S3 API access is also available on eligible plans.
From there, access can be restricted to the appropriate credentials, directories, and permissions. Routine file work can be handled with native file automations, while APIs and webhooks can pass the workflow to another application when business logic is required.
The same activity remains traceable through audit records, with audit-log streaming available on eligible plans for organizations that need file and access events in their SIEM or observability platform. BAAs are available on eligible plans for organizations handling PHI and ePHI.
This keeps the file transfer, the file itself, and much of the work immediately around it within one managed service rather than requiring a separate SFTP server, storage platform, and collection of file-handling scripts.
What should healthcare teams take away from HIPAA-compliant SFTP?
HIPAA-compliant SFTP isn't really about finding a special version of the SFTP protocol. It's about using secure SFTP within a managed environment that can support the way ePHI is stored, accessed, processed, monitored, and passed to other systems.
For healthcare teams, that makes the environment around the SFTP connection just as important as the connection itself.
Frequently asked questions
HIPAA-compliant SFTP generally describes an SFTP service being used within an environment that can support the HIPAA requirements applicable to ePHI. SFTP secures file transfer over SSH, while the wider service may provide protected storage, controlled access, audit records, automation, and other capabilities needed around the file.
Is SFTP itself HIPAA compliant?No protocol is independently made HIPAA compliant simply by its technical design. HIPAA is technology-neutral and does not require organizations to use SFTP. SFTP can form part of a HIPAA-compliant file environment because it provides encrypted transfer, provided the organization also addresses the other applicable safeguards and responsibilities.
Can SFTP be used to transfer healthcare ePHI?Yes. SFTP transfers files through an encrypted SSH connection and supports authentication methods such as SSH public keys. Whether the overall workflow complies with HIPAA depends on the broader way ePHI is handled, including access, storage, risk management, auditability, and service-provider responsibilities.
Does SFTP encrypt ePHI while it is stored?No. SFTP protects the transfer session. Protection after the file arrives comes from the storage environment or additional file-level encryption. A managed cloud SFTP service can combine encrypted transfer with encrypted cloud storage so the file remains inside a controlled service after the connection ends.
What is the difference between SFTP and managed SFTP or MFT?SFTP is the protocol used to transfer files securely over SSH. Managed SFTP or MFT provides the service around that protocol, which can include cloud storage, user and directory controls, authentication options, audit logs, availability, file automation, APIs, webhooks, and managed infrastructure.
Does a cloud SFTP provider need a BAA for ePHI?If the provider creates, receives, maintains, or transmits ePHI on behalf of a covered entity or business associate and is therefore acting as a business associate, an appropriate BAA is required. HHS also states that a cloud provider can remain a business associate when the ePHI is encrypted and the provider does not possess the decryption key.
Does a BAA make an SFTP service HIPAA compliant?No. A BAA defines the contractual responsibilities between the parties where a business associate relationship exists. It does not replace encryption, access control, risk management, auditability, or the other safeguards required for the way ePHI is handled.
Can healthcare SFTP file processing be automated inside MFT?Yes. Modern MFT services can automate file-level work such as moving, copying, renaming, deleting, encrypting, decrypting, scheduling, and notifications. Keeping those actions inside the managed file environment can reduce unnecessary file movement and external scripts.
When should an SFTP workflow use an iPaaS or another application?An external system is useful when the workflow moves beyond file handling and needs application-specific data or business logic. MFT can handle secure transfer, storage, and file-level processing first, then use an API or webhook to hand the next stage to an iPaaS, business application, database, or other system.
What should healthcare organizations look for in a HIPAA-compliant SFTP provider?Evaluate more than the SFTP connection. Check the BAA, cloud storage model, encryption at rest, credential separation, permissions, authentication, network restrictions, auditability, availability, file automation, APIs, webhooks, and the way responsibilities are divided between the provider and customer.