Coviant Software recently commissioned a survey of IT leaders in healthcare to learn more about how they transfer sensitive healthcare and other mission-critical files. We wanted to understand things like their use of automation, encryption and other security measures in their data transfers, and the role those processes play in helping them to comply with security and privacy mandates associated with laws like HIPAA and GDPR.
What we found was astonishing, and not in a good way. Fifteen years after the Health Information Technology for Economic and Clinical Health Act (HITECH) and the Affordable Care Act (ACA) imposed digitization requirements for health records, accelerating the evolution of electronic health records (EHR), we were surprised to learn, for example, that only 9% of organizations surveyed have a fully automated and integrated data transfer process for sending and receiving EHRs. What’s more, nearly 25% still rely on manual processes for at least some of their file transfers—despite the fact that 91% acknowledged those manual file transfer processes resulted in errors.
Lack of Data Transfer Automation, Lack of Confidence
Lack of automation means that nearly half of the organizations we surveyed said they struggle with visibility into their file transfer workflows. They lack confidence that the jobs are getting done on time, that files are reaching the appropriate destinations, or that key security provisions like encryption are being followed. In fact, 41% said their current file transfer tools resulted in compliance risks and security vulnerabilities. That’s a big problem when you consider that data breaches affecting the healthcare industry (including misdelivered files) cost an average of $7.42 million according to the Ponemon Institute/IBM 2025 Cost of a Data Breach Report.
We also learned that a lack of file transfer process automation keeps many organizations from freely sharing necessary data with their partners in the healthcare digital supply chain. In fact, only one-in-four healthcare organizations reported that their third-party file exchanges worked seamlessly. That means that if a patient’s medical records need to get to a diagnostics lab, or if their insurance and payment information needs to be sent to a clearinghouse for processing, it requires that someone in an administrative role handles it manually.
Manual Data Transfer is Inefficient and Risky
That is inefficient, disruptive, and extremely risky. It costs time, money, and increases the chance that someone will make a mistake that results in compromised patient privacy. It also means that IT staff are more likely to be asked to intervene in support of their colleagues in administration rather than focus on their primary roles (which often include IT management, healthcare technology management, and cybersecurity).

Healthcare IT leaders know that file transfer automation is necessary. As the healthcare digital supply chain grows more complex; as EHRs become more sophisticated with the advent of artificial intelligence, and as healthcare networks grow larger through mergers and acquisitions, demand for safe, efficient, and secure file transfers will increase. Many tools even lack interoperability with EHR vendors like Epic, Oracle Healthcare/Cerner, and Meditech. Automation is the key to meeting this demand and while 62% of respondents acknowledged that need, they are being forced to make do with manual scripts or tools that fall short.
Key Features of a Good Data Transfer Automation Solution
Fortunately, addressing these challenges and shortfalls is a simple matter of replacing your current file transfer tool or scheme with a fully automated managed file transfer (MFT) solution that has both security features and broad interoperability with the services and applications used by healthcare organizations. That means an MFT solution that includes:
- Automated PGP encryption management and SFTP support
- Unlimited concurrent job scheduling and automation
- Automated process data capture and one-click audit reporting
- Threat intelligence for automated IP risk analysis and blocking
- IP whitelisting and destination authentication
- Secure by design architecture
- Multi-factor authentication (MFA)
- Administration with least-privilege access
- Dry-run workflow testing and affirmation
- Post-quantum computing cryptographic support
If you’d like to read the full report, Healthcare Data Transfer in 2025: The File Transfer Gap and the Race to Close It, just click the link. We’d be happy to give it to you. If you’d like to talk to an MFT expert about how our Diplomat MFT automated file transfer solution can help you meet your organization’s security, productivity, and compliance needs, contact us and let us know. We’d be happy to talk about your file transfer challenges and provide a free demonstration based on your unique needs.
