Award-winning MFT Software - Diplomat MFT
Award-winning MFT Software - Diplomat MFT

Diplomat MFT Upgraded With an Eye on Looming HIPAA Updates

by | May 29, 2025

There are big changes coming for organizations obligated to comply with the Health Insurance Portability and Accountability Act (HIPAA). Many of the updates under consideration for bringing HIPAA in-line with the healthcare industry’s security needs will require hospitals and other healthcare providers to update their compliance strategies as there are new provisions that reflect today’s threat environment. We’ve covered this issue before, but some of the more notable HIPAA updates are likely to mean healthcare organizations must:

  • Create and maintain a written inventory of technology assets
  • Identify and map all network connections in the digital supply chain
  • Implement change management controls and a patch management program
  • Encrypt ePHI at rest and in motion, subject to limited exceptions.
  • Use multi-factor authentication (with limited exceptions).
  • Address vendor risks using National Institute for Standards and Technology (NIST) guidance
  • Plan for migration to post-quantum cryptographic standards

Healthcare Architecture for HIPAA UpdatesA Thousand Pages of HIPAA Updates

There’s much more to it than that (a thousand pages worth!), but I’ve chosen to focus on these because they are the changes that most affect the use of managed file transfer tools (MFT), and where a good, enterprise-grade managed file transfer solution can help support a comprehensive HIPAA compliance program. And knowing that these are among the likely changes to HIPAA, they influenced the development of our latest product upgrade: Diplomat MFT 9.4.

Many of our biggest and oldest customer relationships are healthcare organizations. They rely on Diplomat MFT to move sensitive files containing protected health information (PHI), electronic health records (EHR), and other information covered by HIPAA. That is why we identified ways in which our product could be used to make security and compliance simple, and it is why we added new reporting and testing features that address expected changes to HIPAA. That includes things like:

  • Simplified documentation for HIPAA updates and other regulations with SFTP Audit Report and digital supply chain Connection Map.
  • A “Dry Run” mode to enable testing to validate workflow function and security and to avoid errors.
  • Flexible role assignment and LDAP integration to establish custom permissions and directory integration based on organizational needs.

Stronger Support and More Flexibility

These upgrades offer IT and security administrators a greater level of flexibility when implementing and maintaining access to Diplomat MFT by automatically synchronizing permissions with an organization’s own directory server including support for SAML based single sign-on for admin users. In other words, when you update roles and permissions in your directories, permissions in Diplomat MFT reflect those changes automatically. Diplomat MFT already supports current NIST standards for quantum resistant cryptography. All this is in keeping with our “secure by design” ethic and a firm belief that strong security should be simple.

To be blunt, it is also an acknowledgment that threat actors have targeted vulnerabilities in other managed file transfer products—to devastating effect. We are proud that Diplomat MFT has not been successfully breached in more than twenty years of service, but we refuse to be complacent. We track the attacks that have hit our industry and make sure similar vulnerabilities are not present in our own, challenge assumptions, listen to our customers’ feedback, and invest in improvements that strengthen security and improve the user experience.

A couple other nice upgrades to 9.4 include an ROI calculator that quantifies the time and money your organization saves by automating file transfers with Diplomat MFT vs. other approaches, and one-click integration for file transfer workloads to OneDrive. Of course, when you choose Coviant Software you get all the other features that have helped Diplomat MFT earn industry awards and customer praise. That includes things like:

  • Automated PGP encryption management.
  • Authorized recipient/destination confirmation.
  • A robust scheduler with unlimited concurrent job capacity.
  • Process data capture troubleshooting and audit reporting.
  • Alert notifications your channels of choice (email, text, Slack, Teams, etc.).
  • Integration with the ERP, CRM, and other business applications you already use.
  • Cloud storage support for S3, Azure, Google Cloud, SharePoint, Box, Dropbox, etc.
  • Ethical pricing and the industry’s top-rated customer and technical support.

Built for HIPAA and Beyond

To be clear, while this upgrade to Diplomat MFT was done with HIPAA and healthcare in mind, the improvements translate to the needs of every industry and support compliance with other regulations like GDPR, GLBA, DORA, PIPEDA, and on and on. Diplomat MFT’s security, simplicity, and reliability means users can process heavy job loads with multiple trading partners consistently, helping organizations in any industry—healthcare, financial services, government, retail, biopharma, manufacturing—to maintain compliance with industry standards and security and privacy regulations.

You can download our guide for how an MFT solution supports compliance amid the upcoming HIPAA updates. And if you’re looking for a new MFT solution, or want to replace the one you’ve got, give us a call. We know we can help you.