Two years ago, we described the future of managed file transfer (MFT) from our position as one of the leading players in the market. That post, which you can read here, was influenced heavily by a spate of cyberattacks exploiting vulnerabilities in MFT products like GoAnywhere, MOVEit, Aspera, Titan, and ShareFile. Attacks on MFT platforms have continued since that time targeting newly discovered vulnerabilities in some of those same products and with new campaigns exploiting weaknesses in products from vendors like CrushFTP, Cleo, and others.
Why Managed File Transfer Matters in 2025
Because of that dark MFT cloud, we predicted that organizations in high-risk industries like healthcare and financial services would step back to re-examine their choice of MFT and, when necessary, make change to security policies, processes, and even their file transfer products. We know that has happened because we have talked to many organizations that have expressed their concerns following a breach of trust with their incumbent. In some cases, we were chosen to displace a legacy MFT solution or modernize where an unsecure “homebrew” solution was in use. In others, a different vendor prevailed, but smart enterprises took steps to do something to reduce their risk, and that’s a positive outcome.
Managed file transfer is not unusual in suffering these attacks, of course. There’s not an industry in high tech that hasn’t been hit by cybercriminals. At the time, we said that “software is made and installed by humans, and humans are known to be imperfect. Managed file transfer was merely the latest to be targeted.” That has not changed. If we all apply the hard lessons learned through adversity to make improvements, then there can’t help but be a benefit. Organizations that don’t invest in improvement are doomed anyway. Then, as now, we believe the future of MFT is bright.
Security Standards, Regulations, MFA, Encryption, and More
One thing we didn’t see transpiring, but that is consistent with our view, is that changes to the regulatory environment would be made. Because not every organization chooses to invest in the tools and processes necessary to establish a sufficient minimum security threshold, those standards have to be set by authorities having jurisdiction, and, as such, big changes are coming to tighten the security standards mandated for the healthcare industry. An update to the Health Insurance Portability and Accountability Act (HIPAA) is in process, with the Department of Health and Human Services reviewing comments on proposed changes to HIPAA.
Hospitals and other healthcare organizations have been beleaguered by a constant fusillade of attacks by cybercriminals, human error, and technical shortcomings that have resulted in data breaches, including the largest healthcare data breach on record. In February 2023 health insurance giant Change Healthcare was hit by a ransomware attack that TechCruch reports affected 190 million people. Key to the attack was a lack of multi-factor authentication (MFA) on a Citrix server used in the management of sensitive records.
Managed File Transfer and Keeping Pace with HIPAA
The use of MFA is featured prominently in the likely changes coming for HIPAA. We discussed those changes in more detail earlier this year. Here’s a brief list of some of the changes to be mandated by HIPAA security rules that healthcare organizations should expect:
-
Multi-factor authentication
-
Encryption of protected health information (PHI) at rest and in motion
-
Use of technical controls for configuring relevant IT systems in a consistent manner
-
Maintenance of written risk monitoring and incident response policies and procedures
-
Configuration management controls (i.e., anti-malware protection, software updates, port disablement, etc.) in accordance with risk analysis
-
Twice-yearly vulnerability scans and annual PEN tests
-
Ongoing digital asset inventory and network connection mapping
-
Support for NIST post-quantum encryption standards
If anything, the changes likely to be mandated by the coming HIPAA update will accelerate the arrival of the future of managed file transfer we envisioned in 2023. As we said then, “The future of managed file transfer is bright because it is a trusted and mature technology, and with continuing emphasis on data privacy and security, MFT only makes sense. Products like Diplomat MFT that are reliable, easy to use, and have what it takes to handle the load for the largest of enterprises are a natural fit for keeping files safe.”
In fact, our optimism is such that we recently updated Diplomat MFT with features specifically designed to address some of the coming HIPAA changes insofar as it made sense for a managed file transfer solution. For example, users can quickly generate a map of all digital trading partners connected through Diplomat MFT, and there are new administrative controls that are consistent with likely HIPAA mandates. These are in addition to the secure-by-design features we’ve always supported, like:
-
Automated PGP encryption management
-
Support for elliptical curve cryptography and current NIST post-quantum cryptography standards
-
SFTP support for transport security
-
Full process documentation and retention for audit reporting
-
Multi-factor authentication and role based administration;
-
Automatic job status alerts over chosen channels like email, Slack, and Teams.
The Future of Managed File Transfer is Now
Managed file transfer software is a proven, mature technology that continues to prove its value as the business world becomes more interconnected. But proven and mature does not mean static, which is why we continue to listen to our customers, follow security trends, and make the investments necessary to keep Diplomat MFT state-of-the-art. But don’t just take our word for it. See for yourself and Try Diplomat Managed File Transfer for free. You can also learn more about Managed File Transfer and how it works by reading What is Managed File Transfer? An Expert MFT Guide for more information. Or schedule a demo so we can show you how a managed file transfer solution can save you time and money while increasing security. It’s never too late to join the MFT trend, but we think you’d rather do it to help prevent a breach rather than because you suffered one.
