Award-winning MFT Software - Diplomat MFT
Award-winning MFT Software - Diplomat MFT

Ohio OARRS SFTP Compliance: Diplomat MFT automates ASAP 5.0 & ARCOS submissions for sftp.ohiopmp.gov

R

Purpose-built for ASAP 5.0 & ARCOS compliance

R

Automates format routing, encryption & audit trails

R

20+ years trusted by healthcare organizations

R

Meets 24-hour, 5-day & monthly deadlines

R

SFTP + PGP encryption for Board & DEA audits

Trusted by Ohio Pharmacies, Wholesalers & Manufacturers for OARRS Compliance

Join organizations across Ohio who depend on Diplomat MFT for automated ASAP 5.0 pharmacy submissions, ARCOS wholesale reporting, and suspicious order tracking.

From FTP to SFTP: How Ohio’s OARRS Infrastructure Change Impacts Your Compliance

Ohio’s prescription monitoring system completed a critical infrastructure transition on September 30, 2025, moving all OARRS submissions from legacy FTP to secure SFTP via sftp.ohiopmp.gov. This change affects over 1,850 retail pharmacies, hospital pharmacies, wholesale distributors, manufacturers, and medical marijuana dispensaries across Ohio. This requires organizations to update not just their connection protocols, but their entire file transfer workflow.

The transition creates two distinct compliance challenges that manual processes struggle to address. Now, organizations must establish and maintain reliable SFTP connections with proper authentication and encryption, and they must manage two completely incompatible reporting formats.. Format confusion between these systems now results in immediate rejections, leaving organizations with shrinking windows to correct and resubmit. Manual OARRS file preparation exposes healthcare organizations to compliance risks that Ohio’s Board of Pharmacy and the DEA will scrutinize.

OARRS Diagram 2025
Risks of custom scripts

20

Years Trusted by Healthcare

Manual ASAP & ARCOS submissions are error-prone, time-consuming, and put your Ohio license at risk.

Format confusion and wrong-endpoint submissions: Mixing ASAP 5.0 pharmacy files with ARCOS wholesale formats for sftp.ohiopmp.gov causes immediate OARRS rejections and compliance gaps

Missed critical compliance deadlines: 24-hour pharmacy reporting, 5-day suspicious orders, and 15-day zero reports require automated tracking; manual processes lead to Board inquiries and DEA enforcement actions.

Insufficient data protection: SFTP secures the transmission channel but not the file itself; prescription data sitting unencrypted on local systems creates HIPAA audit exposure and breach vulnerability.

Missing compliance documentation: Manual submissions lack the comprehensive audit trails, timestamps, and cryptographic proof required during Board of Pharmacy or DEA investigations.

How Diplomat MFT Automates & Secures Ohio OARRS Compliance: ASAP, ARCOS & sftp.ohiopmp.gov

Ohio OARRS Compliance Features - Diplomat MFT
CAPABILITIES
HOW IT ENSURES
OARRS COMPLIANCE
Format-Aware
Automation
Diplomat MFT automatically routes ASAP 5.0 pharmacy files and ARCOS wholesale files to correct endpoints, preventing format confusion and wrong-endpoint submission errors.
Multi-Deadline
Management
Automated scheduling handles 24-hour pharmacy deadlines, 5-day suspicious orders, monthly wholesale reports, and 15-day zero reports with countdown alerts and buffer time.
SFTP + PGP
Encryption
Diplomat MFT connects to sftp.ohiopmp.gov with secure SFTP while applying automatic PGP file encryption, protecting OARRS prescription data both in transit and at rest for complete HIPAA compliance.
Comprehensive
Audit Trails
Every OARRS submission generates tamper-proof audit documentation with timestamps, file hashes, and delivery confirmations—turning multi-day Board of Pharmacy audit reconstructions into one-click reports.
Suspicious Order
Tracking
Built-in workflows track suspicious orders from identification through ARCOS file submission within Ohio's strict 5-day deadline, with escalating alerts to prevent DEA violations.
Zero Report
Management
Diplomat MFT automatically detects inactive months with no wholesale transactions and generates properly-formatted zero reports for submission within the 15-day window, ensuring continuous compliance.

Customer Challenges

Common OARRS Compliance Pain Points

01

Manual File Transfer Processes

Transform manual, time-consuming, and error-prone file transfers that don’t scale with your organization’s growth. Eliminate operational overhead and human errors that put patient data at risk.

02

Format Complexity & Wrong-Endpoint Submissions

Stop ASAP versus ARCOS format confusion that causes rejected submissions. Prevent pharmacy files being sent for wholesale transactions and vice versa. Format-aware automation ensures files reach the correct endpoint every time.

03

Multiple Deadline Chaos

End the chaos of managing 24-hour pharmacy deadlines, 5-day suspicious orders, monthly wholesale reports, and 15-day zero reports. Automated scheduling handles every deadline type with countdown alerts and buffer time.

04

Lack of Encryption Automation

SFTP encrypts the channel but not the file itself. Automated PGP encryption protects OARRS data at rest and in transit, demonstrating HIPAA due diligence without manual security processes.

05

Missing Audit Trails

Generate comprehensive audit trails required for Board of Pharmacy and DEA compliance reporting. Every OARRS submission is logged, tracked, and documented with cryptographic proof—turning multi-day audit reconstructions into one-click reports.

06

No Visibility Into File Delivery

Discover OARRS transmission failures in real-time, not after Board inquiries. Real-time notifications and delivery confirmations eliminate guesswork and provide instant proof of compliance.

Frequently Asked Questions

When did Ohio require SFTP for OARRS submissions, and what changed?

Ohio’s Board of Pharmacy completed the transition to secure SFTP on September 30, 2025, retiring legacy FTP and FTPS protocols. All OARRS submissions now go through sftp.ohiopmp.gov on port 22. This change affects over 1,850 retail pharmacies, hospital pharmacies, wholesale distributors, manufacturers, 3PLs, and medical marijuana dispensaries across Ohio. The transition requires organizations to update authentication methods, implement SSH key management, and modify file transfer workflows. Beyond the protocol change, organizations must now manage heightened compliance stakes where format errors result in immediate rejections, missed deadlines trigger Board of Pharmacy inquiries, and inadequate security creates HIPAA exposure.

What's the difference between ASAP 5.0 and ARCOS formats for OARRS?
ASAP 5.0 and ARCOS are fundamentally incompatible file formats serving different purposes. ASAP 5.0 is a variable-length, pipe-delimited format used for pharmacy dispensing records. Each prescription generates segments (PAT for patient, RX for prescription, DSP for dispenser) separated by pipe characters, with fields in specific order but varying total length. ARCOS is a fixed-length, positional format derived from DEA requirements for wholesale distribution. Every field occupies exact character positions—your DEA number must be in positions 3-11, business name in positions 12-46, date in positions 47-54. ARCOS files require Control Records (type “01”) followed by Transaction Records (type “02”). Submitting ASAP files for wholesale transactions generates immediate OARRS rejection; sending ARCOS for pharmacy dispensing fails validation. Organizations handling both must implement format-aware workflows preventing wrong-endpoint submissions.
Is SFTP alone enough for OARRS compliance and HIPAA protection?

SFTP provides channel encryption but not file encryption, creating a compliance gap. SFTP secures data during transmission between your system and sftp.ohiopmp.gov, but the file itself remains unencrypted before transmission, during preparation, and if stored on the OARRS server. HIPAA’s Security Rule requires appropriate technical safeguards for ePHI. While encryption at rest is an “addressable” standard (not strictly required), it’s widely regarded as best practice for prescription monitoring data and expected by compliance auditors. Most healthcare organizations combine SFTP transport encryption with PGP file encryption for layered security demonstrating due diligence. This approach protects OARRS data throughout its lifecycle: during preparation on local systems, in transit via SFTP, and at rest on both sending and receiving servers. During Board of Pharmacy or DEA audits, organizations can demonstrate comprehensive protection beyond minimum requirements.

What are the OARRS reporting deadlines I need to meet?
Ohio OARRS has multiple deadline types depending on your operation. Pharmacy dispensing (ASAP 5.0): 24 hours from dispensing for controlled substances Schedules II-V, gabapentin, and naltrexone. Wholesale monthly reports (ARCOS): Due by the 15th of the following month for all reportable transactions. Suspicious orders (ARCOS): Must be reported within 5 calendar days of identification—not business days, making weekends and holidays critical. Zero reports (ARCOS): Due within 15 days of month-end when you had no reportable transactions, distinguishing “no activity” from “failed to report.” Medical marijuana: Sales must be reported within 5 minutes via PMP Clearinghouse. Organizations handling multiple report types must track different calendars simultaneously while ensuring format-appropriate submissions.
What happens if I miss an OARRS submission deadline?

Consequences escalate based on report type and frequency. Missing the 24-hour pharmacy reporting deadline triggers Board of Pharmacy inquiries, potential fines starting at several hundred dollars per violation, and possible HIPAA investigations if the Board determines your safeguards were inadequate. Repeated violations lead to increased fines, formal compliance plans, and in severe cases, license suspension. Missing monthly wholesale reports generates Board penalties and may trigger DEA attention. Missing the 5-day suspicious order deadline is most serious—DEA enforcement actions can include significant fines ($10,000+ per violation), criminal liability if diversion occurred, and intensive audits of your entire operation. Missing zero reports still generates Board penalties even though no transactions occurred. The best defense is automated scheduling with countdown alerts, buffer time before deadlines, and escalating notifications ensuring submissions never slip through the cracks.

What is a suspicious order and how do I report it to OARRS?

Under Ohio Admin. Code 4729:6-3-05, suspicious orders show unusual size, frequency, or patterns deviating from normal customer ordering. Indicators include quantities significantly larger than typical orders, unusually frequent orders, unusual ratios of specific controlled substances, or patterns suggesting diversion. When you identify a suspicious order, you have 5 calendar days to report it using modified ARCOS format via SFTP to sftp.ohiopmp.gov. Required fields include Compliance Officer name and contact details, detailed explanation of why the order is suspicious (generic statements like “unusual quantity” will be rejected), whether you shipped the order (Y/N), and if shipped, your justification. Automated workflows track suspicious orders from identification through submission, maintaining countdown timers and escalating alerts to prevent missed deadlines that trigger DEA enforcement.

Do I need to file zero reports if I had no OARRS activity?

Yes, wholesalers must file zero reports within 15 days of month-end when no reportable transactions occurred. Zero reports distinguish “no activity this month” from “failed to report,” preventing Board inquiries about missing submissions. The zero report uses ARCOS format with specific indicators showing intentional inactivity rather than oversight. Exemptions exist for distributors with no reported drugs in inventory or pharmacies permanently ceasing wholesale operations—these require exemption forms filed through the OARRS portal. Organizations often overlook zero reports because intuition suggests “nothing to report means nothing to do.” This thinking leads to Board penalties. Automated zero report management detects inactive months, generates properly-formatted files, and schedules submission before the 15-day deadline, ensuring continuous compliance even during slow periods.

How long does OARRS compliance implementation take?

Implementation timelines vary by organizational complexity. Single-format operations (pharmacy-only using ASAP or wholesale-only using ARCOS) typically implement in 1-2 days: configure SFTP connection to sftp.ohiopmp.gov, set up data source integration with pharmacy management system or ERP, enable PGP encryption, configure scheduling for appropriate deadlines, and test end-to-end workflow. Dual-format operations (pharmacy dispensing plus wholesale sales) require 2-3 days due to format-aware routing complexity. Multi-location operations with complex distribution networks may need 3-5 days. Organizations can maintain manual processes during implementation, switching to automation only after thorough validation confirms reliable operation. Diplomat MFT integrates with pharmacy systems (PioneerRx, QS/1, Liberty, Computer-Rx, PrimeRx, and others) and wholesale ERPs through watch folders, database queries, APIs, or HL7/NCPDP message processing for flexible connectivity.

How much does OARRS automation cost compared to manual processes?
Manual OARRS compliance carries hidden costs that exceed software investment. A single pharmacy manually submitting ASAP files daily spends approximately 15-20 minutes per submission across 365 days—that’s 91-122 hours annually. At $25/hour staff cost, manual pharmacy compliance costs $2,275-3,050 in labor alone, not counting error correction or audit preparation time. Wholesale operations manually preparing ARCOS reports spend 76+ hours annually at $35/hour = $2,660+. Organizations handling both pharmacy and wholesale face combined labor costs exceeding $5,000 annually. Diplomat MFT typically generates positive ROI within 12-24 months for single pharmacies, 6-12 months for wholesalers or chains, and 3-6 months for dual-track operations. The calculation excludes risk reduction value: avoiding Board fines ($500-5,000+), DEA penalties ($10,000+), and HIPAA violation investigations.
How does Diplomat MFT compare to enterprise MFT solutions or building in-house?
Enterprise MFT platforms (MOVEit, GoAnywhere) target Fortune 500 infrastructure with pricing starting at $10,000-50,000+ annually and implementation timelines of months. These solutions excel at complex, global transfer networks but include significant capabilities irrelevant to OARRS compliance. Diplomat MFT focuses specifically on healthcare compliance with days-to-production implementation, healthcare-specific support understanding OARRS requirements, and pricing appropriate for pharmacies and wholesalers. Building custom OARRS automation typically costs $30,000-75,000 in development (200-500 hours) plus ongoing maintenance, with 6-12 months before reaching production readiness. Organizations supporting both ASAP and ARCOS add 200-400 hours due to dual-format complexity. Most organizations reach build-vs-buy break-even within 12-18 months while accepting significantly higher risk during development. The hidden cost is opportunity cost—what else could development resources accomplish if OARRS compliance was handled by purpose-built software?

Understanding the 2025 HIPAA Changes and the Impact on File Transfers

In 2025, important updates to the Health Insurance Portability and Accountability Act (HIPAA) are set to reshape how healthcare organizations handle sensitive data. These changes will address the advancing cybersecurity threats such as the Change Healthcare ransomware attack, strengthen data protection measures and ensure patient privacy in an increasingly digital healthcare environment. For organizations that are constantly transferring personal information and sensitive files, adapting to these updates is paramount to maintain compliance and protect information.

Key HIPAA Updates for 2025

Enhanced Data Encryption Standards: Strict encryption protocols for both data at rest and in transit for all sensitive data and ePHI.

Real-Time Incident Reporting: Organizations will need to report a data breach within 48 hours.

Increased Emphasis on Vendor Management: Organizations must verify that all third-party vendors, including those providing file transfers adhere to the new HIPAA standards.

Broader Scope of Audit Requirements: Healthcare organizations will need to demonstrate robust controls and comprehensive logging of all file transfers.

Increased Penalties: Financial penalties for non-compliance and sanctions for repeat violations.

Download the HIPAA Compliance Guide 2025

Doubts about scripts and security? Get Confident with Diplomat MFT.

Scripts cause compliance issues. Diplomat MFT replaces doubt with automation, security, and clarity. 20+ years breach-free, with DMZ protection, Edge Gateway architecture, and audit-ready workflows – proven to protect your digital supply chain.

SIMPLE

We automate file transfers and are easy to use.

SECURE

Encryption, decryption, and affirmed destination to secure your entire digital supply chain.

HIPAA COMPLIANCE

With multi-factor authentication, full audit trails, network mapping, and more features designed to support your HIPAA compliance program.

Years of experience

Individual transfers per day

Terabytes transferred per day

Concurrent jobs

Choose from 3 Editions

We have three editions of Diplomat MFT to suit varying business requirements and budgets.

BASIC
$1,149/yearly
Diplomat MFT Core Platform
Automate Secure File Transfers
Web based Administration
Basic File Handling
ENTERPRISE

$10,999/yearly

Extensive Protocol Support
Advanced File Handling
Distribution, Replication and Sync
24x7 Critical Incident Response ($15,749/year)
STANDARD

$2,899/yearly

OpenPGP Encryption
Rich Scheduler
File Monitoring
Notifications, Alerts, Reporting & Auditing

WHAT’S NEW IN VERSION 9.4.1?

Key Diplomat MFT 9.4.1 and 9.4 enhancements include:

Features & Benefits of Diplomat MFT 9.4.1

Threat Intelligence: Real-time blocking of malicious IP addresses with automated threat detection to prevent intrusions and advanced persistent threats.

IP Access Rules: Granular control to block high-risk IP addresses, ensuring only trusted users and networks have access.

PGP Enforcement Rules: Automatically removes files that aren't PGP encrypted, preventing exposure of sensitive information and ensuring data protection compliance.

SFTP Connections Report: Complete visibility into file access for compliance audits and security monitoring with full transparency.

Syslog Logging: Centralized monitoring of all system logins to identify suspicious activity across the entire network.

Zoho WorkDrive Transport Type: Easy integration and automated file transfers to Zoho WorkDrive, reducing manual work and errors.

Expanded RegEx: More flexibility in organizing file names and file types, reducing manual sorting and errors.

Connection Map Report: Visual documentation of data flow for compliance (HIPAA, etc.) showing connections between systems made by Diplomat MFT.

Granular Permissions and Custom Roles: Fine-tuned access control for improved security and regulatory compliance with role-based security.

Support for SSO (Single Sign-On) for Administrators: Simplifies administrator login, centralizes user management, and reduces administrative overhead.

If you have questions, please reach out to schedule a discussion and quick demonstration of Diplomat MFT. Or you can take Diplomat MFT for a free 15-day test drive with no obligations.

BOOK YOUR FREE DEMO TODAY!

Choose any available time for a live, personalized session. We will take the time to understand your specific requirements and goals–from simple tasks to enterprise-level workflow management. 

Book a Free MFT Software Demo

Ensuring Data Integrity in the Healthcare Sector

In the healthcare industry, safeguarding Protected Health Information (PHI) is not just a best practice—it’s a legal imperative. The below diagram depicts our software, Diplomat MFT, which is a Secure File Transfer solution, meticulously designed to meet the rigorous demands of HIPAA/HITECH compliance. We recognize the complexities of your data ecosystem, encompassing electronic health records (EHRs), medical imaging systems, patient portals, and diverse endpoints. Diplomat excels at orchestrating secure and compliant file transfers across this intricate environment.

Notice how our architecture emphasizes layered security, a cornerstone of HIPAA compliance. Data originating from various healthcare platforms, including EHR systems, lab information systems (LIS), and picture archiving and communication systems (PACS) depicted here, flows seamlessly through our secure DMZ. Diplomat MFT’s Edge Gateway and SFTP Server, positioned within the DMZ, act as vigilant gatekeepers, ensuring that PHI is handled with the utmost care. Critically, no sensitive credentials or patient data reside within the DMZ itself, significantly mitigating the risk of a HIPAA breach. Furthermore, our design eliminates the need for inbound firewall openings, bolstering your network’s defenses against external threats.

Diplomat’s robust features, including multi-layer security protocols, audit trails, and access controls, ensure that your valuable patient information remains protected throughout its journey, adhering to HIPAA’s stringent requirements for data integrity and confidentiality. Whether you’re exchanging data with hospitals, clinics, research institutions, or business associates, Diplomat provides the confidence and control you need. We empower healthcare providers to streamline operations, maintain regulatory compliance, and safeguard patient trust with an uncompromising approach to secure and HIPAA-compliant file transfer. Choose Diplomat MFT, and experience the peace of mind that comes with best-in-class data protection in the healthcare sector.

Healthcare SFTP Solution Diagram

WHAT OUR CUSTOMERS SAY

G2 is the largest and most trusted software marketplace. More than 90 million people annually—including employees at all Fortune 500 companies—use G2 to make smarter software decisions based on authentic peer reviews.

Scott J.

Senior Application Engineer

Diplomat MFT has been a powerful workhorse for all of our enterprise file exchange for many years. No other enterprise application we use comes with the same level of support we receive from Coviant.

Eric D.

Director of Information Technology

The support is fantastic. I had to contact them on a few occasions – as it turns out, not for issues with Diplomat MFT but issues with one of the FTP partners. Coviant support stuck with me and went above and beyond to troubleshoot and figure out the issue.

Dave L.

Manager of Information & Technology

Diplomat MFT is a solid data transfer product, its easy to set up, and easy to use. I like the way the transaction builder is laid out. It’s so easy to understand what values it wants.

Adah B.

Senior Programmer Analyst

Extremely robust platform for managing our enterprise file transactions. Every upgrade provides us with additional useful tools to streamline our business processes.

Stephen H.

IT BI Analyst SE

I find the sftp file transfers to be the most helpful tool of Diplomat MFT. No need for programming, the interface is customized already and users only need to fill in the boxes.

Jeff M.

IT Software Application Director

The interface and GUI are very straightforward. The options are simple and labeled so anyone can understand how to set up and configure. The ability to test something without actually sending something is also beneficial.