Ohio OARRS SFTP Compliance: Diplomat MFT automates ASAP 5.0 & ARCOS submissions for sftp.ohiopmp.gov
Purpose-built for ASAP 5.0 & ARCOS compliance
Automates format routing, encryption & audit trails
20+ years trusted by healthcare organizations
Meets 24-hour, 5-day & monthly deadlines
SFTP + PGP encryption for Board & DEA audits
Trusted by Ohio Pharmacies, Wholesalers & Manufacturers for OARRS Compliance
Join organizations across Ohio who depend on Diplomat MFT for automated ASAP 5.0 pharmacy submissions, ARCOS wholesale reporting, and suspicious order tracking.



























From FTP to SFTP: How Ohio’s OARRS Infrastructure Change Impacts Your Compliance
Ohio’s prescription monitoring system completed a critical infrastructure transition on September 30, 2025, moving all OARRS submissions from legacy FTP to secure SFTP via sftp.ohiopmp.gov. This change affects over 1,850 retail pharmacies, hospital pharmacies, wholesale distributors, manufacturers, and medical marijuana dispensaries across Ohio. This requires organizations to update not just their connection protocols, but their entire file transfer workflow.
The transition creates two distinct compliance challenges that manual processes struggle to address. Now, organizations must establish and maintain reliable SFTP connections with proper authentication and encryption, and they must manage two completely incompatible reporting formats.. Format confusion between these systems now results in immediate rejections, leaving organizations with shrinking windows to correct and resubmit. Manual OARRS file preparation exposes healthcare organizations to compliance risks that Ohio’s Board of Pharmacy and the DEA will scrutinize.
Manual ASAP & ARCOS submissions are error-prone, time-consuming, and put your Ohio license at risk.
Format confusion and wrong-endpoint submissions: Mixing ASAP 5.0 pharmacy files with ARCOS wholesale formats for sftp.ohiopmp.gov causes immediate OARRS rejections and compliance gaps
Missed critical compliance deadlines: 24-hour pharmacy reporting, 5-day suspicious orders, and 15-day zero reports require automated tracking; manual processes lead to Board inquiries and DEA enforcement actions.
Insufficient data protection: SFTP secures the transmission channel but not the file itself; prescription data sitting unencrypted on local systems creates HIPAA audit exposure and breach vulnerability.
Missing compliance documentation: Manual submissions lack the comprehensive audit trails, timestamps, and cryptographic proof required during Board of Pharmacy or DEA investigations.
How Diplomat MFT Automates & Secures Ohio OARRS Compliance: ASAP, ARCOS & sftp.ohiopmp.gov
OARRS COMPLIANCE
Automation
Management
Encryption
Audit Trails
Tracking
Management
Customer Challenges
Common OARRS Compliance Pain Points
01
Manual File Transfer Processes
Transform manual, time-consuming, and error-prone file transfers that don’t scale with your organization’s growth. Eliminate operational overhead and human errors that put patient data at risk.
02
Format Complexity & Wrong-Endpoint Submissions
Stop ASAP versus ARCOS format confusion that causes rejected submissions. Prevent pharmacy files being sent for wholesale transactions and vice versa. Format-aware automation ensures files reach the correct endpoint every time.
03
Multiple Deadline Chaos
End the chaos of managing 24-hour pharmacy deadlines, 5-day suspicious orders, monthly wholesale reports, and 15-day zero reports. Automated scheduling handles every deadline type with countdown alerts and buffer time.
04
Lack of Encryption Automation
SFTP encrypts the channel but not the file itself. Automated PGP encryption protects OARRS data at rest and in transit, demonstrating HIPAA due diligence without manual security processes.
05
Missing Audit Trails
Generate comprehensive audit trails required for Board of Pharmacy and DEA compliance reporting. Every OARRS submission is logged, tracked, and documented with cryptographic proof—turning multi-day audit reconstructions into one-click reports.
06
No Visibility Into File Delivery
Discover OARRS transmission failures in real-time, not after Board inquiries. Real-time notifications and delivery confirmations eliminate guesswork and provide instant proof of compliance.
Frequently Asked Questions
When did Ohio require SFTP for OARRS submissions, and what changed?
Ohio’s Board of Pharmacy completed the transition to secure SFTP on September 30, 2025, retiring legacy FTP and FTPS protocols. All OARRS submissions now go through sftp.ohiopmp.gov on port 22. This change affects over 1,850 retail pharmacies, hospital pharmacies, wholesale distributors, manufacturers, 3PLs, and medical marijuana dispensaries across Ohio. The transition requires organizations to update authentication methods, implement SSH key management, and modify file transfer workflows. Beyond the protocol change, organizations must now manage heightened compliance stakes where format errors result in immediate rejections, missed deadlines trigger Board of Pharmacy inquiries, and inadequate security creates HIPAA exposure.
What's the difference between ASAP 5.0 and ARCOS formats for OARRS?
Is SFTP alone enough for OARRS compliance and HIPAA protection?
SFTP provides channel encryption but not file encryption, creating a compliance gap. SFTP secures data during transmission between your system and sftp.ohiopmp.gov, but the file itself remains unencrypted before transmission, during preparation, and if stored on the OARRS server. HIPAA’s Security Rule requires appropriate technical safeguards for ePHI. While encryption at rest is an “addressable” standard (not strictly required), it’s widely regarded as best practice for prescription monitoring data and expected by compliance auditors. Most healthcare organizations combine SFTP transport encryption with PGP file encryption for layered security demonstrating due diligence. This approach protects OARRS data throughout its lifecycle: during preparation on local systems, in transit via SFTP, and at rest on both sending and receiving servers. During Board of Pharmacy or DEA audits, organizations can demonstrate comprehensive protection beyond minimum requirements.
What are the OARRS reporting deadlines I need to meet?
What happens if I miss an OARRS submission deadline?
Consequences escalate based on report type and frequency. Missing the 24-hour pharmacy reporting deadline triggers Board of Pharmacy inquiries, potential fines starting at several hundred dollars per violation, and possible HIPAA investigations if the Board determines your safeguards were inadequate. Repeated violations lead to increased fines, formal compliance plans, and in severe cases, license suspension. Missing monthly wholesale reports generates Board penalties and may trigger DEA attention. Missing the 5-day suspicious order deadline is most serious—DEA enforcement actions can include significant fines ($10,000+ per violation), criminal liability if diversion occurred, and intensive audits of your entire operation. Missing zero reports still generates Board penalties even though no transactions occurred. The best defense is automated scheduling with countdown alerts, buffer time before deadlines, and escalating notifications ensuring submissions never slip through the cracks.
What is a suspicious order and how do I report it to OARRS?
Under Ohio Admin. Code 4729:6-3-05, suspicious orders show unusual size, frequency, or patterns deviating from normal customer ordering. Indicators include quantities significantly larger than typical orders, unusually frequent orders, unusual ratios of specific controlled substances, or patterns suggesting diversion. When you identify a suspicious order, you have 5 calendar days to report it using modified ARCOS format via SFTP to sftp.ohiopmp.gov. Required fields include Compliance Officer name and contact details, detailed explanation of why the order is suspicious (generic statements like “unusual quantity” will be rejected), whether you shipped the order (Y/N), and if shipped, your justification. Automated workflows track suspicious orders from identification through submission, maintaining countdown timers and escalating alerts to prevent missed deadlines that trigger DEA enforcement.
Do I need to file zero reports if I had no OARRS activity?
Yes, wholesalers must file zero reports within 15 days of month-end when no reportable transactions occurred. Zero reports distinguish “no activity this month” from “failed to report,” preventing Board inquiries about missing submissions. The zero report uses ARCOS format with specific indicators showing intentional inactivity rather than oversight. Exemptions exist for distributors with no reported drugs in inventory or pharmacies permanently ceasing wholesale operations—these require exemption forms filed through the OARRS portal. Organizations often overlook zero reports because intuition suggests “nothing to report means nothing to do.” This thinking leads to Board penalties. Automated zero report management detects inactive months, generates properly-formatted files, and schedules submission before the 15-day deadline, ensuring continuous compliance even during slow periods.
How long does OARRS compliance implementation take?
Implementation timelines vary by organizational complexity. Single-format operations (pharmacy-only using ASAP or wholesale-only using ARCOS) typically implement in 1-2 days: configure SFTP connection to sftp.ohiopmp.gov, set up data source integration with pharmacy management system or ERP, enable PGP encryption, configure scheduling for appropriate deadlines, and test end-to-end workflow. Dual-format operations (pharmacy dispensing plus wholesale sales) require 2-3 days due to format-aware routing complexity. Multi-location operations with complex distribution networks may need 3-5 days. Organizations can maintain manual processes during implementation, switching to automation only after thorough validation confirms reliable operation. Diplomat MFT integrates with pharmacy systems (PioneerRx, QS/1, Liberty, Computer-Rx, PrimeRx, and others) and wholesale ERPs through watch folders, database queries, APIs, or HL7/NCPDP message processing for flexible connectivity.
How much does OARRS automation cost compared to manual processes?
How does Diplomat MFT compare to enterprise MFT solutions or building in-house?
Understanding the 2025 HIPAA Changes and the Impact on File Transfers
In 2025, important updates to the Health Insurance Portability and Accountability Act (HIPAA) are set to reshape how healthcare organizations handle sensitive data. These changes will address the advancing cybersecurity threats such as the Change Healthcare ransomware attack, strengthen data protection measures and ensure patient privacy in an increasingly digital healthcare environment. For organizations that are constantly transferring personal information and sensitive files, adapting to these updates is paramount to maintain compliance and protect information.
Key HIPAA Updates for 2025
Enhanced Data Encryption Standards: Strict encryption protocols for both data at rest and in transit for all sensitive data and ePHI.
Real-Time Incident Reporting: Organizations will need to report a data breach within 48 hours.
Increased Emphasis on Vendor Management: Organizations must verify that all third-party vendors, including those providing file transfers adhere to the new HIPAA standards.
Broader Scope of Audit Requirements: Healthcare organizations will need to demonstrate robust controls and comprehensive logging of all file transfers.
Increased Penalties: Financial penalties for non-compliance and sanctions for repeat violations.
Doubts about scripts and security? Get Confident with Diplomat MFT.
Scripts cause compliance issues. Diplomat MFT replaces doubt with automation, security, and clarity. 20+ years breach-free, with DMZ protection, Edge Gateway architecture, and audit-ready workflows – proven to protect your digital supply chain.
SIMPLE
We automate file transfers and are easy to use.
SECURE
Encryption, decryption, and affirmed destination to secure your entire digital supply chain.
HIPAA COMPLIANCE
With multi-factor authentication, full audit trails, network mapping, and more features designed to support your HIPAA compliance program.
Years of experience
Individual transfers per day
Terabytes transferred per day
Concurrent jobs
Choose from 3 Editions
We have three editions of Diplomat MFT to suit varying business requirements and budgets.
BASIC
Diplomat MFT Core Platform
Automate Secure File Transfers
Web based Administration
Basic File Handling
ENTERPRISE
$10,999/yearly
Extensive Protocol Support
Advanced File Handling
Distribution, Replication and Sync
24x7 Critical Incident Response ($15,749/year)
STANDARD
$2,899/yearly
OpenPGP Encryption
Rich Scheduler
File Monitoring
Notifications, Alerts, Reporting & Auditing
WHAT’S NEW IN VERSION 9.4.1?
Key Diplomat MFT 9.4.1 and 9.4 enhancements include:
Threat Intelligence: Real-time blocking of malicious IP addresses with automated threat detection to prevent intrusions and advanced persistent threats.
IP Access Rules: Granular control to block high-risk IP addresses, ensuring only trusted users and networks have access.
PGP Enforcement Rules: Automatically removes files that aren't PGP encrypted, preventing exposure of sensitive information and ensuring data protection compliance.
SFTP Connections Report: Complete visibility into file access for compliance audits and security monitoring with full transparency.
Syslog Logging: Centralized monitoring of all system logins to identify suspicious activity across the entire network.
Zoho WorkDrive Transport Type: Easy integration and automated file transfers to Zoho WorkDrive, reducing manual work and errors.
Expanded RegEx: More flexibility in organizing file names and file types, reducing manual sorting and errors.
Connection Map Report: Visual documentation of data flow for compliance (HIPAA, etc.) showing connections between systems made by Diplomat MFT.
Granular Permissions and Custom Roles: Fine-tuned access control for improved security and regulatory compliance with role-based security.
Support for SSO (Single Sign-On) for Administrators: Simplifies administrator login, centralizes user management, and reduces administrative overhead.
If you have questions, please reach out to schedule a discussion and quick demonstration of Diplomat MFT. Or you can take Diplomat MFT for a free 15-day test drive with no obligations.
Ensuring Data Integrity in the Healthcare Sector
In the healthcare industry, safeguarding Protected Health Information (PHI) is not just a best practice—it’s a legal imperative. The below diagram depicts our software, Diplomat MFT, which is a Secure File Transfer solution, meticulously designed to meet the rigorous demands of HIPAA/HITECH compliance. We recognize the complexities of your data ecosystem, encompassing electronic health records (EHRs), medical imaging systems, patient portals, and diverse endpoints. Diplomat excels at orchestrating secure and compliant file transfers across this intricate environment.
Notice how our architecture emphasizes layered security, a cornerstone of HIPAA compliance. Data originating from various healthcare platforms, including EHR systems, lab information systems (LIS), and picture archiving and communication systems (PACS) depicted here, flows seamlessly through our secure DMZ. Diplomat MFT’s Edge Gateway and SFTP Server, positioned within the DMZ, act as vigilant gatekeepers, ensuring that PHI is handled with the utmost care. Critically, no sensitive credentials or patient data reside within the DMZ itself, significantly mitigating the risk of a HIPAA breach. Furthermore, our design eliminates the need for inbound firewall openings, bolstering your network’s defenses against external threats.
Diplomat’s robust features, including multi-layer security protocols, audit trails, and access controls, ensure that your valuable patient information remains protected throughout its journey, adhering to HIPAA’s stringent requirements for data integrity and confidentiality. Whether you’re exchanging data with hospitals, clinics, research institutions, or business associates, Diplomat provides the confidence and control you need. We empower healthcare providers to streamline operations, maintain regulatory compliance, and safeguard patient trust with an uncompromising approach to secure and HIPAA-compliant file transfer. Choose Diplomat MFT, and experience the peace of mind that comes with best-in-class data protection in the healthcare sector.
WHAT OUR CUSTOMERS SAY
G2 is the largest and most trusted software marketplace. More than 90 million people annually—including employees at all Fortune 500 companies—use G2 to make smarter software decisions based on authentic peer reviews.

Scott J.
Diplomat MFT has been a powerful workhorse for all of our enterprise file exchange for many years. No other enterprise application we use comes with the same level of support we receive from Coviant.

Eric D.
Director of Information Technology
The support is fantastic. I had to contact them on a few occasions – as it turns out, not for issues with Diplomat MFT but issues with one of the FTP partners. Coviant support stuck with me and went above and beyond to troubleshoot and figure out the issue.

Dave L.
Manager of Information & Technology
Diplomat MFT is a solid data transfer product, its easy to set up, and easy to use. I like the way the transaction builder is laid out. It’s so easy to understand what values it wants.

Adah B.
Extremely robust platform for managing our enterprise file transactions. Every upgrade provides us with additional useful tools to streamline our business processes.

Stephen H.
IT BI Analyst SE
I find the sftp file transfers to be the most helpful tool of Diplomat MFT. No need for programming, the interface is customized already and users only need to fill in the boxes.

Jeff M.
The interface and GUI are very straightforward. The options are simple and labeled so anyone can understand how to set up and configure. The ability to test something without actually sending something is also beneficial.





