Secure Data Transfer

Secure data transfer (SUFEX)

SUFEX is a secure file transfer service for the Population Health Research Network (PHRN) and its stakeholders.  SUFEX is one of the options that data custodians can use to send files to the PHRN data linkage units and researchers. SUFEX uses a secure online application that allows users to send and receive files from anywhere at anytime. It provides users with a secure file exchange service and is not a file storage solution.

Security

SUFEX uses the Accellion Managed File Transfer application which provides various security features:

  • files are encrypted using AES 128-bit encryption or 256-bit encryption;
  • files are encrypted in transit and at rest;
  • secure links generated by a double 128-bit MD5 token;
  • links have a limited lifespan and access to the file is blocked after its expiration;
  • users must identify themselves before they can download a file;
  • recipients download files via an HTTPS/SSL connection;
  • prevents forwarding links by verifying if a user is on the original recipient list of the email for downloading a file; and
  • recipient email address, time of access and IP address are logged for auditing purposes.

As part of the development process, the Centre for Data Linkage commissioned an independent security audit of the service, hosting environment and associated processes.  The audit confirmed that security had been a major consideration throughout the design and development of the SUFEX environment, and that the resulting infrastructure provided a solid basis for deployment to the PHRN and its stakeholders. To read a summary of the report click here.

User managed
SUFEX provides users with a secure, yet easy to use solution. Users can send and receive files, track recipients, delete or withdraw files, and view file reports. The only software needed to access SUFEX is a standard web browser. Using SUFEX requires little, if any, local IT support.

Accountability

SUFEX provides tracking at both the user and administrator level:

  • User level - return receipts to the sender specify which file has been downloaded, by whom and when;
  • Administrator level - reports account for each and every access to a file, which affords a comprehensive audit trail and high visibility. An Administrator cannot view the files transmitted by the application.

Features of SUFEX

SUFEX features include:

  • access to the service through a simple and intuitive user interface;
  • support for large file transfer;
  • automatic file encryption/decryption;
  • email notifications;
  • download receipts; and
  • individual file reports.

How do I use SUFEX?

SUFEX has been designed to complement current data linkage processes. It is intended to be used by individuals, such as data custodians, who are responsible for sending and receiving data for data linkage research. Registered users will be given personal login credentials. Registered users can then send and request files from other registered, as well as from non-registered users.

For registration details, please contact us at support@sufex.org.au.

Secure file transfer is a simple four step process:

  1. Sender uploads files
  2. Email sent to recipient with link to files
  3. Recipient downloads files
  4. Sender receives notification of download

Cost
Under current funding arrangements, the service is offered free to PHRN partners and their stakeholders.

More information
The service is provided through the PHRN (established by the National Collaborative Research Infrastructure Strategy (NCRIS)) and has been designed, implemented and hosted by the Centre for Data Linkage (CDL), a national node of the network. If you have any questions or need more information, please contact support@sufex.org.au.