SUFEX

Secure data transfer (SUFEX)

SUFEX is a secure file transfer service for the Population Health Research Network (PHRN) and its stakeholders.  SUFEX is one of several data transfer methods identified in the PHRN Data Transfer Agreement that Researchers can use to send and receive files from Data Custodians and Data Linkage Units.

SUFEX uses a secure online system that allows users to send and receive files from anywhere at any time. It provides users with a secure file exchange service and is not a file storage solution.  It can be accessed at https:\\sufex.org.au.

Security

SUFEX uses the Accellion Managed File Transfer application which provides various security features:

  • Files are encrypted using AES 128-bit encryption;
  • Files are encrypted in transit and at rest;
  • Secure links generated by a double 128-bit MD5 token;
  • Links have a limited lifespan and access to the file is blocked after its expiration;
  • Users must identify themselves before they can download a file;
  • Recipients download files via an HTTPS/SSL connection;
  • Prevents forwarding links by verifying if a user is on the original recipient list of the email for downloading a file; and
  • Logging of Recipient email address, time of access and IP address makes it easy to audit activity.

As part of the development process, the CDL commissioned an independent security audit of the service; including the configuration, hosting environment and relevant processes. To read a summary of the report click here.

User managed
SUFEX is a powerful, yet easy to use solution. Users can send and receive files, track recipients, and delete or withdraw files. The only software needed to access SUFEX is a standard web browser. Using SUFEX requires minimal local IT support.

Accountability

SUFEX provides tracking at both the user and administrator level:

  • User level - return receipts to the sender specify which file has been downloaded, by whom and when; and
  • Administrator level - reports account for each and every access to a file, which affords a comprehensive audit trail and high visibility. An Administrator cannot view the files transmitted by the application.

Key features of SUFEX

  • Access to the service through a simple and intuitive user interface
  • Support for large file transfer
  • Automatic file encryption/decryption
  • Email notifications
  • Download receipts
  • Individual file reports

How do I use SUFEX?
SUFEX has been designed to complement current data linkage processes and is initially intended to be used by individuals, such as researchers, who are responsible for sending and receiving data for data linkage research. Registered users will be given personal login credentials. Registered users can then send and request files from other registered, as well as from non-registered users.
For registration details, please contact us at support@sufex.org.au.

The secure file transfer is a simple four step process:

1. Sender uploads files
2. Email sent to recipient with link to files
3. Recipient downloads files
4. Sender receives notification of download

Cost
Under current funding arrangements, the service is offered free to PHRN partners and their stakeholders.

More information
The service is provided through the PHRN (established by the National Collaborative Research Infrastructure Strategy (NCRIS)) and has been designed, implemented and hosted by the Centre for Data Linkage (CDL), a national node of the PHRN. If you have any questions or need more information, please contact support@sufex.org.au.