Compliance, HIPAA

HIPAA Compliance with Offline Secure Storage

Protect electronic Protected Health Information (ePHI) by implementing physical safeguards that exceed HIPAA Security Rule requirements.

  • Offline by default
  • Identity locked access
  • Hardware encrypted
Framework matrix
Security analyst reviewing an isolated workstation with disconnected cables

$10.93M

Average healthcare data breach cost

725

Healthcare breaches reported in 2023

$2.1M

Average HIPAA fine

01The requirement

The HIPAA Security Challenge

Healthcare data breaches continue to rise, with the average cost of a healthcare breach now the highest of any industry. HIPAA demands robust physical, technical, and administrative safeguards.

This is a mapping, not a certification claim. Firevault holds Cyber Essentials Plus. Everything else on this page is stated as alignment: Offline Secure Storage® produces evidence you can point at in your own submission, assessment or audit.

02What is tested

HIPAA Security Rule Requirements

Each line below is something an assessor, regulator or underwriter can ask you to evidence.

Physical safeguards for ePHI

Access controls and audit controls

Transmission security

Data integrity and disposal procedures

03Consequences

Breach Consequences

What happens when the control is missing, and the record cannot be produced.

Patient Harm

Exposure of sensitive medical records

OCR Investigation

Mandatory investigation by HHS Office for Civil Rights

Public Disclosure

Breaches over 500 records publicly listed

Class Action Risk

Patient lawsuits and settlements

04The architecture

How OSS Supports HIPAA Compliance

Offline Secure Storage provides the strongest physical safeguard for ePHI by removing it entirely from network-accessible systems.

Physical Safeguards

ePHI stored offline meets the highest standard of physical protection

Access Controls

Identity-verified access ensures only authorised personnel can reach data

Encryption

Hardware encryption at rest exceeds HIPAA addressable requirements

Audit Controls

Complete access logs for every interaction with stored ePHI

05What sits offline

Healthcare Data Protected

The records most often moved into Offline Secure Storage® for this framework.

Patient medical records

Clinical trial data

Insurance and billing information

Mental health records

Genetic and genomic data

Research and pharmaceutical data

Mark Fermor
David Bailey
Kenny Phipps
Online Now
Concierge

Tell us which framework you are being tested against.

We will map Offline Secure Storage® to the outcomes your assessor is checking, and give you the wording and evidence to submit.

Takes about 2 minutes. No account needed.

Free2 minsNo sign-up