---
title: "HIPAA Safeguards with OSS® | Firevault"
description: "Protect ePHI with physical safeguards that go beyond the HIPAA Security Rule. Offline Secure Storage® keeps health records disconnected from the internet."
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": "GB"
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/compliance/hipaa#webpage",
      "url": "https://fire-vault.com/compliance/hipaa",
      "name": "HIPAA Safeguards with OSS®",
      "description": "Protect ePHI with physical safeguards that go beyond the HIPAA Security Rule. Offline Secure Storage® keeps health records disconnected from the internet.",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-base-platform.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/compliance/hipaa#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/compliance/hipaa#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Compliance",
          "item": "https://fire-vault.com/compliance"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "HIPAA Safeguards with OSS®",
          "item": "https://fire-vault.com/compliance/hipaa"
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Co-operative Group 6.5M records ](https://www.bbc.co.uk/news/articles/cly7z9zj3l1o)[2026 Harrods Attempted intrusion ](https://www.reuters.com/business/retail-consumer/uk-luxury-retailer-harrods-latest-target-cyber-attack-2025-05-01/)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](https://www.gov.uk/government/news/legal-aid-agency-data-breach)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Co-operative Group 6.5M records ](https://www.bbc.co.uk/news/articles/cly7z9zj3l1o)[2026 Harrods Attempted intrusion ](https://www.reuters.com/business/retail-consumer/uk-luxury-retailer-harrods-latest-target-cyber-attack-2025-05-01/)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](https://www.gov.uk/government/news/legal-aid-agency-data-breach)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

The requirementThe gapsConsequencesThe architectureWhat sits offline

Compliance, HIPAA 

# HIPAA Compliance with Offline Secure Storage 

Protect electronic Protected Health Information (ePHI) by implementing physical safeguards that exceed HIPAA Security Rule requirements.

-   Offline by default
-   Identity locked access
-   Hardware encrypted

Book a mapping call[Framework matrix](/compliance/frameworks)

![Security analyst reviewing an isolated workstation with disconnected cables](/assets/hero-square-analyst-CiP17E_k.jpg)

$10.93M

Average healthcare data breach cost

725

Healthcare breaches reported in 2023

$2.1M

Average HIPAA fine

01 The requirement 

## The HIPAA Security Challenge

Healthcare data breaches continue to rise, with the average cost of a healthcare breach now the highest of any industry. HIPAA demands robust physical, technical, and administrative safeguards.

This is a mapping , not a certification claim. Firevault holds Cyber Essentials Plus. Everything else on this page is stated as alignment: Offline Secure Storage® produces evidence you can point at in your own submission, assessment or audit.

02 What is tested 

## HIPAA Security Rule Requirements

Each line below is something an assessor, regulator or underwriter can ask you to evidence.

Physical safeguards for ePHI

Access controls and audit controls

Transmission security

Data integrity and disposal procedures

03 Consequences 

## Breach Consequences

What happens when the control is missing, and the record cannot be produced.

### Patient Harm

Exposure of sensitive medical records

### OCR Investigation

Mandatory investigation by HHS Office for Civil Rights

### Public Disclosure

Breaches over 500 records publicly listed

### Class Action Risk

Patient lawsuits and settlements

04 The architecture 

## How OSS Supports HIPAA Compliance

Offline Secure Storage provides the strongest physical safeguard for ePHI by removing it entirely from network-accessible systems.

### Physical Safeguards

ePHI stored offline meets the highest standard of physical protection

### Access Controls

Identity-verified access ensures only authorised personnel can reach data

### Encryption

Hardware encryption at rest exceeds HIPAA addressable requirements

### Audit Controls

Complete access logs for every interaction with stored ePHI

05 What sits offline 

## Healthcare Data Protected

The records most often moved into Offline Secure Storage® for this framework.

Patient medical records

Clinical trial data

Insurance and billing information

Mental health records

Genetic and genomic data

Research and pharmaceutical data

### Authoritative Sources

-   [ICO GDPR Guidance (ICO) ](https://ico.org.uk/for-organisations/guide-to-data-protection/)
-   [NCSC Cyber Essentials (NCSC) ](https://www.ncsc.gov.uk/cyberessentials/overview)

![Mark Fermor](/assets/mark-fermor-C-vy1NeN.jpg)

![David Bailey](/assets/david-bailey-CnLw95Ao.jpg)

![Kenny Phipps](/assets/kenny-phipps-DxIqwaIL.jpg)

Online Now 

Concierge 

## Tell us which framework you are being tested against.

We will map Offline Secure Storage® to the outcomes your assessor is checking, and give you the wording and evidence to submit.

Takes about 2 minutes. No account needed.

Find Out

Free 2 mins No sign-up