“I have everything protected when I can't be on site.”
How an award-winning care business uses Offline Secure Storage® for storage and backups while retaining control of its data, its users and its existing IT relationship.
- 1+ year with Firevault
- Multi-site organisation
- Highly regulated sector
- Existing IT provider retained

- Sector
- CareSectorHeavily regulated industry
- Environment
- Multi-siteEnvironmentResponsibility beyond one building
- Relationship
- 1+ yearRelationshipStorage and backup, plus after-care
- Existing IT provider
- RetainedExisting IT providerFirevault worked alongside it
“I have multiple sites for my care business.”
Running a multi-site care organisation means responsibility for important information reaches well past a single site.
Protecting information supports the people delivering care every day.
Protection when leadership cannot be on site
The organisation wanted greater confidence that important business data and backups were protected when senior leadership could not be physically present, while operating in a heavily regulated industry where data security is a priority.
No new gap between suppliers
The organisation already had an IT provider. Any new approach needed to work alongside the existing environment rather than create another gap between suppliers.
“Something which is a priority for me as we are in a heavily regulated industry.”
A care organisation holds some of the most sensitive information there is, and the law sets out how it must be kept. This is the general position for registered providers in the United Kingdom, not a description of this customer's records.
Care and health records
Care plans, risk assessments, daily notes, medication administration records and body maps. Health information is special category data under UK GDPR, so it carries a higher standard of protection.
Resident and family information
Next of kin and emergency contacts, funding and financial assessments, capacity and best-interest decisions, and correspondence with families and advocates.
Safeguarding and incident records
Safeguarding referrals, accident and incident reports, complaints, and notifications made to the regulator and to the local authority.
Staff and employment records
Recruitment files, DBS checks and right-to-work evidence, training and supervision records, rotas, payroll and occupational health information.
Contracts and commissioning data
Local authority and NHS contracts, invoices, service user placements and the reporting that commissioners and auditors expect to be produced on request.
Operational evidence
Policies, audits, maintenance and fire records, CCTV where used, and the governance trail that demonstrates the service is safe and well led.
The legal responsibilities
UK GDPR and the Data Protection Act 2018
Personal data must be processed lawfully and kept secure using appropriate technical and organisational measures. Health data is special category data and needs an additional lawful condition. A personal data breach likely to risk people's rights must be reported to the ICO within 72 hours.
ICO guide to UK GDPRGood governance: Regulation 17
Registered providers must maintain accurate, complete and contemporaneous records for every person using the service and for staff, and must keep them securely. Records must be available to the regulator on request.
Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, Regulation 17Records management and retention
Adult social care records, including care plans, carry a minimum retention period of eight years, counted from the point the record stops being operational. Information cannot simply be deleted when a placement ends, so it has to be kept safely for years.
NHS England, Records Management Code of Practice, retention scheduleAvailability during disruption
Care continues during an outage or a cyber attack. Providers are expected to plan for business continuity so that care records remain available to the people delivering care, and to notify the regulator of events that affect the service.
CQC guidance for adult social care providersFirevault does not provide legal advice. Every provider should confirm its own obligations with its data protection officer or legal adviser.
“The support received is professional, knowledgeable, and proactive.”
The full statement provided by the organisation's chief executive.
Firevault worked with the organisation and its existing IT provider, adapting to the way the business operates.
I have been working with Firevault for a year or so now and the support received is professional, knowledgeable, and proactive.
I have multiple sites for my care business and using Firevault for storage and backups helps reassure me that I have everything protected when I can't be on site.
The Vault set up was easy enough with a smooth transition from my previous data storage. I have regular backups to ensure that no data is exposed to cybercrime.
The team at Firevault reassured me and evidenced that data is secure, something which is a priority for me as we are in a heavily regulated industry.
The team at Firevault worked well with our existing IT provider to ensure that there were no gaps that we hadn't thought about and worked alongside me and my team to ensure that access was granted to the right people.
I had full autonomy over the way the Vault was managed. They facilitated the requests I had and adapted to what our business needed.
The care industry changes regularly and we are proud that we can keep up with the changes, especially when it comes to data security.
I am thoroughly happy with the service we received and continue to receive with their after-care.
“The Vault set up was easy enough with a smooth transition.”
Six outcomes the customer describes in their own account of the engagement.
Storage and backup
The organisation uses Firevault as part of the way it protects important data and maintains regular backups.
A smooth transition
The customer describes moving from its previous data-storage approach as a smooth transition.
Existing IT provider retained
Firevault worked alongside the existing IT provider, helping both parties identify potential gaps rather than competing for ownership of the environment.
Access around the organisation
Access was configured around the people who needed it and the way the organisation operates.
Customer autonomy
The organisation retained control over how its Vault was managed.
Ongoing support
The relationship did not end after deployment. After more than a year, the customer highlighted Firevault's professional, knowledgeable and proactive support and after-care.
“I had full autonomy over the way the Vault was managed.”
Each line below is the customer's own wording, and each one stands next to a claim Firevault makes elsewhere on this site.
“The support received is professional, knowledgeable, and proactive.”
“The Vault set up was easy enough with a smooth transition from my previous data storage.”
“The team at Firevault worked well with our existing IT provider.”
“Access was granted to the right people.”
“I had full autonomy over the way the Vault was managed.”
“They adapted to what our business needed.”
“I am thoroughly happy with the service we received and continue to receive with their after-care.”
“I am thoroughly happy with the service we received and continue to receive with their after-care.”
Offline Secure Storage® is designed for selected data that does not need to remain permanently reachable.
Published with the customer's approval. The organisation is not named at its own request.