---
title: "Inside the Vault: How data flows in TrueVault"
description: TrueVault handles sensitive data on a daily basis. This post explains how data flows through TrueVault using a series of diagrams. In this post, we explain how users are authenticated and authorized using TrueVault, as well as how data is stored in Vault, our flagship product.
image: https://safe.truevault.com/hubfs/Hubspot_Authentication.png
---

<https://safe.truevault.com/>

- [CCPA](https://safe.truevault.com/learn/ccpa/what-is-the-ccpa)
- [GDPR Compliance](https://safe.truevault.com/gdpr-guide)
- [HIPAA](https://safe.truevault.com/learn/hipaa)
- [HIPAA Compliance](https://safe.truevault.com/blog/hipaa-compliance-checklist-download.html)
- [Personally Identifiable Information](https://safe.truevault.com/blog/what-is-pii)
- [PHI](https://safe.truevault.com/protected-health-information)

- [Resources](https://safe.truevault.com/learn/)
- Login
  
  [TrueVault Safe Log in to TrueVault Safe](https://console.truevault.com) [TrueVault Polaris Log in to TrueVault Polaris](https://polaris.truevault.com)

- [Resources](https://safe.truevault.com/learn/)
- Login

- Login
- [TrueVault Safe Log in to TrueVault Safe](https://console.truevault.com)
- [TrueVault Polaris Log in to TrueVault Polaris](https://polaris.truevault.com)

[Blog](https://safe.truevault.com/blog)

- [Home](https://www.truevault.com/index.html)
- [Blog](https://safe.truevault.com/blog)

![<span id="hs_cos_wrapper_name" class="hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_text" style="" data-hs-cos-general-type="meta_field" data-hs-cos-type="text" >Inside the Vault: How data flows in TrueVault</span>](https://safe.truevault.com/hubfs/Hubspot_Authentication.png)

# Inside the Vault: How data flows in TrueVault

By Sara Kassabian/ Published on November 20, 2018

Virtually any business that works in the healthcare space will be accessing and managing health information. If [personally identifiable information](https://blog.truevault.com/what-is-pii) (PII) is linked with medical information, that data is considered [protected health information](https://blog.truevault.com/what-is-phi) (PHI), a special class of data that must be secured according to HIPAA standards. But building a HIPPA-compliant application requires expert knowledge in engineering for security as well as the law itself. There are few small businesses that have the financial and staffing capacity to build their own HIPAA-compliant solution from scratch, which is where TrueVault comes in.

TrueVault offers a HIPPA-compliant solution that integrates seamlessly into the architecture of your application. After reading our data flow series, you should have a solid understanding of how data flows between Vault, our flagship product, and your application, using TrueVault technology. *This blog is part 1 of 2 in our data flow series.*

## How It Works: Authentication and Authorization

 

![Authentication-5](https://safe.truevault.com/hs-fs/hubfs/Authentication-5.png?width=1332&name=Authentication-5.png) 

A core component to cybersecurity is access control. TrueVault helps your business manage which users can access sensitive data through a highly secure authentication and authorization process.

Every user on the platform must be authenticated before they can access data. Let’s assume User A opens the login page of your application’s browser to access their account. When User A submits their username and password, this information is sent to the back-end of TrueVault, where it is authenticated. The user experience is never interrupted during this process.

Once the login details reach Vault, Vault authenticates User A using the login details, and retrieves the appropriate access token. User A’s permissions are encoded in this access token. The access token is sent to the login page. User A is then granted access to the application according to the permissions articulated in the access token. This process is depicted above.

## Storing Information in Vault

![Store Information-4](https://safe.truevault.com/hs-fs/hubfs/Store%20Information-4.png?width=1978&name=Store%20Information-4.png)

Since we specialize in HIPAA compliance, many of our customers are digital health enterprises. Oftentimes, these health enterprises achieve HIPAA compliance through [data de-identification](https://blog.truevault.com/how-does-data-de-identification-work). This is achieved by separating the PII from the medical information, with the PII stored in Vault, and the medical information stored in the enterprise’s application back-end, which is itself stored in the hosting solution (e.g., Amazon Web Services, Azure etc.).  A hypothetical example of how PHI is securely stored is explained below.

Bruce Wayne, or his doctor enters: first name, last name, birthday, depression, and Lexapro (Wayne’s medication) into the browser. Next, the PII and medical information is decoupled. PII (name, birthdate) is sent to Vault and the medical information (depression, Lexapro) is sent to their application back-end. The PII remains stored in Vault, but a de-identified User ID is sent back to the browser. The application reads the User ID. Finally, the non-PII medical information and de-identified User ID is stored in the application.

This method is used time and again because it allows a digital health enterprise to circumvent HIPAA by de-identifying sensitive data and enhancing security using Vault. By decoupling PII from medical information, and then storing de-identifying the data is de-risked and HIPAA protocols no longer apply.

*In part 2 of our blog post, we introduce two other functions of Vault and how TrueVault’s 10 Layers of Security guarantees compliance and enhanced security.*

 

### Latest Posts

## [Should Utah's Privacy Law Be on Your Radar?](https://safe.truevault.com/blog/utah-privacy-law-does-it-apply)

 Phillip Walters  / November 17, 2022

## [Connecticut’s Privacy Law: Does It Apply to Your Business?](https://safe.truevault.com/blog/connecticut-privacy-law-does-it-apply)

 Phillip Walters  / November 10, 2022

## [Global Privacy Control: A New Requirement for Compliance](https://safe.truevault.com/blog/global-privacy-control)

 Phillip Walters  / November 7, 2022

## [A Cookie Banner Isn't Enough for CCPA Compliance](https://safe.truevault.com/blog/a-cookie-banner-isnt-enough)

 Phillip Walters  / October 27, 2022

## [Why CCPA Compliance Matters to HR](https://safe.truevault.com/blog/why-ccpa-matters-to-hr)

 Phillip Walters  / October 21, 2022

### Mailing List

### Company

- [Blog](https://safe.truevault.com/blog)
- [Contact Us](https://safe.truevault.com/contact-us-2019)
- [Careers](https://truevault.workable.com)
- [HIPAA Compliance Checklist](https://safe.truevault.com/blog/hipaa-compliance-checklist-download.html)
- [PDF: Developers Guide to HIPAA compliance](https://my.leadpages.net/leadbox/14472b173f72a2%3A131fd12f8b46dc/5760820306771968/)

### Developers

- [Patterns](https://safe.truevault.com/patterns)
- [Documentation](https://docs.truevault.com/)
- [Quick Start Guide](https://safe.truevault.com/quick-start-guide)
- [Secure Infrastructure](https://safe.truevault.com/secure-infrastructure)
- [API Overview](https://safe.truevault.com/api-overview)

### Latest Posts

### Contact Us

201 Mission Street, 12th Floor  
 San Francisco, CA 94105  
 Email: [hello@truevault.com](mailto:hello@truevault.com)

2024 © All Rights Reserved.  [Privacy Policy](https://privacy.truevault.com/privacy-policy)  |  [Terms of Use](https://www.truevault.com/legal/truevault-terms-of-use)  |  [Supplemental Terms](https://www.truevault.com/legal/truevault-supplemental-terms-of-use)<https://www.truevault.com/legal/truevault-terms-of-use> | [California Privacy Notice](https://privacy.truevault.com/privacy-policy#california-privacy-notice)