---
title: "Inside the Vault: Searching and Fetching Data"
description: TrueVault technology integrates seamlessly with your company's API, allowing users to search and fetch data from our secure Vault. Learn more about how data flows between your application and Vault without interruptions for the user.
image: https://safe.truevault.com/hubfs/Search-1.png
---

<https://safe.truevault.com/>

- [CCPA](https://safe.truevault.com/learn/ccpa/what-is-the-ccpa)
- [GDPR Compliance](https://safe.truevault.com/gdpr-guide)
- [HIPAA](https://safe.truevault.com/learn/hipaa)
- [HIPAA Compliance](https://safe.truevault.com/blog/hipaa-compliance-checklist-download.html)
- [Personally Identifiable Information](https://safe.truevault.com/blog/what-is-pii)
- [PHI](https://safe.truevault.com/protected-health-information)

- [Resources](https://safe.truevault.com/learn/)
- Login
  
  [TrueVault Safe Log in to TrueVault Safe](https://console.truevault.com) [TrueVault Polaris Log in to TrueVault Polaris](https://polaris.truevault.com)

- [Resources](https://safe.truevault.com/learn/)
- Login

- Login
- [TrueVault Safe Log in to TrueVault Safe](https://console.truevault.com)
- [TrueVault Polaris Log in to TrueVault Polaris](https://polaris.truevault.com)

[Blog](https://safe.truevault.com/blog)

- [Home](https://www.truevault.com/index.html)
- [Blog](https://safe.truevault.com/blog)

![<span id="hs_cos_wrapper_name" class="hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_text" style="" data-hs-cos-general-type="meta_field" data-hs-cos-type="text" >Inside the Vault: Searching and Fetching Data</span>](https://safe.truevault.com/hubfs/Search-1.png)

# Inside the Vault: Searching and Fetching Data

By Sara Kassabian/ Published on December 4, 2018

Virtually any business that works in the healthcare space will be accessing and managing health information. If [personally identifiable information (PII)](https://blog.truevault.com/what-is-pii) is linked with medical information, that data is considered [protected health information (PHI)](https://blog.truevault.com/what-is-phi), a special class of data that must be secured according to [HIPAA standards](https://safe.truevault.com/hipaa-compliance). But building a HIPAA-compliant application requires expert knowledge in engineering for security as well as the law itself. There are few small businesses that have the financial and staffing capacity to build their own HIPAA-compliant solution from scratch, which is where TrueVault comes in.

TrueVault offers a HIPAA-compliant solution that integrates seamlessly into the architecture of your application. After reading our data flow series, you should have a solid understanding of how data flows between Vault, our flagship product, and your application, using TrueVault technology. This blog is the second and final part of our data flow series. [Read part 1](https://www.truevault.com/blog/inside-the-vault-how-data-flows-in-truevault) of our data flow series if you haven’t already.

## How It Works: Searching

When developers first start working with Vault, one of the first questions they will ask us is "how do I search for data stored in Vault?". The answer: Vault operates like any other database, but it’s more secure.

 

![Search-1](https://safe.truevault.com/hubfs/Search-1.png)

In practice, this means someone can query Vault, and Vault will return all records that match the query. For example, the end user, Amanda, needs to look-up someone’s record. Amanda starts by searching for "first name: Bruce" against the application, which is integrated with Vault. TrueVault receives the query and returns all records that match the criteria "first name: Bruce" so Amanda can select the specific record for the "Bruce" she was trying to find. The search function can be used to query any type of information that is stored in Vault.

The key takeaway is that to searching Vault isn’t a particularly novel or innovative feature, but its usefulness is rooted in its simplicity. Vault integrates seamlessly into other applications and is easy for your development team to implement and use. Your company can store data in Vault and search the data as you would any other database, except with Vault, your company stays HIPAA compliant.

*Our HIPAA Compliant Checklist will give you the lowdown on how to bring your company to compliance using TrueVault. *

[![Get The HIPAA Compliant Checklist](https://hubspot-no-cache-na2-prod.s3.amazonaws.com/cta/default/4693513/e7f4b6db-52ca-46a0-bd1e-cb24ace89926.png)](https://hubspot-cta-redirect-na2-prod.s3.amazonaws.com/cta/redirect/4693513/e7f4b6db-52ca-46a0-bd1e-cb24ace89926)  

## How it works: Fetching

New TrueVault customers usually ask how they can retrieve a complete record. This question often comes up because TrueVault secures sensitive health data by de-identifying it using tokenization. By separating the identifying information (PII) from the health information (PHI), your company stays HIPAA compliant. 

 

 

![Fetch-1](https://safe.truevault.com/hubfs/Fetch-1.png)

 

TrueVault requires an extra step (in the form of a second API call) when fetching a complete record because information that normally would be stored together (like name and medical information), is instead stored in different locations. Though decoupling the PHI components is what secures the data and keeps your company HIPAA compliant, it does add an extra step to the ‘fetching’ process.

In practice, this means that the application must make two API calls from the browser in order to fetch the complete record queried. For example, when the end user (Charley) queries the browser for the complete record, the browser will route the call to two locations (Vault and the application backend) that house the complete dataset that Charley requires.

One API call will send the TrueVault generated “user\_id” to the Vault and retrieve the requested record stored in Vault. The second API call would also be made using the TrueVault generated “user\_id” except this call would go to your own hosting provider to retrieve the other half of the record that is stored in your application backend  The two returned records will meet in the browser, creating a complete record for Charley. Despite the extra step, Charley will experience no interruptions during the search.

The key takeaway is that data is stored in two different systems that are connected by a TrueVault-generated user\_id. To retrieve both sets of information, TrueVault will make two API calls (one to Vault and your application) instead of a single API call to retrieve all relevant information associated with a user\_id.

*Read [part 1](https://safe.truevault.com/blog/inside-the-vault-how-data-flows-in-truevault) of our data flow series to learn more about how sensitive data moves between Vault and your application. *

### Latest Posts

## [Should Utah's Privacy Law Be on Your Radar?](https://safe.truevault.com/blog/utah-privacy-law-does-it-apply)

 Phillip Walters  / November 17, 2022

## [Connecticut’s Privacy Law: Does It Apply to Your Business?](https://safe.truevault.com/blog/connecticut-privacy-law-does-it-apply)

 Phillip Walters  / November 10, 2022

## [Global Privacy Control: A New Requirement for Compliance](https://safe.truevault.com/blog/global-privacy-control)

 Phillip Walters  / November 7, 2022

## [A Cookie Banner Isn't Enough for CCPA Compliance](https://safe.truevault.com/blog/a-cookie-banner-isnt-enough)

 Phillip Walters  / October 27, 2022

## [Why CCPA Compliance Matters to HR](https://safe.truevault.com/blog/why-ccpa-matters-to-hr)

 Phillip Walters  / October 21, 2022

### Mailing List

### Company

- [Blog](https://safe.truevault.com/blog)
- [Contact Us](https://safe.truevault.com/contact-us-2019)
- [Careers](https://truevault.workable.com)
- [HIPAA Compliance Checklist](https://safe.truevault.com/blog/hipaa-compliance-checklist-download.html)
- [PDF: Developers Guide to HIPAA compliance](https://my.leadpages.net/leadbox/14472b173f72a2%3A131fd12f8b46dc/5760820306771968/)

### Developers

- [Patterns](https://safe.truevault.com/patterns)
- [Documentation](https://docs.truevault.com/)
- [Quick Start Guide](https://safe.truevault.com/quick-start-guide)
- [Secure Infrastructure](https://safe.truevault.com/secure-infrastructure)
- [API Overview](https://safe.truevault.com/api-overview)

### Latest Posts

### Contact Us

201 Mission Street, 12th Floor  
 San Francisco, CA 94105  
 Email: [hello@truevault.com](mailto:hello@truevault.com)

2024 © All Rights Reserved.  [Privacy Policy](https://privacy.truevault.com/privacy-policy)  |  [Terms of Use](https://www.truevault.com/legal/truevault-terms-of-use)  |  [Supplemental Terms](https://www.truevault.com/legal/truevault-supplemental-terms-of-use)<https://www.truevault.com/legal/truevault-terms-of-use> | [California Privacy Notice](https://privacy.truevault.com/privacy-policy#california-privacy-notice)