HIPAA’s Security Rule asks for specific safeguards for protected health information: encryption, access limited by role, and a record of who touched what and when. Capture encrypts PHI at rest and in transit, segregates identifiers by role, and logs every change on a field-level audit trail, so you can check the safeguards directly.
Free sandbox · No credit card · 21 CFR Part 11 aligned
Site coordinator
Jane Peterson
DOB: 04-Mar-1978
Subject 01-004
Sees direct identifiersResearcher
Subject 01-004
DOB: withheld
Coded ID only
Sees coded ID onlySame record, two roles. Row-level security enforces the split.
AES-256
encryption for PHI at rest, TLS/SSL in transit
3
access roles, segregating PHI from coded research data
Field-level
audit trail on every record, not editable from the UI
2
hosting regions to choose from: EU or US
The rule
The HIPAA Security Rule calls for administrative, physical and technical safeguards for protected health information: encryption, access controls, and audit controls that record who touched a record and when. There is no HIPAA certification for software. What you check is whether a system provides those specific safeguards, and whether your own policies use them correctly.
EU (Frankfurt)
Default for EU-sponsored studies
US (N. Virginia)
Default for US-sponsored studies
The checklist
Walk any vendor, Capture included, through this list.
AES-256 encryption for stored data.
TLS/SSL on every connection.
Researcher, site coordinator and admin roles, each seeing only what they need.
Every action is attributable to one signed-in user.
Who changed it, when, the old and new value, and the reason.
EU (Frankfurt) or US (N. Virginia), picked at study setup.
Access control
A HIPAA review usually asks who can see a participant’s protected health information alongside their study data. Capture answers with roles: site coordinators see identifiers for their own site’s participants, researchers see the same records under a coded ID, and the split is enforced at the database layer.
Study owner
Builds and configures the study
Principal investigator
Oversees the site, signs off the casebook
Sub-investigator
Enters and signs clinical data
Study coordinator
Screens subjects, enters visit data
Monitor (CRA)
Verifies data, raises queries
Data manager
Reviews, freezes and locks data
Participant
Completes their own questionnaires
The difference
Before you switch
Encryption, roles and the audit trail are part of every plan, including the free sandbox.
HIPAA is shared: Capture provides the safeguards, your own policies and role assignments still matter.
No separate infrastructure. Pick a hosting region during study setup.
Bring an existing study in with the same role-based access control from day one.
Email support, typically under 24 hours, plus documentation for your own review on Enterprise.
Free sandbox with every feature. No credit card, no sales call.
Capture provides the safeguards the HIPAA Security Rule calls for: encrypted PHI, role-based access, and a field-level audit trail. Whether your overall use is HIPAA compliant also depends on your own policies and how you assign roles.
Anything that could identify a participant when combined with health data: name, date of birth, or contact details, for example. Capture separates these direct identifiers from the coded clinical record by role.
Yes. The audit trail is field-level and applies to every record, including participant identifiers.
Yes. Pick EU (Frankfurt) or US (N. Virginia) hosting when you set up the study.
No official HIPAA certification exists for software. What we provide is documentation of the safeguards in place, available on Enterprise, to support your own review.
Yes. The free sandbox includes full role-based access and the audit trail with sample data, no credit card required.
Keep exploring
GDPR-compliant clinical trial software
The same safeguards, framed for EU personal data.
21 CFR Part 11 compliance checklist
The audit trail and e-signature side of the compliance picture.
ALCOA+ data integrity checklist
How the same controls support data integrity more broadly.
Audit trail software
How field-level logging works on every change.
eConsent software
Where signed consent and identifier controls meet.
Features
Every module PHI and access controls run across.
Free sandbox with every feature. No credit card, no sales call.