Compliance checklistUpdated September 27, 2026

HIPAA-compliant clinical trial software, checked against Capture

HIPAA’s Security Rule asks for specific safeguards for protected health information: encryption, access limited by role, and a record of who touched what and when. Capture encrypts PHI at rest and in transit, segregates identifiers by role, and logs every change on a field-level audit trail, so you can check the safeguards directly.

  • AES-256 encryption
  • Role-based PHI access
  • Field-level audit trail

Free sandbox · No credit card · 21 CFR Part 11 aligned

Site coordinator

Jane Peterson

DOB: 04-Mar-1978

Subject 01-004

Sees direct identifiers

Researcher

Subject 01-004

DOB: withheld

Coded ID only

Sees coded ID only

Same record, two roles. Row-level security enforces the split.

AES-256

encryption for PHI at rest, TLS/SSL in transit

3

access roles, segregating PHI from coded research data

Field-level

audit trail on every record, not editable from the UI

2

hosting regions to choose from: EU or US

The rule

HIPAA sets safeguards for PHI, not a certificate for software

The HIPAA Security Rule calls for administrative, physical and technical safeguards for protected health information: encryption, access controls, and audit controls that record who touched a record and when. There is no HIPAA certification for software. What you check is whether a system provides those specific safeguards, and whether your own policies use them correctly.

  • PHI encrypted at rest and in transit.
  • Access limited by role, with individual logins.
  • An audit trail on every record, not just a login log.
Data residency
EU

EU (Frankfurt)

Default for EU-sponsored studies

US

US (N. Virginia)

Default for US-sponsored studies

AES-256 at rest TLS/SSL in transit Chosen at study setup

The checklist

Six things to verify against the Security Rule

Walk any vendor, Capture included, through this list.

PHI encrypted at rest

AES-256 encryption for stored data.

PHI encrypted in transit

TLS/SSL on every connection.

Access limited by role

Researcher, site coordinator and admin roles, each seeing only what they need.

Individual logins, not shared accounts

Every action is attributable to one signed-in user.

An audit trail on every record

Who changed it, when, the old and new value, and the reason.

A choice of hosting region

EU (Frankfurt) or US (N. Virginia), picked at study setup.

Access control

PHI segregated from research data by role

A HIPAA review usually asks who can see a participant’s protected health information alongside their study data. Capture answers with roles: site coordinators see identifiers for their own site’s participants, researchers see the same records under a coded ID, and the split is enforced at the database layer.

  • Researcher and site coordinator roles see different fields on the same record.
  • By-site filtering, so one site never sees another site’s participants.
  • How you assign roles still matters as much as the software.
  • SO

    Study owner

    Builds and configures the study

  • PI

    Principal investigator

    Oversees the site, signs off the casebook

  • SI

    Sub-investigator

    Enters and signs clinical data

  • SC

    Study coordinator

    Screens subjects, enters visit data

  • CRA

    Monitor (CRA)

    Verifies data, raises queries

  • DM

    Data manager

    Reviews, freezes and locks data

  • PT

    Participant

    Completes their own questionnaires

The difference

A paper chart vs a HIPAA-aware system

Who can see a participant’s PHI
Anyone with the paper chart or shared drive
Only the roles you grant, split from coded research data
Encryption
Depends on the laptop and file storage
AES-256 at rest, TLS/SSL in transit, by default
Audit trail
A note in a logbook, if any
Field-level, automatic, on every record
Hosting location
Wherever the file server happens to sit
A region you choose at setup

Before you switch

The questions teams ask before they commit

Cost

Encryption, roles and the audit trail are part of every plan, including the free sandbox.

Compliance

HIPAA is shared: Capture provides the safeguards, your own policies and role assignments still matter.

Setup time

No separate infrastructure. Pick a hosting region during study setup.

Migration

Bring an existing study in with the same role-based access control from day one.

Support

Email support, typically under 24 hours, plus documentation for your own review on Enterprise.

See the safeguards on a real study build

Free sandbox with every feature. No credit card, no sales call.

See the safeguards free

FAQ

Questions teams ask before they switch

Something not covered here? Ask us directly.

Is Capture HIPAA compliant?

Capture provides the safeguards the HIPAA Security Rule calls for: encrypted PHI, role-based access, and a field-level audit trail. Whether your overall use is HIPAA compliant also depends on your own policies and how you assign roles.

What counts as PHI in a clinical trial?

Anything that could identify a participant when combined with health data: name, date of birth, or contact details, for example. Capture separates these direct identifiers from the coded clinical record by role.

Does the audit trail cover PHI as well as clinical data?

Yes. The audit trail is field-level and applies to every record, including participant identifiers.

Can I choose where PHI is stored?

Yes. Pick EU (Frankfurt) or US (N. Virginia) hosting when you set up the study.

Is there a HIPAA certification you can show us?

No official HIPAA certification exists for software. What we provide is documentation of the safeguards in place, available on Enterprise, to support your own review.

Can I see the safeguards before committing to a plan?

Yes. The free sandbox includes full role-based access and the audit trail with sample data, no credit card required.

Check the safeguards on your own sandbox study

Free sandbox with every feature. No credit card, no sales call.

See the safeguards free