No tool is HIPAA compliant by itself. Compliance comes from the vendor agreement, the tool's controls and how your team uses it. Here is the checklist, and the point at which a survey tool stops being the right tool.
Free sandbox · No credit card · 21 CFR Part 11 aligned
Checks
10
Passed
7
Gaps
3
Key points
Checklist
| Requirement | Why | Capture |
|---|---|---|
| BAA or equivalent agreement | Required when the vendor handles PHI for a covered entity | Contact us for agreement terms |
| Encryption | Protects data at rest and in transit | AES-256 at rest, TLS in transit |
| Individual accounts and roles | Least-privilege access | Role matrix per study and site |
| Identity separated from answers | Minimum necessary access for researchers | Coordinators see names; researchers see coded IDs |
| Field-level audit trail | Data integrity and inspection readiness | Every change with user, time, old and new value and reason |
| Scheduled questionnaires | Longitudinal follow-up | Visit-based or recurring with windows and reminders |
| Consent records | Documented, versioned consent | eConsent with verified signatures |
| Electronic signatures | Required for many regulated records | Re-authenticated, with meaning statement |
When to move up
A HIPAA-eligible survey tool is a reasonable choice for a one-time questionnaire to patients, such as a satisfaction survey or a cross-sectional study. The limits appear when participants need to come back on a schedule, when their answers must be linked to clinical data entered by staff, when consent must be documented electronically, or when the data will support regulatory decisions.
At that point a clinical research platform is simpler than stitching together a survey tool, a spreadsheet and a consent process. See Google Forms for clinical research and REDCap vs Qualtrics for comparisons of common tools.
Site coordinator
Jane Peterson
DOB: 04-Mar-1978
Subject 01-004
Sees direct identifiersResearcher
Subject 01-004
DOB: withheld
Coded ID only
Sees coded ID onlySame record, two roles. Row-level security enforces the split.
Consent, scheduled questionnaires and coded data in the free sandbox.
Minimum necessary
The simplest way to reduce HIPAA risk is to collect less. Many research questionnaires do not need names, dates of birth or contact details stored with the answers. HIPAA defines two routes to de-identified data: the Safe Harbor method, which removes 18 specified identifiers, and Expert Determination, where a qualified expert concludes the risk of re-identification is very small. A limited data set, which keeps some dates and geographic data, can be shared under a data use agreement.
Longitudinal research usually does need contact details, to send follow-up questionnaires. In that case, keep identity and answers apart: coordinators see who the participant is, researchers analysing the data see a coded ID. That separation is built into Capture, where identifying data is segregated at the database layer. See HIPAA-compliant clinical trial software.
Beyond HIPAA
| Rule | When it applies | What it adds |
|---|---|---|
| Common Rule | Federally funded human subjects research | IRB review and informed consent requirements |
| FDA human subject protection rules | Research supporting FDA-regulated products | Consent and IRB requirements |
| 21 CFR Part 11 | Electronic records in FDA-regulated research | Audit trails, access control, electronic signatures |
| State privacy laws | Depends on the state and data | Additional rules for some health data |
| GDPR | Participants in the EU or EEA | Legal basis, data subject rights, transfer rules |
See HIPAA vs GDPR for how the two main frameworks compare.
Set-up
Tool, agreement and data flows reviewed.
Including any HIPAA authorisation or waiver.
Only what the study needs, separated from answers.
Individual logins with least-privilege access.
How long data is kept and how it is destroyed.
Who is notified, and when, if something goes wrong.
If no identifiable health information is collected or linked, the responses are generally not PHI. IRB review may still be required.
No. Encryption is one safeguard. HIPAA also needs a BAA where applicable, access and audit controls, policies and training.
A BAA covering the services used, appropriate technical safeguards, and your organisation's policies and configuration. No tool is compliant on its own.
If the tool handles PHI on behalf of a covered entity, generally yes. Check with your privacy office.
Identity separated from answers, scheduled follow-ups, consent records and a field-level audit trail; regulated trials also need electronic signatures.
When participants return on a schedule, answers link to clinical data, consent must be electronic, or the data supports regulatory use.
Yes, in the free sandbox.
Keep exploring
Free sandbox with every feature.