Security Information
While the REDCap environment controls implemented by ITCS keep your research and data safe, we ask that all users take an active role to ensure we continue to maintain our high level of security.
There are four types of sensitive data that may be approved for storage and transmission in REDCap: Family Educational Rights & Privacy Act of 1974 (FERPA), HR/Personnel data, General Data Protection Regulation (GDPR), and Health Insurance Portability and Accountability Act (HIPAA). Before beginning your REDCAP project involving any of these data types, you must obtain approval from the appropriate governing bodies and/or data stewards.
Family Educational Rights & Privacy Act of 1974 FERPA (Level 3)
To protect student confidentiality under FERPA, any person proposing to administer a survey to ECU students, faculty, staff or alumni using REDCap must obtain prior approval from the Survey Review and Oversight Committee (SROC) through ECU’s Office of Institutional Planning, Assessment and Research (IPAR). If the survey requires IRB approval, this submission should occur concurrently with submission to SROC. In addition to approval from the data owner.
Sources:
Family Educational Rights & Privacy Act. Office of the Registrar. (2026, January 4)
Survey review & oversight committee. ECU IPAR. (2024, March 7)
A Survey Request Form is generally not required for:
- Surveys sent to a population that is at or below the departmental level, or a sample size not to exceed 200
-
Workshop or event evaluations, comment cards, or website feedback surveys
-
Surveys that students take for a course requirement or to provide feedback to instructors and their supervisors
Surveys of participants external to the university (e.g. community residents, businesses, community partner organizations)
Source:
Survey review and oversight committee standard operating procedure. ECU Policy. (2024, March 7).
FERPA-Protected Personally Identifiable Information (PII)
- Student name
- Names of parents or family members
- Student or family address
- Personal identifiers (e.g., Social Security Number, student ID number, biometric records)
- Indirect identifiers (e.g., date of birth, place of birth, mother’s maiden name)
- Information that could reasonably identify a student when combined with other data
- Information requested by someone who is reasonably believed to already know the identity of the student
Definition of a Record
Under FERPA, a record is any information maintained in any format, including:
- Handwritten documents
- Printed materials
- Electronic/computer records
- Audio or video recordings
- FilmMicrofilm or microfiche
Sources:
FERPA. FERPA | Protecting Student Privacy. (n.d.).
Legal Authority: 20 U.S.C 1233g
Examples of Protected FERPA Data Include:
- Student grades and transcripts
- Course schedules and enrollment records
- Financial aid information
- Academic standing and disciplinary records
- Student identification numbers
Examples of Survey Questions Collecting FERPA Data:
- Have you been placed on academic probation in the last semester?
- What grade did you receive in Biology 1001?
General Data Protection Regulation (GDPR) (Level 3)
GDPR is a European Union (EU) privacy law that broadly applies to the collection and use of personal information of any persons located in the European Economic Area (EEA), which include EU member states, plus Iceland, Norway, and Liechtenstein. If the survey requires IRB approval, this submission should occur concurrently with submission to SROC. In addition to approval from the data owner.
Source:
What is GDPR?. General Data Protection Regulation (GDPR). (2019, May 8).
The controller shall implement appropriate technical and organization measures to ensure that, by default, only personal data which are necessary for each specific purpose of the processing are processed. This applies to the amount of personal data collected, the extent of their processing, and the period of their storage and their accessibility.
Source:
B. (2020, July 23). Art. 25 GDPR - data protection by design and by default. GDPR.eu.
Key Considerations:
- Legitimate Interest: The use of Personal Information is necessary to pursue the legitimate interest of the university, but with consideration given to protecting the privacy rights and freedoms of person in the EEA.
- Contract: The use of Personal Information is necessary to fulfill a contract between the university and persons in the EEA.
- Consent: Persons in the EEA have consented to the university’s use of their personal information.
Source:
What is GDPR?. General Data Protection Regulation (GDPR). (2019, May 8).
Examples of protected GDPR data include:
- Names, home addresses, phone numbers, and email addresses
- Digital identifiers such as IP addresses, device identifiers, and web tracking cookies collected by ECU
- University-related identifiers, including student IDs (Banner IDs), employment records, and financial aid data associated with individuals residing in the European Economic Area (EEA)
- Biometric data, and political or religious beliefs collected during international studies or research activities.
Examples of survey questions collecting GPDR data:
- What is your Banner ID?
- What is your personal e-mail address?
Health Insurance Portability and Accountability Act (HIPAA) Compliance and PHI (Level 4)
If your REDCap project collects information covered by HIPAA, you are required to complete ECU’s most current HIPAA Security Training and obtain approval from your Department Chair and when conducting research, the Institutional Review Board (IRB). You can access ECU’s HIPAA training through the Cornerstone employee training system using your PirateID.
The HIPAA Security Rule requires covered entities to implement reasonable administrative, physical, and technical safeguards to protect electronic health information (ePHI), which is individually
identifiable health information stored or transmitted electronically. These safeguards must protect ePHI across all electronic devices and systems, including computers, network, disks, CD-ROMS, handheld devices, and other clinical technologies.
Privacy depends upon security measures: no security, no privacy.
Key Security Considerations
- Always consider the security of your data and only export when necessary.
- Export data only when required for reporting or analysis outside of REDCap.
- Limit export privileges to users with a legitimate business or research need.
- Once data is downloaded from REDCap to a device (e.g., a computer, laptop, or mobile device), the user is responsible for that data.
- Devices must comply with ECU standards (e.g., HIPAA requirements.)
Access to detailed information from ECU including the HIPAA Security Rule and Policies are available through SSO login.
At ECU, we are committed to protecting our patients’ privacy and maintaining our organization’s security of information. We continue to comply with the HIPAA rule and maintain the confidentiality, security, and integrity of our patients’ health information. Note: If you have a question about HIPAA or wish to report a privacy concern, please call: 1-252-744-5200 or email ECUPRIVACY@ecu.edu.
HIPAA Identifiers
- Names
- All geographic subdivisions smaller than state, including street address, city, county, precinct, Zip Code, and their equivalent geographic codes, except for the initial three digits of a ZIP Code if, according to the current publicly available data from the Bureau of the Census:
- The geographic unit formed by combining all ZIP Codes with the same three initial digits contains more than 20,000 people.
- The initial three digits of a ZIP Code for all such geographic units containing 20,000 or fewer people are changed to 000.
- All elements (except year) for dates directly related to an individual, including birth date, admission date, discharge date, date of death; and all ages over 89 and all elements of dates (including year) indicative of such age, except that such ages and elements may be aggregated into a single category of age 90 and older.
- Telephone numbers
- Facsimile numbers
- Electronic mail addresses
- Social Security numbers (not allowed in REDCap)
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate/license numbers
- Vehicle identifier and serial numbers, including license plates
- Device Identifiers and serial numbers
- Web Universal Resource Locators (URLs)
- Internet Protocol (IP) address numbers
- Biometric Identifiers, including finger and voiceprints
- Full-face photographic images and any comparable images
- Any other unique identifying number, characteristic, or code that could identify the individual
Source:
Summary of the HIPAA Privacy Rule. HHS.gov. (2026, March 18).
Examples of HIPAA protected data include:
- Patient medical records
- Clinical documentation containing diagnoses, treatments, or procedures
- Protected Health Information (PHI) linking an individual's name, date of birth, medical record number, or other identifiers to health-related information
- Research data containing identifiable health information
Examples of survey questions collecting HIPAA data:
- Have you tested positive for COVID last month?
- What was the data of your cancer diagnosis?
Mark the Identifiers in REDCap:
When you are creating project fields in your data collection instrument, remember the 18 HIPAA Identifiers. If your field label uses identifying information, make sure you choose YES next to Identifier. This will be important when you are ready to export your data. All fields tagged as identifiers will be marked in red.
HR/Personnel (Level 3)
- Name
- Age (not date of birth)
- Date of original employment or appointment
- Terms of any contract by which the employee is employed whether written or oral, past and current, to the extent that the agency has the written contract or a record of the oral contract in its possession
- Current position
- Title
- Current salary
- Date and amount of each increase or decrease in salary at the university
- Date and type of each promotion, demotion, transfer, suspension, separation, or other change in position classification at the university
- General description of the reasons for each promotion at the university
- Date and type of each dismissal, suspension, or demotion for disciplinary reasons. If the disciplinary action was a dismissal, a copy of the written notice of the final decision of the head of the department setting forth the specific acts or omissions that are the basis of the dismissal
- Office or station to which the employee is currently assigned (this includes work-related contact information, such as department address, department telephone and fax numbers, and email address)
Any additional information regarding employees not specifically identified above is considered confidential under state law unless otherwise explicitly authorized by the Human Resources Act. The Human Resources Act requires that university employees who are in or come into possession of such confidential personnel information maintain its confidentiality.
Note: Any employment records relating to an individual who is employed as a result of his/her status as a student are education records. In such a case, the items above would not be public personnel information.
Examples of protected HR/Personnel data include:
- Employee name and age
- Original date of employment
- Current position and job title
- Salary and compensation history
- Performance evaluations and personnel records
Examples of survey questions collecting HR/Personnel data:
- What is your current salary?
- What policy did you violate during your last disciplinary action?
REDCap User Rights Information
Please Note: REDCap is a web-based system. Once data is downloaded from REDCap to a device (computer, laptop, mobile device), the user is responsible for that data. If the downloaded data is protected health information (PHI), the user must be trained and knowledgeable as to which devices are secure and in compliance with ECU’s standards (like HIPAA) for securing PHI.
| User right and access |
Potential to access PHI |
|
Data Entry Rights
Grants user one of these rights to the project's data collection instruments:
- No Access
- Read Only
- View & Edit
- Edit Survey Responses
WARNING: The data entry rights pertain only to a user's ability to view or edit data on the web page. It has NO effect on data exports
|
Yes.
If access to a form with PHI is Read Only or View & Edit, user will be able to view PHI.
|
|
Expiration Date
Automatically terminates a user's project access on a specific date.
|
|
Highest Level Privileges:
| User Right, Access and Notes |
Potential to Access to PHI |
|
Project Design and Setup
Access to add, update or delete any forms within the project. Also allows user to enable and disable project features and modules.
This should be allocated only to trained study members and should be limited to a very few number of users per study.
|
|
|
User Rights
Access to change the rights and privileges of all project users, including themselves.
WARNING: Granting User Rights privileges gives the user the ability to control other users' project access. This user should be very trusted and knowledgeable about the project and REDCap. Giving user rights to team members should be a carefully thought-out decision. The consequences of poor user rights assignments could be damaging to both the security and integrity of your project. For instance, giving record deletion or project design rights to an unqualified person could result in data loss or database integrity issues.
|
Yes.
User can change own user rights and grant access to any module where PHI can be viewed or downloaded to a device.
|
|
Data Access Groups
Access to create and add users to data access groups.
Do not assign yourself to a data access group; you will limit your ability to access all project data and to add other users to data access groups.
For multi-site studies this allows the ability to place barriers between sites' data (i.e. group A cannot see, export, or edit group B's data).
|
|
Privileges for Data Exports (including PDFs and API exports), Reports and Stats:
| User Right, Access and Notes |
Potential to Access to PHI |
|
Data Exports
Grants No Access, De-Identified Only, Remove All Tagged Identifier Fields and Full Data Set Access to export all or selected data fields to Microsoft Excel, SAS, SPSS, R and Stata.
Default Access: De-Identified; De-identified access shifts all dates even if they are not marked as identifiers.
Non-validated text fields and note fields (free text) are also automatically removed from export.
Remove All Tagged Identifier Fields ONLY removes fields marked as identifiers and does NOT automatically remove non-validated text fields or field notes and does NOT date shift. In reports and in the API data exports, any fields that have been tagged as...
WARNING: The De-identified and Remove All Tagged Identifier field options are contingent upon correctly flagging identifiers in each field.
It is advised to mark all PHI fields as identifiers and restrict export access to de-identified.
|
Yes.
PHI can be exported and downloaded to a device
Exporting data is NOT linked to data entry rights. User with full export rights can export ALL data from all data collection instruments.
Please see Data Exports, Reports, and Stats FAQ for additional info.
|
|
Add/Edit Reports
Access to build reports within the project. If user does not have access to a data collection instrument that the report is pulling data from, those fields will not appear in the report.
For complex querying of data, best results are acquired by exporting data to a statistical package.
|
Yes.
Depending on data entry rights, PHI can be viewed.
|
|
Stats and Charts
Access to view simple statistics on each field in the project in real time. If user does not have access to a data collection instrument, that instrument will not be listed on the page.
Outliers can be identified. When clicked, navigates to the record, form and field with the outlier data.
|
Yes.
Depending on data entry rights, PHI can be viewed.
|
Other Privileges:
| User Right, Access and Notes |
Potential to Access PHI |
|
Manage Survey Participants
Access to manage the public survey URLs, participant contact lists, and survey invitation log.
|
Yes.
Email addresses (PHI) may be listed for the participant contact lists and invitation logs. Emails can be downloaded to a device.
|
|
Calendar
Access to track study progress and update calendar events such as mark milestones, enter ad hoc meetings.
In combination with the scheduling module the calendar tool can be used to add, view and update project records which are due for manipulation.
|
Yes.
PHI can be entered and viewed in the Notes field. Data entered can be printed to PDF and downloaded to a device.
|
|
Data Import Tool
Access to download and modify import templates for uploading data directly into the project bypassing data entry forms.
WARNING: This gives the user the capability to overwrite existing data. Blank cells in the data import spreadsheet do no overwrite fields with data.
|
|
|
Data Comparison Tool
Access to see two selected records side by side for comparison.
Extremely helpful when using double data entry.
|
Yes.
PHI can be viewed. Data can be printed and downloaded to a device. ALL data discrepancies for all fields in project are displayed and can be downloaded to user with access to this module - NOT linked to Data Entry Rights or Data Export Tool Rights.
|
|
Logging
Grants user access to view log of all occurrences of data exports, design changes, record creation, updating & deletion, user creation, record locking, and page views. This is the audit trail of the project.
Useful for audit capability
|
Yes.
ALL data entered, modified and changed is listed in module, can be viewed and downloaded to a device.
|
|
File Repository
Access to upload, view, and retrieve project files and documents (ex: protocols, instructions, announcements). In addition, it stores all data and syntax files when data is exported using the Data Export Tool.
WARNING: While users with restricted data export rights will not be able to access saved identified exports, they will be able to view any other sensitive information stored in the file repository such as photos or scanned documents. Limit this privilege to those who should have access to PHI.
|
Yes.
Depending on Data Export Tool rights, PHI can be downloaded to a device.
|
|
Data Quality
Access to find data discrepancies or errors in project data by allowing user to create & edit rules; and execute data quality rules. If user does not have access to a data collection instrument that the query is referencing, access will be denied for query results.
|
Yes.
Depending on Data Entry Rights, PHI can be viewed.
|
|
API
Access to the API interface that allows external application to connect to REDCap remotely, and is used for programmatically retrieving or modifying data or settings within REDCap, such as performing automated data imports/exports from a specified project.
Reminder: While REDCap itself has many security layers to ensure the highest level of security and data integrity, it is your responsibility to ensure that you are using the most secure methods and best practices when using the REDCap API. This is especially important if you are moving sensitive data in to or out of REDCap.
|
Yes.
Depending on the Data Import/Export rights the user will be able to view PHI being imported or exported.
|