Additional REDCAP Resources and FAQs

On this page:

REDCap Use at WSU-affiliated Organizations

Organizations outside WSU may use WSU鈥檚 REDCap system only if they have an affiliation agreement with WSU. Users from affiliated organizations must also have a WSU username and password (W#). These organizations may include hospitals and clinical practice sites subject to HIPAA requirements, particularly regarding the recording, storage, and sharing of Protected Health Information (PHI).

Project Setup and Review

  • Use a REDCap template whenever possible when creating a new project. Templates include predefined WSU User Roles designed to limit access to research data and support HIPAA compliance. If an empty project is created instead, the recommended User Roles should be applied according to the WSU User Rights Table.
  • Before a project is moved to Production, WSU REDCap Administrators will review it to confirm that:
    • Fields that may contain PHI are identified as Identifiers.
    • User rights appropriately limit access to and disclosure of PHI.
    • Project users are included in the applicable IRB materials.

Additional Protections for Clinical/PHI Projects

When a project is approved for Production, WSU REDCap Administrators will:

  • Convert the project's WSU User Roles to the PHI-specific recommended roles.
  • Remove users' ability to change User Rights or Data Access Groups, ensuring access to PHI is controlled by the Project Owner.
  • Remove access to the File Repository to reduce the risk of unintended disclosure of documents containing PHI.
  • Add a Clinical Site Auditor role to support clinical-site oversight and HIPAA compliance.
  • Add a support user for the Project Owner when needed for project-design changes.
  • Add the designated Clinical Site Auditor to the project.
  • Add the clinical site's initials in brackets to the end of the Project Title (e.g., [ABC]). This allows WSU REDCap Administrators to identify, track, and report on projects by clinical site.

In short: Affiliated organizations can use WSU REDCap, but projects involving PHI are subject to additional user-access restrictions, administrator review, clinical-site auditing, and project-identification requirements.

Protecting PHI

What is PHI?

Protected Health Information (PHI) includes information that can identify a person and must be protected under HIPAA. In REDCap, identifiers include:

  • Names, addresses, phone/fax numbers and email addresses
  • Social Security, medical record, health plan, account, license or certificate numbers
  • URLs, IP addresses, vehicle or device identifiers
  • Biometric identifiers and identifying photographs
  • Other unique identifying numbers, codes, or characteristics
  • Dates more specific than the year

Important: Information that does not identify someone by itself can become identifying when combined with other details. Examples include a person's doctor or treatment location, gender, rare condition, workplace, occupation, income, education, family composition, ethnicity, age/birth year, or detailed free-text responses. This is sometimes called the 鈥�19th identifier.鈥�

How REDCap Protects PHI

System-wide protections

REDCap at 糖心原创 provides:

  • Secure access: Users authenticate with their unique University W# and password.
  • Controlled account creation: New REDCap accounts must be activated by REDCap Administration.
  • Secure servers: REDCap operates behind a firewall on 糖心原创 CaTS servers.
  • Regular backups: Data are backed up on-site, with an additional off-site backup.

Project-level protections

Project Owners are responsible for controlling access to PHI within their projects.

  • Grant access only when needed. Add only project team members who require access and set an expiration date when access is no longer needed.
  • Use appropriate User Rights. Restrict who can:
    • Change User Rights
    • View forms containing PHI
    • Export data
    • Export specific types of data or identifiers
  • Use Data Access Groups when appropriate, especially for multi-site studies.
  • Collect the minimum necessary PHI. Only include identifiers required for the study.
  • Limit free-text fields. Notes and other open-ended fields can unintentionally contain PHI.
  • Mark PHI variables as 鈥淚dentifiers.鈥�
  • Use password masking when entering sensitive information where appropriate.

Protecting PHI During Data Export and Sharing

  • Use de-identification options when exporting data whenever possible.
  • Limit data-export privileges to users who need them.
  • Restrict PHI-containing files in the File Repository.
  • Never share exported files or documents containing PHI with people outside the project team unless they are authorized to receive them.
  • Use REDCap Logging to monitor activity, including data exports.

Remember- collect the minimum. Give access only to those who need it. Limit exports. Protect files containing PHI. Monitor project activity.

For additional guidance, see PMID 30017974, DOI

Managing User Rights

User access in REDCap is managed at two levels: REDCap account access and project access.

Who manages access?

  • WSU REDCap Administrators create REDCap user accounts and manage system-wide access.
  • Project Owners control who can access their projects and what each user can do within the project.
  • Project Owners are responsible for appropriate access to project data and are encouraged to designate a backup Project Owner with similar rights.

Having a REDCap account does not automatically give a user access to any project.

Give users only the access they need

Set project-specific rights based on each team member's role. Limiting access helps ensure users can access only the settings, features, and data they need鈥攊ncluding PHI, data exports, and other sensitive functions.

WSU provides recommended roles that can be imported when creating a project from a template. If you created an empty project, you can create these roles manually.

Common recommended roles:

  • Project Owner: Full project management and User Rights responsibilities.
  • Data Entry: Access needed to enter and manage study data.
  • Quality Reviewer: Read-only access for reviewing data and quality.
  • Statistician: Access to appropriate reports, statistics and analysis functions.
  • Site Auditor: Limited, read-only access for auditing; this role is added when needed.

The exact rights for each role should follow the WSU recommended User Rights tables.

Add users to a project

Users can be added during Development or Production.

You can either:

  1. Assign Custom Rights 鈥� search for the user, select their User Rights, and select the forms and functions they need.
  2. Assign a Role 鈥� create a project role with the appropriate rights, then assign users to that role.

If a user's name does not appear in the search, they do not have a REDCap account. Only WSU REDCap Administrators can create new accounts.

Change or end access

Users with permission to manage User Rights can change a team member's rights or role at any time.

When someone leaves the project team or institution:

  • Set an expiration date for their project access.
  • Do not delete or remove the user from the project. Doing so can negatively affect audit trails, user logs, and other project functions.
  • The project expiration date affects access to that project only.

REDCap accounts are also subject to system-wide W# account status. When a REDCap account expires, access to all projects is suspended. Contact the WSU REDCap Administrators if someone needs continued project access after leaving WSU.

Projects involving PHI

Projects involving WSU-affiliated clinical organizations may require additional restrictions to protect PHI and support clinical-site oversight.

After a project is submitted for Move to Production, WSU REDCap Administrators will change the Project Owner's rights to the appropriate PHI Project Owner role. Additional PHI-specific roles are available for quality reviewers, statisticians, and site auditors.

Use Data Access Groups for multi-site projects

Data Access Groups (DAGs) can restrict users to viewing data from their assigned site. This provides an additional layer of protection for PHI in multi-site research.

  • Create a DAG for each site.
  • Assign users to the appropriate site.
  • Use the DAG Switcher when assigning multiple users.
  • A user can belong to multiple DAGs.
  • Only place users in a DAG when they need to be restricted to specific sites.
  • Do not place users who need access to all sites鈥攕uch as Project Owners or Project Coordinators鈥攊n a DAG.

Key principle- give each REDCap user the minimum level of access needed to perform their role, and update or end that access when their role changes.

Changes after production

Changes can be made to a REDCap project after it has been moved to Production, but they should be made carefully. To make changes, click Enter Draft Mode. The REDCap Administration team will review proposed changes before approval to ensure they do not negatively affect data that have already been collected.

Changes that generally do not affect existing data:

The following changes can be made without consequences:

  • Add new fields.
  • Reorder existing fields on the same form.
  • Add Action Tags or field notes.
  • Mark a field as an Identifier.
  • Rename forms.
  • Add or change Section Headers.
  • Change a radio button field to a dropdown, or vice versa.
  • Add a new multiple-choice option at the end of an existing list.
  • Add or remove minimum or maximum value validation.
  • Add, change, or remove branching logic.
  • Add or remove whether a field is required.
  • Add, modify, or delete a matrix group name.

Note: Adding branching logic may hide fields that already contain data.

Changes that may cause data loss

Use caution with changes such as:

  • Deleting fields.
  • Changing forms using the Data Dictionary.
  • Changing a field between Radio Buttons and Check All That Apply.
  • Changing or reordering choices in multiple-choice fields.
  • Deleting a multiple-choice response option.
  • Updating a calculated-field formula.
    • Existing data remain, but are not recalculated using the new formula.
  • Changing slider numbers or anchors.

Changes that may cause data loss or corruption

These changes may affect the meaning or integrity of existing data:

  • Changing a field label when the change alters the meaning of the data entered.
  • Changing a text box to a calculated field.
  • Changing the field validation format.
  • Changing slider labels when the change alters the meaning of the data entered.

Changes that cannot be made

The following changes are not permitted after moving to Production:

  • Changing a variable name.
  • Converting a matrix field into separate fields.

Key principle- Before changing a Production project, consider how the change could affect data that have already been collected. When in doubt, use caution and allow the REDCap Administration team to review the change.

Citing REDCap

If you use REDCap for research, please cite the REDCap publication in the Methods section and References of any resulting publications.

REDCap use is also tracked through information entered in your project settings, including:

  • Project title
  • Project purpose (e.g., Research)
  • Principal Investigator (PI) name
  • PI name as it should appear in publications (last name and initials)

REDCap Publication

Use the following citation:

Harris PA, Taylor R, Thielke R, Payne J, Gonzalez N, Conde JG. Research electronic data capture (REDCap)鈥擜 metadata-driven methodology and workflow process for providing translational research informatics support. J Biomed Inform. 2009 Apr;42(2):377鈥�81.

Article:

Analysis/Clean up

When data collection is complete, Project Owners are encouraged to move the project to Analysis/Clean Up status. This limits project changes while allowing necessary data review and analysis.

Move a Project to Analysis/Clean Up

  1. Go to Project Setup.
  2. Select the Other Functionality tab.
  3. Click Move to Analysis/Clean Up status.

This status:

  • Restricts changes to the project.
  • Restricts data entry.
  • Allows data editing and quality checks to continue.
  • Keeps data exports enabled.

Project Owners should also review user access at this stage. Add expiration dates for users who are no longer involved in data cleaning or data exports. See Managing User Rights for more information.

Mark a Project as Completed

Once all analysis, data cleaning, and exports are finished:

  1. Go to Project Setup.
  2. Select the Other Functionality tab.
  3. Click Mark project as Completed.

A completed project is locked:

  • Users cannot make changes to the project.
  • Users cannot export data.
  • The project is hidden from users' My Projects list by default.

Users can still choose to display completed projects by selecting the appropriate option in their My Projects list.

Frequently Asked Questions

  • My REDCap access is gone 鈥� what happened to it?

    There are a couple of situations in which user access is discontinued.

    1. User access to a project can be suspended by the Project Owner.
    2. The 糖心原创/糖心原创 Research Institute system administrators will end access when you leave the university or after a one-year period of dormancy.

    Thus, if you have not left the university, first check with the Project Owner.

  • Where is the REDCap system hosted?

    REDCap at 糖心原创 is hosted by CaTS at 糖心原创. The REDCap Administration for 糖心原创 is comprised of Information Technology (IT) personnel and content/non-technical user support individuals. REDCap Administrators have specific rights determined by REDCap policy and/or 糖心原创 policy.

  • How can I get help with REDCap use?

    REDCap has many built-in training videos located throughout the system on relevant pages. Additional help can be found in REDCap under the Help & FAQs link. 

    The WSU REDCap page has several Quick Start guides for new user accounts and creating new projects.

    You can also contact the REDCap Help Desk mailbox REDCap@wright.edu with specific questions.

  • Are there restrictions on what I can use REDCap for?

    REDCap is to be used for academic research. Do not use REDCap for storing official 糖心原创/糖心原创 Research Institute business data or in place of patient medical records.

  • What is a REDCap Project Owner? Secondary Owner? REDCap User? What is the difference between a REDCap Project Owner and the Principal Investigator (PI)?

    REDCap User: Anyone who signs up for a user account.

    Project Owner: Designated owner of any separate project.

    Principal Investigator (PI): the PI of the research project. The PI may or may not be the Project Owner. For example, the Project Owner could be the Research Manager of a large research project for which there is a different PI. Generally, the PI will be the Project Owner and can give broad REDCap access rights to the Research Manager. Thus, the Research Manager can set up and oversee the research assistants and their rights, databases, and project implementation. 

    Secondary Owners: The Project Owner must designate a Secondary Owner for every project, and request access for the Secondary Owner on a per project basis. This assists during Project Owner illness or leave of absence, or an apparently dormant account. Thus, one of the requirements to move a project to Production will be to have a designated Secondary Owner. The research manager of a project can be a Secondary Owner.

  • Why is a second Project Owner required?

    A Project Owner is a predefined role created by the WSU REDCap Administrators that has the most user rights allowing that user to customize their project as needed. Even if you do not use this role name, having a second user designated with the same rights as the project leader/creator provides consistency in cases when the project leader is unavailable, e.g., illness or leave of absence, or has left the organization.

    REDCap Administrators may ask you to designate a second user with these rights when reviewing a project that is moving from Development Mode to Production.

  • What is the relationship of REDCap to the IRB?

    There is no formal relationship between REDCap and the 糖心原创 IRB. However, use of REDCap helps investigators to meet many of the requirements enforced through the IRB. See example statement for description of a REDCap project for IRB submissions (#16).

  • Is there a standard statement to describe the use of REDCap for my project to the IRB or granting agencies?

    Statements should be consistent with the type of project undertaken. Here is an example of wording that could be appropriate for many types of projects:

    Example: The project will be undertaken with the assistance of REDCap (Research Electronic Data Capture), a software toolset and workflow methodology for electronic collection and management of research and clinical trial data. REDCap data collection projects rely on a study-specific data dictionary, developed iteratively with a testing process. All users are given individual usernames and passwords and their access is restricted on a role-specific basis. Surveys and other data collection instruments created in REDCap can engage potential respondents using a variety of notification methods.  REDCap provides secure, web-based applications that provide an intuitive interface for users to enter data with real time validation rules (with automated data type and range checks) at the time of entry. These systems offer easy data manipulation with full audit trails and reporting, and an automated export mechanism to common statistical packages (Excel, SPSS, SAS, Stata, R/S-Plus). REDCap servers are securely housed in an on-site limited access data center managed by the 糖心原创 Research Institute at 糖心原创. All web-based information transmission is SSL encrypted. All the data is stored on a private, firewall protected network. REDCap was developed specifically around HIPAA-Security guidelines and is implemented and maintained according to these standards. REDCap has >1,700 active institutional consortium partners in 98 countries, > 200,000 projects, >300,000 users internationally (see updated info at ).1

    1Paul A. Harris, Robert Taylor, Robert Thielke, Jonathon Payne, Nathaniel Gonzalez, Jose G. Conde, Research electronic data capture (REDCap) - A metadata-driven methodology and workflow process for providing translational research informatics support, J Biomed Inform. 2009 Apr;42(2):377-81.

    Link to article: 

  • What is the required REDCap Citation for publications using data acquired through REDCap?

    The following is from the  website.

    鈥淲e recommend the following boilerplate language:

    Study data were collected and managed using REDCap electronic data capture tools hosted at 糖心原创/糖心原创 Research Institute. REDCap (Research Electronic Data Capture) is a secure, web-based application designed to support data capture for research studies, providing 1) an intuitive interface for validated data entry; 2) audit trails for tracking data manipulation and export procedures; 3) automated export procedures for seamless data downloads to common statistical packages; and 4) procedures for importing data from external sources.1

    1Paul A. Harris, Robert Taylor, Robert Thielke, Jonathon Payne, Nathaniel Gonzalez, Jose G. Conde, Research electronic data capture (REDCap) - A metadata-driven methodology and workflow process for providing translational research informatics support, J Biomed Inform. 2009 Apr;42(2):377-81.

    Link to article: 鈥�

  • Why must the 糖心原创 REDCap Administrators approve my project to move from Development to Production?

    The REDCap Administrators have ultimate authority on approving migration to production mode, and must perform the actual IT process for the migration. The main role of this review step is to ensure users have addressed HIPAA requirements for PHI and have set appropriate user rights, and to prevent errors commonly reported by other institutions. This is the norm in the industry.

  • Please explain what the administrator rights, versus user rights, are for REDCap. Administrators have certain rights that users do not for security and data integrity reasons.

    糖心原创/糖心原创 Research Institute REDCap Administrator Rights (from project-redcap.org)

    REDCap information technology system administrators, also known as superusers by REDCap, have the ability to do several things that REDCap end users (regular users) cannot do. The following is a list of some of these capabilities.

    1. Move a project to production.
    2. Add custom text to the top of the Home page of a project.
    3. Add custom text to the top of all Data Entry pages of a project.
    4. Add custom logo and institution name to the top of every page of a project.
    5. Add grant to be cited.
    6. Display a different language for text within a project. The languages available vary by institution.
    7. Turn Double Data Entry on and off.
    8. Customize the date shift range for date shifting de-identification.
    9. Approve API token requests.
    10. Delete all API tokens.
    11. Create an SQL field, generally used to create a dynamic dropdown list with data drawn either from the same project or another.
    12. For project already in production:
      1. Add/modify events.
      2. Designate instruments to events.
      3. Convert an instrument that is a survey to being a data entry instrument only.
      4. Erase all data.
      5. Move the project back to development status.
      6. Delete the project.
    13. Suspend and unsuspend users from all of REDCap. Note, however, that expiring a users鈥� access to a specific project does not require a REDCap administrator.
    14. Reset the password for a user.
    15. Update the email address associated with an account for a user, in case that user is neither able to log in nor has access to the email address associated with their account.
  • What are some variable naming conventions that I should consider? How can I prepare for sharing my data with others in the future?

    Variable names: The variable field name must be unique across the entire project, and will be the field name used for branching or piping. The variable name should start with a letter; the remaining characters may be any letter, digit, a period or the symbols #, @, _, or $. Do not end with a period. No more than 64 characters are permissible. No duplicate names are acceptable. Certain words cannot be used for variable names, specifically: ALL, AND, BY, EQ, GE, GT, LE, LT, NE, NOT, OR, TO and WITH. 

    Ontology / metadata: Researchers should use classic, recognized ontology, and create metadata for each project, experiment or analysis.  Ontology refers to an organizational system designed to categorize information and informational relationships. A simplistic example would be categorizing something as a bacteria or a virus.  Metadata is data that describe other data, such as 鈥�3 projects with 3 arms each and 800 total variables鈥�.   Frequently, using ontology and metadata is not difficult and is intuitive.  However, some projects require higher level support for the metadata.  Increasing needs for data sharing and big data analysis require recognized ontologies.  Listed here are several support tools:

    Ontology/terminology: Consider using the Bioportal to use internationally recognized ontology and terminology:   , under UMLS License ( ).   This includes SNOMED clinical terms, RxNORM, Medical Dictionary for Regulatory Activities (MEDDRA), National Drug Data File (NDDF), Current Procedural Terminology (CPT), Medical Subject Headings (MESH), Radiology Lexicon (RADLEX), National Cancer Institute Thesaurus (NCIT), Symptom Ontology (SYMP), and much more. 

    Metadata Support Tools: Create metadata for experiments and analyses that are not just done for one-time consideration. 
    Again, this can be intuitive, but for larger or complicated projects downloaded from REDCap into Excel, one metadata tool, Rightfield, can be particularly useful. 

    Examples of metadata tools (all of these can be used by Windows, Mac, and Linux with some limitations):

    Rightfield - this uses info from the Bioportal.  It is an open source tool for adding ontology term selection to Excel spreadsheets, i.e, Excel plug-in.  鈥淩ightfield is used by a 鈥楾emplate Creator鈥� to create semantically aware Excel spreadsheet templates.  The Excel templates are then reused by scientists to collect and annotate their data without any need to understand, or even be aware of, RightField of the ontologies used.鈥�

    Annotare - a 鈥渢ool for annotating biomedical investigators and resulting data.  It is intended to help a bench biologist construct a MIAME-compliant file based on the MAGE-TAB format.鈥� 

    , for lab scientists to record experimental information and meet annotation requirements.  Metadata schema is ISA-tab.  Good for Life Sciences.

     - 鈥淗andles all microscopy images in a secure central repository鈥�. 

     - 鈥渇acilitates ontology search and tagging functionalities within Google Spreadsheets.鈥�  It has been developed by the  at the University of .  Ontology searching and automated tagging from the NCBO Bioportal.    Part of ISA-Tools Suite.  Annotations are generated within the tabular data file.