REDCap — Compliant Research Data Capture

The academic standard for collecting sensitive study data: institution-hosted surveys and case-report forms with the audit trails, access controls, and compliance IRBs expect.

Category Data
Pricing Free
Rating ★★★★☆ (4/5)

Overview

REDCap is how regulated research collects data: your institution hosts it, ethics boards know it, and its case-report forms, audit logs, role permissions, and export controls satisfy HIPAA/GDPR-class requirements that SurveyMonkey never will. 7,000+ institutions run it.

Why researchers use it

  • Compliance by construction — audit trails, e-consent, granular permissions
  • Institution-hosted — data stays on university infrastructure, satisfying DPAs
  • Longitudinal designs — scheduling, repeat instruments, and survey invitations built in

Getting started

  1. Request access through your institution’s REDCap administrator (there almost certainly is one).
  2. Build instruments with the online designer; pilot with test records before going live.
  3. Define your export strategy early — identified vs de-identified exports are a project setting, not an afterthought.

The honest review

Strengths. The rare tool ethics committees pre-approve by name; data dictionaries make instruments shareable and studies replicable at other REDCap sites.

Limitations. The interface is dated and the designer clunky; complex branching logic gets unwieldy; you depend on your institution’s version and admin responsiveness.

When NOT to use this For anonymous, low-stakes surveys, lighter tools (LimeSurvey, even forms) are faster — REDCap’s overhead is the price of compliance, so spend it only where the data demands it.