Skip to content
tiviztech.

Security audit
for REDCap

Your REDCap instance stores patient data and clinical research information. We verify it is protected, up to date, and compliant with current regulations.

42

Instances analysed in Spain

70%

With high-risk findings

GDPR

Compliance verification

E6(R3)

ICH alignment

The problem nobody checks

Most REDCap instances in Spain are installed and forgotten. No updates, no configuration review, no security verification. Meanwhile, they store special-category data protected under GDPR.

Data exposure

Publicly accessible file directories, patient documents indexed by search engines.

Insecure configuration

Accessible installation pages, outdated versions with known vulnerabilities, missing security headers.

Regulatory non-compliance

No audit trail, indefinite retention policies, no formal validation for ICH E6(R3) or the Spanish National Security Framework (ENS).

Real case

Patient data exposed publicly

During a routine assessment, we found that a biomedical research institution had its REDCap instance's file directory accessible without authentication. Documents containing patient data were indexable by any search engine.

The centre was notified and the issue was fixed within 24 hours. Without a specialised audit, the exposure could have continued indefinitely.

GDPR Art. 32 Special-category data Fixed in <24h
Services

Three levels of
protection

Level 01

Basic Security Assessment

  • External attack surface analysis
  • Sensitive information exposure check
  • Server security configuration assessment
  • Best-practice compliance check
  • Report with findings and recommendations

Delivery: 1-2 days

Request assessment
Recommended Level 02

Security and Compliance Audit

  • Everything in the previous level
  • Access control and authentication assessment
  • GDPR and ICH E6(R3) compliance analysis
  • Data and retention policy review
  • OWASP Top 10 vulnerability scan
  • Executive + technical report + risk matrix

Delivery: 3-5 days

Request audit
Level 03

Audit + Remediation

  • Everything in the previous level
  • Fixes for all findings
  • System hardening and updates
  • Verification re-test
  • Remediation certificate

Delivery: 1-2 weeks

Request a quote
Ongoing service

Annual security maintenance

Periodic audits, REDCap updates, threat monitoring, and priority incident support. Your instance always protected and up to date.

Learn more

Why Tiviztech

REDCap specialists

We're not a generic cybersecurity firm. We know REDCap from the inside: its architecture, its common weak points, and its regulatory requirements.

Spanish ecosystem

We have analysed 42 REDCap instances across Spanish hospitals, medical societies and universities.

Regulatory compliance

We assess against GDPR, ICH E6(R3), the Spanish National Security Framework (ENS) and OWASP. We don't just find technical issues: we verify regulatory compliance.

Free initial assessment

We show you the most relevant findings for your instance with no obligation. You decide if you want to go further.

Request a free initial assessment

We analyse your REDCap instance and show you the main findings. No cost, no obligation.

Frequently asked questions

Why do I need a REDCap-specific audit?

REDCap stores health data protected under GDPR. Inadequate configuration can expose patient information, breach ICH E6(R3), and lead to penalties. A specialised audit detects vulnerabilities that a generic assessment does not cover.

How is this different from a generic pentest?

A generic pentest reviews standard web vulnerabilities. Our audit understands REDCap's internal architecture, its common weak points, and the regulatory requirements of the healthcare and clinical trials sector.

Is it remote or on-site?

The basic assessment and the full audit are carried out remotely. Only the remediation package may require on-site access, depending on the complexity of the infrastructure.

How long does it take?

The basic assessment is completed in 1-2 days. The full audit takes 3 to 5 days. The audit with remediation can extend to 1-2 weeks depending on the number of findings.