Anyone can install REDCap on a server. Whether that server is actually configured for the compliance requirements and operational realities of running research data infrastructure is a different question entirely — and one a sales pitch won't answer for you. Here are seven questions worth asking directly.
1. How many environments do I get — and are they real?
Responsible REDCap administration runs at minimum DEV, TEST, and PROD environments, so instrument changes get tested before they touch live study data. A provider offering only a single production environment is cutting a corner that eventually costs you a corrupted live project.
2. Who executes the BAA, and what does it actually cover?
A Business Associate Agreement should be standard, not an add-on. Ask specifically what infrastructure it covers — server, backups, network — and confirm in writing that the provider has zero access to your actual REDCap data, consistent with the consortium license terms.
3. What does "HIPAA compliant" actually mean in their environment?
This phrase gets used loosely. Ask for specifics: encryption at rest and in transit, access logging, backup encryption, and what their incident response process looks like if something goes wrong.
4. Is pricing per-project, per-server, or flat-rate?
Per-project pricing punishes exactly the growth you want as a research program. Understand the pricing model before you're locked into a study count that determines your monthly bill.
5. Who handles REDCap version upgrades — and on what schedule?
REDCap ships regular updates, some with security implications. Ask how upgrades are scheduled, tested, and communicated, not just whether they happen "eventually."
6. What's the actual support response time?
Get this in writing, not as a verbal assurance. A downed REDCap environment during active data collection is a real operational emergency, not a ticket that can sit for three days.
7. Can this environment grow with you?
If your research program is likely to eventually need FHIR interoperability, an EMPI connection, or a data lake feeding downstream analytics, ask whether the provider can support that or whether REDCap hosting is a dead-end silo you'll have to re-architect around later.
Anyone selling REDCap hosting can answer question 1 and 2. Very few can answer questions 6 and 7 credibly, because most REDCap-only hosting providers have never actually built the broader interoperability layer research data eventually needs to connect to.
Tell us what's not talking to what.
Whether it's a data lake that needs building, an EMPI that needs replacing, or a document pipeline eating your team's time — start with a real conversation.
Start a Conversation