Security & HIPAA Compliance

The Code Rare Survey Platform was architected with enterprise-grade security and true zero-knowledge privacy. Personal identity data is encrypted so that only the participant can access it — researchers and survey owners see only anonymized aliases.

HIPAA Compliant
AES-256 Encrypted
Zero-Knowledge Privacy
GDPR & CCPA Ready
MFA Required

Our Core Security & Privacy Architecture

🔒
256-Bit SSL/TLS Encryption

All pages, logins, survey submissions, and API calls use industry-standard 256-bit SSL/TLS with SHA-256 certificates. Data is always encrypted in transit.

🔑
Password-as-Encryption-Key
(Zero-Knowledge Privacy)

Every participant's personal identity information (name, email, and any PHI) is encrypted client-side in the browser using their own password as the encryption key (AES-256-GCM via PBKDF2). The server never receives or stores plaintext personal data.

🛡️
Multi-Factor Authentication
(MFA Required)

Both administrators and participants must use MFA on every login. This protects accounts even if a password is compromised, adding a critical second layer of identity verification.

Privacy for Researchers & Survey Administrators

When survey data is viewed at the individual answer level by researchers or survey administrators at Code Rare, the participant's real identity is never shown. Instead, each participant is displayed only as an anonymized alias — for example, Participant-XYZ-123.

Survey answers remain fully usable for analysis, comparisons, feedback, and visualizations, but they are permanently decoupled from any personally identifiable information. This pseudonymization ensures that researchers can perform their work without ever seeing or accessing real identities.

How We Meet HIPAA Security Rule Requirements

Administrative Safeguards
  • ✔Full audit logging of every access, change, and decryption attempt
  • ✔Role-based access control (survey owners vs. participants vs. administrators)
  • ✔Risk analysis, security policies, and Business Associate Agreement (BAA)
  • ✔Workforce training and confidentiality agreements
Physical & Technical Safeguards
  • ✔Hosted on HIPAA-eligible cloud infrastructure
  • ✔SQL Server Transparent Data Encryption (TDE) for data at rest
  • ✔Client-side AES-256-GCM encryption of all PII
  • ✔Protection against SQL injection, XSS, and CSRF
  • ✔Regular penetration testing and vulnerability scanning
De-Identification for Research
  • ✔Pseudonymization via aliases for all admin/researcher views
  • ✔The link between an alias and a real identity is kept only so you can resume surveys and receive account notices — it is never shown in any admin or researcher view, and every access is audit-logged
  • ✔Meets HIPAA Safe Harbor and Expert Determination de-identification standards

Broader Privacy Regulations

GDPR Compliance

SurveyApp meets all seven GDPR principles through:

  • Data minimization & purpose limitation
  • Client-side encryption and pseudonymization
  • Right to access, rectification, erasure ("right to be forgotten"), and portability
  • Full accountability via audit logs
CCPA Compliance

California residents receive full rights under CCPA:

  • Right to know what data is collected
  • Right to delete their personal information
  • Right to opt-out of any data sale — we never sell data
  • Right to non-discrimination

Additional Enterprise Protections

reCAPTCHA v3 Spam Protection
All public-facing survey entry points are protected against automated bots and spam submissions.
99.9% Uptime SLA with HIPAA-Eligible Hosting
Deployed on infrastructure that meets HIPAA eligibility requirements with guaranteed availability.
Regular Independent Security Audits
Third-party penetration testing and vulnerability scanning are conducted on a regular schedule.
Automated Encrypted Backups
All data is backed up automatically and encrypted at rest. Easy data export is available to authorized users.
Strict Input Validation
All API inputs are validated and sanitized to prevent SQL injection, XSS, and other common web attack vectors.

Business Associate Agreement (BAA)

Healthcare organizations that use this portal to collect Protected Health Information (PHI) are required under HIPAA to maintain a signed BAA with Code Rare. We provide one upon request.