By submitting this pre-approval request you are taking responsibility for the security of every device that uses any API tokens that are later approved.
If you would like to just test how the mobile app works, please send email to redcap@iu.edu instead of filling out this form.
First Name
* must provide value
Last Name
* must provide value
Deprecated, always hidden field
Phone number
* must provide value
E-mail
* must provide value
Department
* must provide value
If you are not the principal investigator (PI) for this project, please provide the name, phone number, and email address of the PI.
What type of devices will you use?
* must provide value
Approximately how many devices will you use?
* must provide value
Who will be responsible for maintaining the devices?
Please provide name, email, and phone number.
IU REDCap administrators will not be able to configure and maintain mobile devices. Typically departmental IT staff will maintain mobile devices.
* must provide value
Please provide a short description of the work that will be supported.
Please include how the mobile app will be used.
* must provide value
Why is the mobile app necessary or desired compared to using a web browser on a mobile device?
* must provide value
PLEASE NOTE: You can use IU REDCap on smart phones and tablets without having to use the mobile app.
The IU REDCap mobile browser interface is easier to use and has more functionality than the REDCap mobile app.
Other reasons to use the mobile app for this work
What IU REDCap project (or projects) will be accessed by the mobile devices?
Please provide the project id(s) of the project(s). You can find the project id for a project by navigating to that project and looking in the URL for 'pid=NNNN', where NNNN would be the project id.
* must provide value
If some or all of the projects don't exist yet, include the ones that exist and note that some projects don't yet exist.
Will the device(s) store critical data, such as protected health information?
Critical data is defined as: "Inappropriate handling of this data could result in criminal or civil penalties, identity theft, personal financial loss, invasion of privacy, and/or unauthorized access to this type of information by an individual or many individuals."
* must provide value
Yes No
Although each person using the mobile app will need to request their own API token, this pre-approval only needs to be requested once for each project (or set of related projects).
Please list about how many people will be requesting tokens for this project and, where possible, the names of the people who will be requesting tokens.
Each user of the mobile app will use their own API token to access IU REDCap.
Users will not share accounts in the mobile app and/or share the password for their mobile app account.
* must provide value
Yes No
The API tokens used by the mobile app to authenticate to IU REDCap will not be shared with anyone nor stored anywhere besides in IU REDCap and in the mobile app.
* must provide value
Yes No
The QR code used by the mobile app to transfer the API token from IU REDCap to the mobile app will not be copied or shared in any way, except by the QR reader in the mobile app.
* must provide value
Yes No
When asking participants to self-enter data, the Lock-out feature of the REDCap mobile app will be used so that participants can not see other data.
* must provide value
Yes No
Each user of the mobile app will be trained to protect their API token, to protect their QR code, to use only their own app account, to use the Lock-out feature when allowing patients to self enter data, and to follow any further institutional and/or department guidelines on protecting the security and privacy of data on mobile devices
* must provide value
Yes No
Yes No
The maintainers of the devices have read and will abide by any departmental policies related to mobile devices.
* must provide value
Yes No
In accordance with IT-12.1 guidelines for devices storing critical data, devices will be protected with whole-device encryption.
* must provide value
Yes No
In accordance with IT-12.1 guidelines for devices storing critical data, backups are not allowed to cloud services, such as iCloud, so backups will be turned off or directed at institutional services.
* must provide value
Yes No
All security incidents involving the mobile device will be communicated to the IU REDCap administrators (redcap@iu.edu) and to Indiana University incident response (it-incident@iu.edu).
This includes compromised, unsecured, lost and/or stolen devices, API tokens, and QR codes.
* must provide value
Yes No
Problems with devices will be escalated to departmental IT providers. Problems with the REDCap Mobile app will be escalated to the IU REDCap administrators (redcap@iu.edu).
* must provide value
Yes No
All users will have met their specific research affiliate/institution mandated HIPAA training and research training before using the app.
* must provide value
Yes No
When a user stops being associated with a project or when a device is disposed of in any way (sold, given, returned, exchanged), all REDCap data will be cleared from the device and the user's API token will be deleted from the IU REDCap project.
If a device has failed such that the REDCap app can no longer be opened in order to dispose of data, the device will be remotely wiped, if possible, or the device will be destroyed, using institutional services for device destruction, if available.
If destroying a device would void a desired warranty, the manufacturer of the device will be contacted to request that the device is destroyed after being returned or exchanged.
* must provide value
Yes No
Which IT person or department have you conferred with to make sure that the devices that will host the API token(s) will follow all relevant policies?
* must provide value