REDCap (Research Electronic Data Capture) is a secure, web-based application designed to support data collection and management for research studies. It allows users to build and manage online surveys and databases quickly and without needing extensive programming knowledge.
REDCap is widely used in academic, clinical, and translational research for its flexibility, audit trails, data validation, and compliance with regulatory standards like HIPAA. Its features include automated workflows, user permissions, and integration capabilities, making it a powerful tool for capturing high-quality research data.
REDCap is accessible to all UM Faculty, Staff and Students. External users can also access REDCap with a CaneID which can be requested through the Cane Self-Service Portal. No additional request form is needed, access is automatically granted.
| Current Version | ⚙️ 16.0.25 LTS |
| Total Projects | 📂 6,648 |
| Total Users | 👤 12,194 |
| Last Upgrade | ✅ Februrary 2026 |
| Next Upgrade | ⬆️ July 2026 |
For requests regarding REDCap, please submit your request via ServiceNow General Support. Please ensure to include REDCap in the details of your request to ensure proper routing to our team.
v16
16.0.39 (released on 2026-07-14)
Critical Security Fix
A Remote Code Execution vulnerability was found in which a malicious user who is logged in could potentially exploit it by manipulating any REDCap logic that is stored in a project (e.g., calculations, branching logic, data quality rule logic, report filter logic). If successfully exploited, this could allow the attacker to remotely execute arbitrary code on the REDCap server. Note: Only authenticated users are able to exploit this. This vulnerability exists in all versions of REDCap.
v16
16.0.39 (released on 2026-07-14)
Major Security Fix
An SQL Injection vulnerability was found on a MyCap-related page, in which a malicious user could potentially exploit it and execute arbitrary SQL commands on the database by manipulating an HTTP request in a specially-crafted way. This can only be exploited by authenticated users that have Project Design privileges in a MyCap-enabled project. Bug exists in REDCap 13.0.0 and higher.
v16
16.0.37 (released on 2026-07-02)
Critical Security Fix
Stored XSS vulnerability allowing malicious HTML/JavaScript injection through user input displayed throughout REDCap (field labels, survey instructions, reports, survey responses). Exploitable by authenticated users and survey participants.
v16
16.0.37 (released on 2026-07-02)
Major Security Fix
Unauthenticated Open Mail Relay vulnerability allowing attackers to send large volumes of custom emails from a survey-related page.
v16
16.0.37 (released on 2026-07-02)
Major Security Fix
File upload endpoint validation strengthened to prevent uploads to non-File Upload field types.
v16
16.0.37 (released on 2026-07-02)
Major Bug Fix
MyCap mobile app communication failure preventing existing participants from syncing with the server after a recent change.
v16
16.0.37 (released on 2026-07-02)
Improvement
MyCap participant experience automatically restored after upgrade without requiring users to rejoin projects.
v16
16.0.36 (released on 2026-06-25)
Major Security Fix
Participant impersonation vulnerability in MyCap API allowing a participant to potentially access another participant's data.
v16
16.0.36 (released on 2026-06-25)
Major Bug Fix
PDF viewer toolbar controls (zoom, paging, printing) disabled when viewing inline PDFs.
v16
16.0.36 (released on 2026-06-25)
New Feature
Added Copy Project option: "Log the copying of all records in the new project (may take much longer)" to reduce memory and processor utilization during large project copies.
v16
16.0.36 (released on 2026-06-25)
Improvement
Updated AI integration to support newer OpenAI models using max_completion_tokens.
v16
16.0.36 (released on 2026-06-25)
Improvement
Optimized branching logic JavaScript for improved page-load performance.
v16
16.0.35 (released on 2026-06-18)
Major Security Fix
Reflected XSS vulnerability on the Database Query Tool page exploitable through specially crafted URLs by authenticated administrators.
v16
16.0.35 (released on 2026-06-18)
Major Bug Fix
Form status value incorrectly populated during blank data imports, potentially changing form status icons.
v16
16.0.35 (released on 2026-06-18)
Major Bug Fix
Bulk Record Delete allowed deletion of data within locked records.
v16
16.0.35 (released on 2026-06-18)
Improvement
Improved handling of large clinical history background fetches and adjudication processing.
v16
16.0.35 (released on 2026-06-18)
Improvement
Fixed embedded PDF submission issues causing endless "Working..." states.
v16
16.0.31 (released on 2026-05-20)
Major Bug Fix
Form status imports incorrectly retained null values instead of defaulting to status "0".
v16
16.0.31 (released on 2026-05-20)
Major Security Fix
DAG users could retrieve Survey Access Codes, Survey Queue Links, or Survey Return Codes for records outside their Data Access Group.
v16
16.0.31 (released on 2026-05-20)
Improvement
Fixed branching logic recursion errors.
v16
16.0.30 (released on 2026-05-14)
Major Bug Fix
Form status field import process incorrectly retained blank values.
v16
16.0.30 (released on 2026-05-14)
Major Bug Fix
Some survey pages could fail unexpectedly with a fatal PHP error.
v16
16.0.29 (released on 2026-05-13)
Major Security Fix
CSV injection vulnerability that could potentially execute malicious code when downloaded CSV files are opened in Microsoft Excel.
v16
16.0.29 (released on 2026-05-13)
Improvement
Enhanced CSV file encoding validation to prevent truncation and import issues.
v16
16.0.28 (released on 2026-05-07)
Major Security Fix
JavaScript Injection Sinks vulnerability allowing authenticated users to inject malicious client-side code.
v16
16.0.28 (released on 2026-05-07)
Major Bug Fix
CDIS/CDP background fetch jobs repeatedly crashed because of memory exhaustion.
v16
16.0.28 (released on 2026-05-07)
Major Bug Fix
e-Consent responses could be overwritten, potentially nullifying participant consent under concurrent access conditions.
v16
16.0.28 (released on 2026-05-07)
Major Security Fix
DAG users could export Survey Links for records outside their Data Access Group.
v16
16.0.27 (released on 2026-05-01)
Major Bug Fix
Surveys and data entry forms incorrectly displayed branching logic errors and failed to properly hide fields.
v16
16.0.26 (released on 2026-04-30)
Major Bug Fix
User Roles failed to be created when creating projects from Project XML files.
v16
16.0.26 (released on 2026-04-30)
Improvement
Multiple CDIS/CDP/CDM performance, caching, adjudication, and FHIR fetch stability improvements.
v16
16 16.0.22 (released on 2026‑04‑09)
Major security fix
Stored XSS vulnerability on MyCap pages exploitable by users with Manage MyCap Participants rights (REDCap ≥ 13.0.0).
v16
16 16.0.22 (released on 2026‑04‑09)
Major security fix
SQL Injection vulnerability on MyCap pages exploitable by users with Project Design privileges (REDCap ≥ 13.0.0).
v16
16 16.0.20 (released on 2026‑03‑27)
Major bug fix
Non-admin users could not access projects when Access Control Groups were enabled due to fatal PHP errors.
v16
16.0.18 (released on 2026‑03‑19)
Major bug fix
PDF Snapshot functionality failed after renaming records.
v16
16.0.18 (released on 2026‑03‑19)
Major bug fix
Modifying user privileges could unintentionally remove Data Access Group assignment.
v16
16.0.17 (released on 2026‑03‑12)
Major security fix
Reflected XSS vulnerability on API Playground exploitable by authenticated API token holders (REDCap ≥ 6.9.0).
v16
16.0.17 (released on 2026‑03‑12)
Major bug fix
CDP/DDP background fetch workflows could stop before processing all selected data, leaving records incomplete.
v16
16.0.17 (released on 2026‑03‑12)
Major bug fix
Survey Form Status values could enter an inconsistent “limbo” state; upgrade SQL corrects affected responses.
v16
16.0.16( released on 2026‑03‑05)
Improvement
REDCap now blocks API and survey calls using versioned URLs to reduce exposure to older-version vulnerabilities.
v16
16.0.14(released on 2026-02-18)
Major bug fix
When a survey page is submitted with some required fields left empty, in certain scenarios the page might not be redisplayed with the Required Fields warning. Bug emerged in the previous version.
v16
16.0.12(released on 2026-02-05)
Critical security fix
A Remote Code Execution vulnerability was found in which a malicious user who is logged in could potentially exploit it by manipulating any REDCap logic that is saved via specific REDCap endpoints or is stored in a project (e.g., calculations, branching logic, data quality rule logic, report filter logic). Note: Only authenticated users are able to exploit this. This vulnerability exists in all versions of REDCap.
v16
16.0.11(released on 2026-01-30)
Major bug fix
The upgrade page would mistakenly not load due to a fatal PHP error when using PHP 8.4 or 8.5.
Anyone who needs access to REDCap must have an active CaneID, including UMiami personnel and external collaborators. Please visit CaneID to register or for additional assistance with your account. Once a CaneID is obtained, navigate to https://redcap.miami.edu, log in using your CaneID credentials and complete the presented form. Once confirmed, your account will be created immediately. Once a CaneID is obtained, to access REDCap, please navigate to https://redcap.miami.edu, log in using your CaneID credentials, then complete and submit the presented form below. A REDCap account will be provisioned immediately.
Although the University of Miami’s REDCap application is a web-based, secure, and HIPAA compliant system, there are three categories of studies that are not REDCap eligible: 🚫 Research that requires 21 CFR Part 11 compliance 🚫 Research that involves an investigational new drug or device 🚫 Research that is tracked for billing compliance If your project falls into any of the above, then Velos eResearch is the application you should use. Please see the Clinical Research Participant Enrollment and Tracking Policy (PDF) for more information. If your Research does not require 21 CFR Part 11 compliance or involve an investigational new drug or device, but requires tracking for billing compliance, you may still use REDCap as a supplemental system to Velos as long as all participants are registered in Velos for billing compliance purposes.
REDCap has a few quick video tutorials available that will provide more details on the application. To view them, click on the “Training Videos” link near the top of the page, after logging into REDCap. If you don’t see the link, navigate to here after logging in: https://redcap.miami.edu/index.php?action=training As of 2024, the REDCap project is 15 years old and used by over 7000 institutions. There are many free and accessible resources online. Additionally, University of Miami hosts several trainings offered by the Biostatistics Collaboration and Consulting Core (BCCC) and the Biomedical Data Services at the Louis Calder Memorial Library. Biomedical Data Services: https://sp.library.miami.edu/subjects/biomedicaldata#tab-8 BCCC: https://www.publichealth.med.miami.edu/divisions/biostatistics/biostatistics-core/index.html Training videos from the University of Arizona: https://cb2.uahs.arizona.edu/services-tools/surveys-clinical-databases-redcap/redcap-video-tutorials
To gain access to a project, please contact your project administrator/PI so that they can add you to the project. If you are the administrator seeking access and your project is not an e-Consent project associated to a research study with FDA oversight, please complete the REDCap Form - User Right here.
Team members with a project administrative role have the ability to manage all aspects of a project including the addition and removal of team members. The only exception where Administrative rights are not permitted is for e-Consent projects associated to research studies with FDA oversight. The administration of the study team members for these projects is managed by the REDCap Administrator. To request Administrative rights for non-FDA e-Consent projects or to request team members to be added or removed for FDA e-Consent projects, please submit the User Matrix ServiceNow Form.
New project requests are initiated within the REDCap application by following the steps below: 1. Log into REDCap at REDCap.miami.edu 2. Click on the + New Project link (near the top of the site) for each project that you would like to request. 3. Complete the form and when you click on the blue “Create Project” button, the Decision Tree Survey will display in a pop up window to complete additional information regarding your project. 4. Complete the Decision Tree Survey and when you click Submit, a system generated email will be sent to the ServiceNow ticketing system, which will auto create a ServiceNow ticket for the fulfillment of your project request. All communications for your project request from the REDCap administrator will be performed via the auto generated ServiceNow ticket. You will receive an email with the ticket.
The Decision Treey Survey (DTS) is required for all projects. The DTS determines the eligibility of your project to be implemented in REDCap. This is a required step for your project to be eligible for REDCap, and all questions must be answered. Upon completing and submitting the DTS, an email is sent to the ServiceNow ticketing system and you will receive an autogenerated new project ticket for your submission. All communications regarding your project request will be via this ticket until fulfillment of you request is complete.
To add a variable: Click on the "Add Field" button, just above or below the area/section that you'd like to insert the new variable/field: To modify a variable: Click on the pencil icon for the field you wish to modify. Edit within the "Edit Field" pop up window Click on the Save button on the bottom right to commit the changes. To delete a variable: Click on the red "X" corresponding to the item that you wish to remove: Click on the Delete button on the "Delete Field" button of the pop-up window to confirm.



Navigate to My Projects to locate your project in REDCap. Click on the “Alerts & Notifications” link under the Applications section on the left. Click on the green "Add New Alert" button on the right Complete the Create New Aler form and click on the green “Save” button at the bottom to save / add the new alert.
You must have Administrator rights to alter privileges for other users, i.e. edit team members on projects. As best practice, this access is usually granted via the role of PI or system administrator. There are exceptions to granting Administrator rights to a project. As best practice, this access is usually granted via the role of PI or system administrator. There are exceptions to granting Administrator rights to a project. For more information on this please click here. To request Administrator rights you must complete and Submit the User Matrix ServiceNow form found here. Adding A Team Member: Removing a Team Member


When to move a project to production: All REDCap projects begin in Development mode. After the project is developed and tested thoroughly, the project must be moved to Production mode before collecting "real" data. Prior to moving a project to Production, it is recommended that testing is completed by simulating data collection. Changes to a project in Production should be kept to a minimum or ideally to none. Once a project is moved to Production, changes to the project may cause accidental deletion of collected data; therefore, changes must be reviewed and committed by the REDCap Administration team, which may take several business days. See “Can I make changes to a project after moved to production?” for more information. Moving a Project to Production: An email will be sent to the REDCap Administrative team who will work on your request to move your project to production or advise if anything further is needed.


Yes, a project can be moved back to development status to make the necessary changes such as revision to existing project instruments, addition of new instruments. To move a project from Production to Development, please contact the REDCap Administrative Team so that they can further assist. When making changes in production, REDCap offers built-in checks to safeguard against unintentional data loss caused by, for example, deleting a field, changing a field type, altering a multiple-choice option, rewording a field prompt. To make changes while in production, the project must be entered into draft mode, and the changes submitted for review when completed. There are some changes that will need to be reviewed and committed by the REDCap Administrator team. This is done to ensure your data is not adversely affected by the changes you are making. Process After Change After making the changes, it is highly recommended to click on the “View detailed summary of all drafted changes”, screenshot below, link which displays a preview of all the fields that are added, removed, and modified, and drawing attention to changes that could result in data corruption or deletion. Any changes in RED should be carefully reviewed. This table summarizes types of changes and possible impact. The changes that need to be carefully made and considered are to those fields where data already has been collected. When ready to submit changes, click the Submit Changes for Review button and then click Submit. As stated, there are changes that will need to be reviewed and committed by the REDCap Administration team to prevent undesirable changes or loss of data. Tips and recommendations for the following project changes:
Enter Draft Mode:





To initiate a copy request, please follow the steps below: Once the above steps have been completed, a request will be sent to our team, and if needed, our team will send a decision tree survey for you to submit.








Another way to backup your project’s data is by navigating to the “Data Exports, Reports, and Stats” link under the Applications section on the left, click Export Data, and select the desired data format option to export.

















Please submit a ticket to help@med.miami.edu, and be sure to include the word “REDCap” as part of the email Subject line. When the email is sent, a ServiceNow ticket will auto generate and will get triaged to a REDCap system administrator. Examples of consultation, but not limited to are the following:
Our infrastructure currently support files attachments up to 512MB in size. If you need additional support regarding these limitation, please submit a support request via ServiceNow so we can discuss options available.
Our Research Support Helpdesk is here to help:
Monday - Friday
8:00 AM - 5:00 PM
305-243-2314Submit Request