Adds HIPAA technical safeguards to Contact Form 7: encrypted storage, no PHI in email, encrypted file uploads, an MFA-gated viewer and a tamper-evident audit log.
This plugin helps administrators protect Contact Form 7 submissions while keeping the existing form workflow intact.
Interception
Runs before CF7 sends mail. Protects every CF7 form by default (or only the forms you choose).
Fails closed
If HTTPS, the encryption key, storage or the write fails, the submission is aborted and nothing is emailed or stored.
No PHI in email
Staff notice contains only a form name, a short reference and a sign-in link. Attachments, Reply-To and answer-echoing tags are stripped. The patient auto-reply (Mail 2) is disabled by default, or replaced with a generic message.
Encrypted storage
Entries are encrypted with libsodium XChaCha20-Poly1305 (authenticated encryption) into wp_cf7_hipaa_entries. Each ciphertext is bound to its entry ID and form ID, so rows cannot be swapped undetected.
Key management
The master key must be defined in wp-config.php. There is no auto-generated fallback key stored in the database. Sub-keys are derived per purpose. Key IDs and CF7_HIPAA_PREVIOUS_KEYS support rotation, and a “Re-encrypt” action migrates entries and files.
Encrypted attachments
Files are encrypted in 64 KB authenticated chunks (truncation, reordering and tampering are detected), stored outside the web root when the host allows it, and delivered only through an authenticated, audited proxy. Original file names live only inside the ciphertext.
MFA step-up
Built-in TOTP (any authenticator app) with replay protection, 5-attempt lockout, single-use recovery codes, and unlock tied to the login session. Secrets are stored encrypted. Sites that already enforce MFA can switch to an attested “external” mode.
Automatic logoff
Server-side idle check plus a client-side timer that signs out and blanks the screen (5 to 60 minutes, default 15).
Tamper-evident audit log
Every view, download, delete, login-step, settings change and blocked submission is recorded in an HMAC hash chain, with an off-database checkpoint. A “Verify integrity” button walks the chain. CSV export. Contains no PHI.
Roles
HIPAA Reviewer can view entries. Only administrators can delete, change settings, view the audit log or reset MFA.
Security Setup screen
Detects common PHI leaks around the plugin: Flamingo and other submission-storing plugins, Akismet on protected forms, missing key, non-HTTPS, storage inside the web root, WP_DEBUG_LOG, users without MFA.
Retention
Optional automatic deletion after N days.
This plugin provides technical safeguards that may assist with HIPAA-related security work. Installing, configuring, or using it does not make an organization HIPAA compliant. Organizations must perform their own legal, administrative, and technical assessment and maintain all required policies, procedures, agreements, and controls.
The encryption key must be a securely generated 32-byte key represented as 64 hexadecimal characters. Keep a protected backup of the key. Losing it makes encrypted data unrecoverable.
wp-config.php constants
CF7_HIPAA_ENCRYPTION_KEY (Required) – Base64 of 32 random bytes.
CF7_HIPAA_PREVIOUS_KEYS – Array of older keys, kept so old entries and audit history stay readable after rotation.
CF7_HIPAA_STORAGE_DIR – Absolute path for encrypted files, ideally outside the web root.
CF7_HIPAA_TRUSTED_IP_HEADER – e.g. ‘HTTP_CF_CONNECTING_IP’. Only set if your proxy overwrites that header, otherwise it can be spoofed.
CF7_HIPAA_REMOVE_DATA_ON_UNINSTALL – true to delete all tables and files on uninstall. Default: delete nothing.
CF7_HIPAA_ALLOW_INSECURE – Development only. Disables the HTTPS requirement. Never set in production.
Submission fields and uploaded files are stored locally in encrypted form. Audit records may include administrator IDs, actions, timestamps, IP addresses, and user-agent information. The plugin does not send submission data to a third-party service.
Deactivating the plugin does not delete stored data. Uninstalling also preserves data by default; an explicit configuration constant is required before a site owner chooses to remove plugin data. Make backups and document retention decisions before changing that behavior.
CF7_HIPAA_ENCRYPTION_KEY.CF7_HIPAA_PREVIOUS_KEYS: define( 'CF7_HIPAA_PREVIOUS_KEYS', array( 'old-key' ) );This shows what each feature supports. It is not a claim of compliance.
Access control (a)(1): unique user ID, automatic logoff, encryption, WordPress accounts, roles/capabilities, idle logoff, encryption at rest.
Audit controls (b): Hash-chained audit log, integrity verification, export.
Integrity (c)(1): Authenticated encryption for entries and files, chain-verified log.
Person or entity authentication (d): TOTP MFA with replay protection and lockout.
Transmission security (e)(1): HTTPS enforcement at the WordPress layer, no PHI in email.
cf7_hipaa_audit_logged) and restrict database privileges where your host allows.A self-hosted plugin that never touches your customers’ data generally does not by itself make its author a business associate, and this plugin has no telemetry or remote access. If you later offer hosting, managed service or support with admin access, that changes. Have a healthcare attorney review your terms.
This plugin does not transmit submission data, files, or audit records to external services. Its health check uses a loopback request to the same WordPress installation.