HIPAA Compliance Helper for Contact Form 7

Description

Adds HIPAA technical safeguards to Contact Form 7: encrypted storage, no PHI in email, encrypted file uploads, an MFA-gated viewer and a tamper-evident audit log.

This plugin helps administrators protect Contact Form 7 submissions while keeping the existing form workflow intact.

What it does

Interception
Runs before CF7 sends mail. Protects every CF7 form by default (or only the forms you choose).

Fails closed
If HTTPS, the encryption key, storage or the write fails, the submission is aborted and nothing is emailed or stored.

No PHI in email
Staff notice contains only a form name, a short reference and a sign-in link. Attachments, Reply-To and answer-echoing tags are stripped. The patient auto-reply (Mail 2) is disabled by default, or replaced with a generic message.

Encrypted storage
Entries are encrypted with libsodium XChaCha20-Poly1305 (authenticated encryption) into wp_cf7_hipaa_entries. Each ciphertext is bound to its entry ID and form ID, so rows cannot be swapped undetected.

Key management
The master key must be defined in wp-config.php. There is no auto-generated fallback key stored in the database. Sub-keys are derived per purpose. Key IDs and CF7_HIPAA_PREVIOUS_KEYS support rotation, and a “Re-encrypt” action migrates entries and files.

Encrypted attachments
Files are encrypted in 64 KB authenticated chunks (truncation, reordering and tampering are detected), stored outside the web root when the host allows it, and delivered only through an authenticated, audited proxy. Original file names live only inside the ciphertext.

MFA step-up
Built-in TOTP (any authenticator app) with replay protection, 5-attempt lockout, single-use recovery codes, and unlock tied to the login session. Secrets are stored encrypted. Sites that already enforce MFA can switch to an attested “external” mode.

Automatic logoff
Server-side idle check plus a client-side timer that signs out and blanks the screen (5 to 60 minutes, default 15).

Tamper-evident audit log
Every view, download, delete, login-step, settings change and blocked submission is recorded in an HMAC hash chain, with an off-database checkpoint. A “Verify integrity” button walks the chain. CSV export. Contains no PHI.

Roles
HIPAA Reviewer can view entries. Only administrators can delete, change settings, view the audit log or reset MFA.

Security Setup screen
Detects common PHI leaks around the plugin: Flamingo and other submission-storing plugins, Akismet on protected forms, missing key, non-HTTPS, storage inside the web root, WP_DEBUG_LOG, users without MFA.

Retention
Optional automatic deletion after N days.

Disclaimer

This plugin provides technical safeguards that may assist with HIPAA-related security work. Installing, configuring, or using it does not make an organization HIPAA compliant. Organizations must perform their own legal, administrative, and technical assessment and maintain all required policies, procedures, agreements, and controls.

Requirements

  • WordPress 5.9 or later.
  • Contact Form 7.
  • PHP 7.4 or later.
  • The PHP Sodium extension (or the Sodium implementation available through the supported WordPress environment).
  • HTTPS for production use and protected administrative access.

Configuration

The encryption key must be a securely generated 32-byte key represented as 64 hexadecimal characters. Keep a protected backup of the key. Losing it makes encrypted data unrecoverable.

wp-config.php constants
CF7_HIPAA_ENCRYPTION_KEY (Required) – Base64 of 32 random bytes.

CF7_HIPAA_PREVIOUS_KEYS – Array of older keys, kept so old entries and audit history stay readable after rotation.

CF7_HIPAA_STORAGE_DIR – Absolute path for encrypted files, ideally outside the web root.

CF7_HIPAA_TRUSTED_IP_HEADER – e.g. ‘HTTP_CF_CONNECTING_IP’. Only set if your proxy overwrites that header, otherwise it can be spoofed.

CF7_HIPAA_REMOVE_DATA_ON_UNINSTALL – true to delete all tables and files on uninstall. Default: delete nothing.

CF7_HIPAA_ALLOW_INSECURE – Development only. Disables the HTTPS requirement. Never set in production.

Privacy and data

Submission fields and uploaded files are stored locally in encrypted form. Audit records may include administrator IDs, actions, timestamps, IP addresses, and user-agent information. The plugin does not send submission data to a third-party service.

Deactivating the plugin does not delete stored data. Uninstalling also preserves data by default; an explicit configuration constant is required before a site owner chooses to remove plugin data. Make backups and document retention decisions before changing that behavior.

Key rotation

  • Generate a new key. Set it as CF7_HIPAA_ENCRYPTION_KEY.
  • Move the old key into CF7_HIPAA_PREVIOUS_KEYS: define( 'CF7_HIPAA_PREVIOUS_KEYS', array( 'old-key' ) );
  • Security Setup – Re-encrypt. Repeat until none remain.
  • Keep the old key listed: earlier audit-log events were signed with it, and integrity verification needs it. Entries stay readable without it once re-encrypted.

HOOKS

  • cf7_hipaa_audit_logged (action): receives each audit row. Forward to syslog/SIEM for stronger tamper resistance.
  • cf7_hipaa_transport_secure (filter): tell the plugin a request is secure when TLS ends at a proxy WordPress cannot see.
  • cf7_hipaa_external_mfa_satisfied (filter): verify your own MFA in “external” mode.
  • cf7_hipaa_risky_plugins (filter): extend the list of submission-copying plugins to flag.

How it maps to the HIPAA Security Rule (45 CFR 164.312)

This shows what each feature supports. It is not a claim of compliance.

Access control (a)(1): unique user ID, automatic logoff, encryption, WordPress accounts, roles/capabilities, idle logoff, encryption at rest.

Audit controls (b): Hash-chained audit log, integrity verification, export.

Integrity (c)(1): Authenticated encryption for entries and files, chain-verified log.

Person or entity authentication (d): TOTP MFA with replay protection and lockout.

Transmission security (e)(1): HTTPS enforcement at the WordPress layer, no PHI in email.

What this plugin cannot do

  • It cannot make your host, backups, email provider or other plugins compliant. Software cannot verify BAAs, risk analyses, policies, training or breach procedures. Security Setup lists these as manual items.
  • It only controls CF7’s own mail and storage. Other CF7 add-ons (CRMs, webhooks, Zapier, Google Sheets, “save to DB” plugins) that hook into submissions still receive the full data. Security Setup flags known ones but cannot see them all.
  • “Tamper-evident”, not “immutable”. Someone holding both the database and the encryption key can rewrite the log undetected. Forward events off-site (cf7_hipaa_audit_logged) and restrict database privileges where your host allows.
  • The unlock check happens in WordPress. A compromised server or a malicious administrator with code execution can bypass it.
  • Loss of the key means loss of the data. That is by design.
  • No QR code is drawn during MFA setup. It would require sending the secret to a third party or bundling a library. Authenticator apps accept the setup key directly.
  • Analytics, chat widgets, ad pixels and caching on form pages are outside this plugin’s control.

About BAAs

A self-hosted plugin that never touches your customers’ data generally does not by itself make its author a business associate, and this plugin has no telemetry or remote access. If you later offer hosting, managed service or support with admin access, that changes. Have a healthcare attorney review your terms.

External services

This plugin does not transmit submission data, files, or audit records to external services. Its health check uses a loopback request to the same WordPress installation.

Installation

  1. Install and activate Contact Form 7.
  2. Upload the plugin to /wp-content/plugins/hipaa-compliance-helper-for-contact-form-7/ or install it from the WordPress Plugins screen.
  3. Activate the plugin.
  4. Define CF7_HIPAA_ENCRYPTION_KEY in wp-config.php before storing protected submissions.
  5. Open HIPAA Entries > Security Setup and complete the setup checks.

FAQ

Does this plugin make my site HIPAA compliant?

No. It supplies selected technical safeguards only. Compliance depends on the organization’s complete legal, administrative, physical, and technical controls.

Does the plugin use an external service?

No third-party service is required. The health screen may make a loopback request to the same WordPress site to check the protected storage endpoint.

What happens if I lose the encryption key?

Protected submissions and files cannot be decrypted. Store the key in a secure secrets-management or backup process appropriate for the site.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“HIPAA Compliance Helper for Contact Form 7” is open source software. The following people have contributed to this plugin.

Contributors

Changelog

0.0.1

  • Initial public release.