Title: HIPAA Compliance Helper for Contact Form 7
Author: mjplugins26
Published: <strong>October 6, 2026</strong>
Last modified: October 6, 2026

---

Search plugins

![](https://s.w.org/plugins/geopattern-icon/hipaa-compliance-helper-for-contact-
form-7.svg)

# HIPAA Compliance Helper for Contact Form 7

 By [mjplugins26](https://profiles.wordpress.org/mjplugins26/)

[Download](https://downloads.wordpress.org/plugin/hipaa-compliance-helper-for-contact-form-7.0.0.1.zip)

 * [Details](https://wordpress.org/plugins/hipaa-compliance-helper-for-contact-form-7/#description)
 * [Reviews](https://wordpress.org/plugins/hipaa-compliance-helper-for-contact-form-7/#reviews)
 *  [Installation](https://wordpress.org/plugins/hipaa-compliance-helper-for-contact-form-7/#installation)
 * [Development](https://wordpress.org/plugins/hipaa-compliance-helper-for-contact-form-7/#developers)

 [Support](https://wordpress.org/support/plugin/hipaa-compliance-helper-for-contact-form-7/)

## Description

Adds HIPAA technical safeguards to Contact Form 7: encrypted storage, no PHI in 
email, encrypted file uploads, an MFA-gated viewer and a tamper-evident audit log.

This plugin helps administrators protect Contact Form 7 submissions while keeping
the existing form workflow intact.

### What it does

**Interception**
 Runs before CF7 sends mail. Protects every CF7 form by default(
or only the forms you choose).

**Fails closed**
 If HTTPS, the encryption key, storage or the write fails, the 
submission is **aborted** and nothing is emailed or stored.

**No PHI in email**
 Staff notice contains only a form name, a short reference and
a sign-in link. Attachments, `Reply-To` and answer-echoing tags are stripped. The
patient auto-reply (Mail 2) is disabled by default, or replaced with a generic message.

**Encrypted storage**
 Entries are encrypted with libsodium **XChaCha20-Poly1305**(
authenticated encryption) into `wp_cf7_hipaa_entries`. Each ciphertext is bound 
to its entry ID and form ID, so rows cannot be swapped undetected.

**Key management**
 The master key **must** be defined in `wp-config.php`. There
is no auto-generated fallback key stored in the database. Sub-keys are derived per
purpose. Key IDs and `CF7_HIPAA_PREVIOUS_KEYS` support rotation, and a “Re-encrypt”
action migrates entries and files.

**Encrypted attachments**
 Files are encrypted in 64 KB authenticated chunks (truncation,
reordering and tampering are detected), stored outside the web root when the host
allows it, and delivered only through an authenticated, audited proxy. Original 
file names live only inside the ciphertext.

**MFA step-up**
 Built-in TOTP (any authenticator app) with replay protection, 5-
attempt lockout, single-use recovery codes, and unlock tied to the login session.
Secrets are stored encrypted. Sites that already enforce MFA can switch to an attested“
external” mode.

**Automatic logoff**
 Server-side idle check plus a client-side timer that signs
out and blanks the screen (5 to 60 minutes, default 15).

**Tamper-evident audit log**
 Every view, download, delete, login-step, settings
change and blocked submission is recorded in an HMAC hash chain, with an off-database
checkpoint. A “Verify integrity” button walks the chain. CSV export. Contains no
PHI.

**Roles**
 HIPAA Reviewer can view entries. Only administrators can delete, change
settings, view the audit log or reset MFA.

**Security Setup screen**
 Detects common PHI leaks _around_ the plugin: Flamingo
and other submission-storing plugins, Akismet on protected forms, missing key, non-
HTTPS, storage inside the web root, `WP_DEBUG_LOG`, users without MFA.

**Retention**
 Optional automatic deletion after N days.

### Disclaimer

This plugin provides technical safeguards that may assist with HIPAA-related security
work. Installing, configuring, or using it does not make an organization HIPAA compliant.
Organizations must perform their own legal, administrative, and technical assessment
and maintain all required policies, procedures, agreements, and controls.

### Requirements

 * WordPress 5.9 or later.
 * Contact Form 7.
 * PHP 7.4 or later.
 * The PHP Sodium extension (or the Sodium implementation available through the 
   supported WordPress environment).
 * HTTPS for production use and protected administrative access.

### Configuration

The encryption key must be a securely generated 32-byte key represented as 64 hexadecimal
characters. Keep a protected backup of the key. Losing it makes encrypted data unrecoverable.

**wp-config.php constants**
 CF7_HIPAA_ENCRYPTION_KEY (Required) – Base64 of 32 
random bytes.

CF7_HIPAA_PREVIOUS_KEYS – Array of older keys, kept so old entries and audit history
stay readable after rotation.

CF7_HIPAA_STORAGE_DIR – Absolute path for encrypted files, ideally outside the web
root.

CF7_HIPAA_TRUSTED_IP_HEADER – e.g. ‘HTTP_CF_CONNECTING_IP’. Only set if your proxy
overwrites that header, otherwise it can be spoofed.

CF7_HIPAA_REMOVE_DATA_ON_UNINSTALL – true to delete all tables and files on uninstall.
Default: delete nothing.

CF7_HIPAA_ALLOW_INSECURE – Development only. Disables the HTTPS requirement. Never
set in production.

### Privacy and data

Submission fields and uploaded files are stored locally in encrypted form. Audit
records may include administrator IDs, actions, timestamps, IP addresses, and user-
agent information. The plugin does not send submission data to a third-party service.

Deactivating the plugin does not delete stored data. Uninstalling also preserves
data by default; an explicit configuration constant is required before a site owner
chooses to remove plugin data. Make backups and document retention decisions before
changing that behavior.

### Key rotation

 * Generate a new key. Set it as `CF7_HIPAA_ENCRYPTION_KEY`.
 * Move the old key into `CF7_HIPAA_PREVIOUS_KEYS`: `define( 'CF7_HIPAA_PREVIOUS_KEYS',
   array( 'old-key' ) );`
 * Security Setup – **Re-encrypt**. Repeat until none remain.
 * **Keep the old key listed**: earlier audit-log events were signed with it, and
   integrity verification needs it. Entries stay readable without it once re-encrypted.

### HOOKS

 * cf7_hipaa_audit_logged (action): receives each audit row. Forward to syslog/SIEM
   for stronger tamper resistance.
 * cf7_hipaa_transport_secure (filter): tell the plugin a request is secure when
   TLS ends at a proxy WordPress cannot see.
 * cf7_hipaa_external_mfa_satisfied (filter): verify your own MFA in “external” 
   mode.
 * cf7_hipaa_risky_plugins (filter): extend the list of submission-copying plugins
   to flag.

### How it maps to the HIPAA Security Rule (45 CFR 164.312)

This shows what each feature supports. It is not a claim of compliance.

**Access control (a)(1):** unique user ID, automatic logoff, encryption, WordPress
accounts, roles/capabilities, idle logoff, encryption at rest.

**Audit controls (b):** Hash-chained audit log, integrity verification, export.

**Integrity (c)(1):** Authenticated encryption for entries and files, chain-verified
log.

**Person or entity authentication (d):** TOTP MFA with replay protection and lockout.

**Transmission security (e)(1):** HTTPS enforcement at the WordPress layer, no PHI
in email.

### What this plugin cannot do

 * **It cannot make your host, backups, email provider or other plugins compliant.**
   Software cannot verify BAAs, risk analyses, policies, training or breach procedures.
   Security Setup lists these as manual items.
 * **It only controls CF7’s own mail and storage.** Other CF7 add-ons (CRMs, webhooks,
   Zapier, Google Sheets, “save to DB” plugins) that hook into submissions still
   receive the full data. Security Setup flags known ones but cannot see them all.
 * **“Tamper-evident”, not “immutable”.** Someone holding both the database and 
   the encryption key can rewrite the log undetected. Forward events off-site (`
   cf7_hipaa_audit_logged`) and restrict database privileges where your host allows.
 * **The unlock check happens in WordPress.** A compromised server or a malicious
   administrator with code execution can bypass it.
 * **Loss of the key means loss of the data.** That is by design.
 * **No QR code** is drawn during MFA setup. It would require sending the secret
   to a third party or bundling a library. Authenticator apps accept the setup key
   directly.
 * **Analytics, chat widgets, ad pixels and caching** on form pages are outside 
   this plugin’s control.

### About BAAs

A self-hosted plugin that never touches your customers’ data generally does not 
by itself make its author a business associate, and this plugin has no telemetry
or remote access. If you later offer hosting, managed service or support with admin
access, that changes. Have a healthcare attorney review your terms.

### External services

This plugin does not transmit submission data, files, or audit records to external
services. Its health check uses a loopback request to the same WordPress installation.

## Installation

 1. Install and activate Contact Form 7.
 2. Upload the plugin to `/wp-content/plugins/hipaa-compliance-helper-for-contact-form-
    7/` or install it from the WordPress Plugins screen.
 3. Activate the plugin.
 4. Define `CF7_HIPAA_ENCRYPTION_KEY` in `wp-config.php` before storing protected submissions.
 5. Open `HIPAA Entries > Security Setup` and complete the setup checks.

## FAQ

### Does this plugin make my site HIPAA compliant?

No. It supplies selected technical safeguards only. Compliance depends on the organization’s
complete legal, administrative, physical, and technical controls.

### Does the plugin use an external service?

No third-party service is required. The health screen may make a loopback request
to the same WordPress site to check the protected storage endpoint.

### What happens if I lose the encryption key?

Protected submissions and files cannot be decrypted. Store the key in a secure secrets-
management or backup process appropriate for the site.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“HIPAA Compliance Helper for Contact Form 7” is open source software. The following
people have contributed to this plugin.

Contributors

 *   [ mjplugins26 ](https://profiles.wordpress.org/mjplugins26/)

[Translate “HIPAA Compliance Helper for Contact Form 7” into your language.](https://translate.wordpress.org/projects/wp-plugins/hipaa-compliance-helper-for-contact-form-7)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/hipaa-compliance-helper-for-contact-form-7/),
check out the [SVN repository](https://plugins.svn.wordpress.org/hipaa-compliance-helper-for-contact-form-7/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/hipaa-compliance-helper-for-contact-form-7/)
by [RSS](https://plugins.trac.wordpress.org/log/hipaa-compliance-helper-for-contact-form-7/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 0.0.1

 * Initial public release.

## Meta

 *  Version **0.0.1**
 *  Last updated **2 days ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 5.9 or higher **
 *  Tested up to **7.1.3**
 *  PHP version ** 7.4 or higher **
 * Tags
 * [contact form 7](https://wordpress.org/plugins/tags/contact-form-7/)[encryption](https://wordpress.org/plugins/tags/encryption/)
   [privacy](https://wordpress.org/plugins/tags/privacy/)[security](https://wordpress.org/plugins/tags/security/)
 *  [Advanced View](https://wordpress.org/plugins/hipaa-compliance-helper-for-contact-form-7/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/hipaa-compliance-helper-for-contact-form-7/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/hipaa-compliance-helper-for-contact-form-7/reviews/)

## Contributors

 *   [ mjplugins26 ](https://profiles.wordpress.org/mjplugins26/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/hipaa-compliance-helper-for-contact-form-7/)