Clinical Research Technology Built for Federal Standards
Federal research teams need a platform that satisfies their security reviewers and still fits how they actually run studies. OpenClinica is pursuing FedRAMP certification so you don’t have to trade one for the other.
Where we are today: OpenClinica LLC is pursuing FedRAMP certification for the OpenClinica cloud platform, working with A-LIGN, a FedRAMP-recognized independent assessment service. Our FedRAMP ID is pending. We’re publishing our scope, security documentation, and contacts now so federal teams can start evaluating us in parallel.
FedRAMP at a Glance
Scope: five services are in boundary for our FedRAMP certification work — Electronic Data Capture (EDC), eConsent, eCOA, Reporting & Analytics, and API Access. Each is categorized Moderate — Class C.
Visit the Trust Center →Built for the Teams Running Federally Funded Research
Federal research runs on the same clinical workflows as everyone else’s, with tighter compliance requirements layered on top. These are the groups our federal offering is aimed at.
Federal Agencies
Agencies and their programs running or sponsoring clinical studies, including CDC, NIH, HHS, FDA, VA, and DoD. Bring your security and privacy reviewers the documentation they need up front.
Federal Health Contractors
Contract-vehicle holders and boutique federal health firms who need a compliant clinical data capability they can include in a proposal without building and authorizing their own electronic data capture (EDC) system.
Consultants and Advocacy Groups
Third-party consultants, clinical advocacy organizations, and advisory firms supporting federal or federally adjacent research programs.
Coordinating Centers and Academic Sites
Data and statistical coordinating centers, academic medical centers, and research support organizations standardizing on one platform across a portfolio of federally funded studies.
The eClinical Workflow Your Study Runs On
Federal teams work in OpenClinica the way our other research customers do. These five services are in boundary for our FedRAMP certification work, each categorized Moderate — Class C.
Electronic Data Capture (EDC)
Core study build and data collection. Design forms with drag-and-drop, set real-time edit checks and role-based permissions, and change your study when the protocol changes — without waiting on a vendor ticket. Every change carries an audit trail.
eConsent
Electronic informed consent for remote, in-person, and hybrid enrollment, with secure e-signatures and a documented consent trail.
eCOA
Electronic clinical outcome assessments — mobile patient-reported outcomes and symptom tracking, with automated participant reminders.
Reporting & Analytics
Real-time dashboards and exportable, submission-ready data with complete audit trails.
API Access (REST/SOAP)
Programmatic access to study metadata, subject data, and event data for integration with external systems.
Our Security Program Didn’t Start With FedRAMP
Independent auditors have assessed our security controls against commercial and health-sector standards for years. FedRAMP is the newest standard we’re taking them through.
- SOC 2 Type II — third-party audit report on our security controls
- ISO/IEC 27001 — certified against both the 2013 and 2022 standards
- NHS Data Security and Protection Toolkit — UK health data handling
- WCAG / VPAT accessibility conformance reporting — how the platform measures against the Web Content Accessibility Guidelines, documented in a Voluntary Product Accessibility Template
- Regulatory Support Package for OpenClinica 4 — manual traceability matrix, notes to file, and release plans, for customers operating under GxP (good practice) regulatory requirements
- Named information security policies — covering data backup and restoration, remote access, and removable media handling, with additional policies available on request
OpenClinica runs as Software-as-a-Service on AWS public cloud infrastructure.
These certifications cover the OpenClinica platform. Related products, including Recruit and BuildClinical, maintain their own supporting compliance documentation.
See the Documentation for Yourself
Every certification above lives in our Trust Center at trust.openclinica.com, alongside our policy overviews. All of it is public — view or download it without an account.
Getting to a private document
For documents we keep private, such as detailed audit and penetration test reports, click Get Access on the page and submit your name, work email, and company. Verify your email and we’ll grant access to the materials you requested.
Questions about our security program, or trouble getting to a document? Email trust@openclinica.com.
What FedRAMP Certification Will Mean for Your Program
FedRAMP — the Federal Risk and Authorization Management Program — is the U.S. government’s standardized security assessment for cloud services. A platform earns it by passing an independent assessment against a strict federal control baseline.
A shorter path through security review
Your reviewers work from a federal baseline they already know instead of a vendor review from scratch.
Health data held to a federal standard
Encryption, access control, monitoring, and continuous oversight — applied to some of the most sensitive data a federal program handles.
Contract eligibility
Many federal programs can only use a cloud service that holds FedRAMP certification.
Add a Clinical Research Platform to Your Federal Proposals
Federal health contractors and coordinating centers win work on their agency relationships and delivery expertise, not on building and authorizing an EDC. OpenClinica gives you the clinical research technology to include in NIH, CDC, VA, FDA, and DoD pursuits while you keep the prime relationship and the services scope.
Talk to us about:
- Security and compliance documentation for your proposal response
- Solution design and federal sales engineering support
- Proposal language and architecture materials
- Teaming and subcontractor agreements
- A demonstration environment
- Registered opportunity protection
- Support for agency demonstrations and technical evaluations
Patient Recruitment — Available as a Separate Offering
Recruit brings targeted digital advertising, custom study landing pages, and participant pre-screening together to accelerate enrollment, with real-time visibility into recruitment activity.
Recruit is a separate, supplemental offering. Tell us how your program is set up and we’ll walk through the options with you.
FedRAMP Marketplace Listing Details
OpenClinica is a Software-as-a-Service (SaaS) eClinical platform that centralizes clinical trial technology for electronic data capture (EDC), eConsent, eCOA (electronic clinical outcome assessments), and reporting and analytics. OpenClinica is hosted on AWS as a Public Cloud deployment. The platform serves academic institutions, pharmaceutical, biotech and medtech sponsors, and contract research organizations (CROs) running clinical trials, including federally funded research studies.
| Provider | OpenClinica LLC |
|---|---|
| FedRAMP ID | Pending |
| Service Model | SaaS |
| Deployment Model | Public Cloud |
| Business Category | Health & Wellness, Research, Data Management, Analytics |
| UEI Number | VJWGYQDM2X28 |
| Sales Contact | Daniel Johnson — djohnson@openclinica.com, 617-729-2650 |
| Security Contact | Ted Gilbert, Head of Compliance and Data Protection Officer — privacy@openclinica.com |
| Product Website | openclinica.com/fedramp |
| Product Logo | ![]() |
| Services In Boundary | Electronic Data Capture (EDC), eConsent, eCOA, Reporting & Analytics, and API Access (REST/SOAP) |
| Security Category | Moderate — Class C, for all in-boundary services. Services outside the authorization boundary are identified in our submitted FedRAMP listing. |
| Secure Configuration Guidance | FedRAMP Secure Configuration Guidance |
| Trust Center | trust.openclinica.com |
| Independent Assessment Service | A-LIGN (FedRAMP assessor ID 138665) |
| Next Ongoing Certification Report Date | Not applicable — initial FedRAMP certification is not yet complete |
Let’s Talk About Your Federal Study
Tell us what you’re running and what your compliance requirements look like, and we’ll walk you through how OpenClinica fits.
Request a Quote →Or email us directly at djohnson@openclinica.com. Security questions go to privacy@openclinica.com.
