QR codes for healthcare
Privacy by design: no PHI in the QR payload, raw IPs never stored (keyed HMAC-SHA-256), bot traffic excluded, and automatic plan-based purging. HIPAA-aware use is a customer responsibility — QRCode Suite is not a HIPAA business associate and does not sign BAAs, so keep PHI out of payloads and destinations and verify your setup with your compliance counsel.
Clinic intake forms
A QR in the waiting room or on appointment confirmation links to your intake form. Patients complete on their own phone — no shared clipboards. Authenticated submission required.
Prescription instructions
A QR on prescription labels links to the patient leaflet, dosing instructions, and contraindications — translated to the patient's language.
Multilingual patient leaflets
Conditional redirects route by phone language, so a single QR on every leaflet serves the right translation automatically.
Post-discharge follow-up
A QR on discharge paperwork links to follow-up appointment booking, symptom-check forms, and care-instruction videos.
How it works
- 1
Generate QRs that point to short URLs
Each QR encodes only a short redirect — no patient data in the QR itself. Sensitive destinations sit behind authentication.
- 2
Print on labels, signage, or paperwork
Export at high contrast for label printers and discharge paperwork. Codes work on phone cameras at typical patient distances.
- 3
Check the retention window and gate access
Analytics retention is enforced automatically by your plan — 30 days on Free, 12 months on Pro, 24 months on Business, 36 months on Agency. Check that window against your record-keeping obligations, and gate sensitive destinations behind an authenticated patient portal (WordPress capabilities, SSO, or your own).
Frequently asked questions
How does QRCode Suite handle IP addresses?
QRCode Suite never stores raw IP addresses. Before any scan event is recorded, the IP is put through an HMAC-SHA-256 hash keyed by a deployment secret, and only that hash is written. The original IP cannot be recovered from it.
Does QRCode Suite filter bot traffic?
Yes. Scans are matched against 26 known bot, crawler, scraper and link-preview user-agent patterns. Matching scans are flagged as bot traffic, excluded from your reported counts, and never forwarded to integrations or webhooks.
Is QRCode Suite compliant with GDPR?
QRCode Suite is built with GDPR in mind: raw IP addresses are never stored, only a keyed hash; bot traffic is filtered out; scan events are purged automatically once your plan retention window elapses; and nothing is forwarded to a third-party platform unless you connect it. Consult your legal team for your specific compliance obligations.
How long is scan data kept?
Retention is enforced automatically per plan — 30 days on Free, 12 months on Pro, 24 months on Business, 36 months on Agency. A background job purges events past that window, so old scan data does not accumulate.
Does QRCode Suite use tracking cookies?
No advertising or cross-site tracking cookies are set. Scan analytics are recorded server-side from the redirect itself, using a hashed IP and a hashed session value rather than a persistent identifier.
Start tracking your QR codes for free
No credit card required. 3 dynamic QR codes, scan analytics, and a Link Hub on the free plan.