Vulnerability Disclosure
If you believe you have identified a security vulnerability affecting a HealthVerity-owned system or service, please report it by emailing security@healthverity.com. If your report involves an active compromise, suspected unauthorized access, exposed credentials, or potentially exposed sensitive information, please mark the subject line as urgent.
Please do not use this process for customer support requests, privacy inquiries, account access issues, or general product feedback.
Report a Security Vulnerability
To help us evaluate your report efficiently, please provide as much of the following information as possible:
- The affected website, application, service, endpoint, or system
- A description of the potential vulnerability
- The steps required to reproduce the issue
- The potential security impact
- Relevant URLs, request and response details, screenshots, or proof-of-concept material
- Any conditions required to reproduce the issue
- Your name and preferred contact information, unless you wish to report anonymously
Please do not include sensitive personal information, protected health information, customer data, authentication credentials, or data belonging to other individuals in your submission.
If you inadvertently access such information while investigating a potential vulnerability, stop immediately, do not view, copy, store, or share it further, and note this in your report so we can address it appropriately.
Scope
This disclosure process is intended for potential security vulnerabilities affecting internet-accessible systems and services owned or operated by HealthVerity.
Examples may include:
- HealthVerity-owned websites and web applications
- Publicly accessible HealthVerity application programming interfaces
- Authentication and authorization issues
- Exposure of sensitive information
- Security configuration issues
- Vulnerabilities that could affect the confidentiality, integrity, or availability of HealthVerity systems or data
The following activities are not authorized under this policy:
- Denial-of-service, resource-exhaustion, or other testing that could degrade or disrupt production systems
- Social engineering, phishing, or physical security testing directed at HealthVerity personnel, facilities, or offices
- Testing against systems, applications, or services owned or operated by third parties, including customer environments, vendor platforms, and hosted infrastructure not controlled by HealthVerity
- Accessing, modifying, copying, or exfiltrating data beyond what is strictly necessary to demonstrate a vulnerability
- Automated scanning at a volume or intensity that could impact system availability, without prior coordination with our Security Team
Safe Harbor
HealthVerity considers security research conducted in good faith and in accordance with this policy to be authorized. We will not pursue civil or criminal legal action, or report you to law enforcement, for accidental, good-faith violations of this policy.
This safe harbor applies only to research that stays within the scope defined above, avoids privacy violations, service degradation, and data destruction, is conducted only against your own accounts or designated test accounts, and is reported to us promptly through the process described on this page.
If a third party initiates legal action against a researcher who acted in good faith and in compliance with this policy, HealthVerity will take steps to make it known that the research was authorized.
What You Can Expect From Us
After receiving a vulnerability report, HealthVerity will make a reasonable effort to:
- Acknowledge receipt of the report, typically within five business days.
- Review the information and determine whether additional details are required.
- Validate and assess the potential security impact.
- Work with the appropriate internal teams to address confirmed vulnerabilities.
- Provide status updates when appropriate and reasonably possible.
- Notify the reporter when the issue has been resolved or otherwise closed, when appropriate.
The time required to investigate or remediate an issue will vary depending on its complexity, severity, affected systems, and required changes.
Submitting a report does not create a contractual relationship, employment relationship, partnership, or obligation between the reporter and HealthVerity.
Rewards and Compensation
HealthVerity does not currently operate a paid bug-bounty program.
We do not promise payment, rewards, gifts, public recognition, or other compensation for vulnerability reports. Researchers should not submit invoices or make payment a condition of disclosing vulnerability information.
Any future decision to provide recognition or compensation would be made solely at HealthVerity’s discretion and would not establish an ongoing obligation.
Coordinated Disclosure
Please keep information about a potential vulnerability confidential while HealthVerity investigates and, where necessary, remediates the issue.
Do not publicly disclose the vulnerability, publish proof-of-concept material, or share affected data before receiving written authorization from HealthVerity or before a mutually agreed disclosure date.
HealthVerity may need additional time when remediation involves complex systems, third-party services, customer coordination, or significant architectural changes.