Responsible Disclosure
How to report a security vulnerability to ConnectHL7, our response timelines, scope, and safe harbor commitments.
ConnectHL7 takes the security of our platform seriously, and we value the work of security researchers who help us keep it safe. If you believe you've found a security vulnerability in a ConnectHL7 system, we want to hear from you.
This page explains how to report a vulnerability, what to expect from us, and the commitments we make to researchers who report in good faith.
How to report a vulnerability
Please email your report to security@connecthl7.com.
To help us investigate quickly, please include where possible:
- A clear description of the vulnerability and its potential impact.
- The affected system, URL, or endpoint.
- Step-by-step instructions to reproduce the issue.
- Any proof-of-concept code, screenshots, or logs that support your report.
- How we can contact you for follow-up.
If you need to send sensitive details, ask us in your initial email and we will arrange an encrypted channel.
Expected response timeline
We aim to work with researchers promptly and transparently. Our target timelines are:
| Milestone | Target |
|---|---|
| Acknowledge receipt of your report | Within 2 business days |
| Provide an initial assessment / triage | Within 5 business days |
| Provide status updates | At least every 10 business days until resolution |
| Remediate validated vulnerabilities | Prioritized by severity |
These are targets, not contractual guarantees. Complex issues may take longer, and we'll keep you informed if they do.
Scope
In scope:
- The ConnectHL7 production platform and its public APIs.
- ConnectHL7-owned web properties, including this Trust Center domain.
Out of scope (please do not test these):
- Denial-of-service (DoS/DDoS) attacks, volumetric or load testing, or anything that degrades service availability.
- Social engineering, phishing, or physical attacks against ConnectHL7 personnel, customers, or facilities.
- Attacks requiring access to a victim's device or account, or that require a compromised account you do not own.
- Reports from automated scanners without a demonstrated, exploitable impact.
- Vulnerabilities in third-party services (e.g., AWS) — please report those to the relevant provider.
- Testing against customer data or any system, tenant, or account you are not explicitly authorized to test.
Never access, modify, or exfiltrate data that is not yours. If you encounter protected health information (PHI) or other sensitive data during testing, stop immediately and report it to us.
Safe harbor
ConnectHL7 will not pursue or support legal action against security researchers who:
- Make a good-faith effort to comply with this policy.
- Act only within the scope described above.
- Avoid privacy violations, data destruction, and any disruption to our services.
- Do not access, store, share, or exfiltrate customer data or PHI.
- Give us a reasonable opportunity to remediate before disclosing publicly.
We consider security research conducted consistently with this policy to be authorized, and we will work with you to understand and resolve the issue quickly. If legal action is initiated by a third party against you for activity conducted in accordance with this policy, we will make this authorization known.
Coordinated disclosure process
We follow a coordinated disclosure model:
- Report — You send us the details privately at security@connecthl7.com.
- Acknowledge & triage — We confirm receipt, validate the issue, and assess severity.
- Remediate — We develop and deploy a fix, prioritized by risk.
- Coordinate disclosure — We agree with you on if and when to publish details, so customers are protected first. We're happy to credit researchers who wish to be acknowledged.
We ask that you keep vulnerability details confidential until we've had a reasonable opportunity to remediate and have agreed on a disclosure timeline.
A note on rewards
We deeply appreciate responsible disclosure. At this time, ConnectHL7 does not operate a paid bug bounty program, and reports are not guaranteed a monetary reward. We are glad to publicly acknowledge researchers who report valid issues in good faith, where they wish to be credited. Should we introduce a formal bounty program in the future, we will announce it here.
Related: Security Overview · Contact
Security contact: security@connecthl7.com Last updated: 1 July 2026
Have a question for a vendor review or need documentation under NDA?
Contact Security