Security Vulnerability Disclosure Policy
OwnIt Health maintains protected health information and takes the security of that information seriously. If you have identified a vulnerability that could allow unauthorized access to data or systems, we ask that you report it to us directly and confidentially so we can address it promptly.
How to Report
Email admin@ehr.ownithealthcare.com with SECURITY in the subject line.
Please submit one finding per report and include:
- A step-by-step description of how the vulnerability can be exploited
- The date and time of your testing and the actions you performed
- Screenshots or other supporting evidence, where available
Reports that cannot be reproduced cannot be remediated, so detailed information is essential.
Guidelines for Researchers
- Limit testing to proof of concept. Use a vulnerability only to the extent necessary to demonstrate that it exists. Do not escalate access, establish persistence, or use the vulnerability to access other systems.
- Stop immediately if you encounter real data. This includes health information, identity documents, and payment information. Do not download, retain, or share it. Notify us of what was accessed so we can assess whether a breach occurred, and then permanently delete any copies.
- Report promptly, ideally on the same day the vulnerability is discovered.
- Do not disrupt patient care. Testing must not degrade service availability, delete or modify data, or interfere with any patient visit.
- Allow reasonable time for remediation before disclosing the vulnerability to any third party.
Prohibited Activities
The following activities are not authorized and will be treated as attacks:
- Denial-of-service attacks, load testing, or any activity that impairs service availability
- Social engineering of staff or patients, including phishing and telephone pretexting
- Physical attempts to access our facilities or personnel
- Testing of third-party vendor systems rather than OwnIt Health systems
- High-volume automated scanning that produces large numbers of low-quality reports
Our Commitments
- We will acknowledge receipt of your report within three (3) business days.
- We will inform you whether we were able to reproduce the issue and, if so, the steps we are taking to resolve it.
- We will not pursue legal action against individuals who conduct research and report findings in good faith and in accordance with this policy.
Recognition
OwnIt Health does not offer a paid bug bounty program. With your permission, we will publicly acknowledge researchers who report significant findings and can provide written confirmation of your contribution upon request.
Information for Patients
Patients do not need to provide technical proof to report a concern. If you viewed information that did not belong to you, or your account behaved in a way that concerned you, please contact us at admin@ehr.ownithealthcare.com or 302-615-6105. Every report will be investigated, and we would much rather review a false alarm than miss a genuine concern.