OwnIt Health

Security Vulnerability Disclosure Policy

Effective September 2026

OwnIt Health maintains protected health information and takes the security of that information seriously. If you have identified a vulnerability that could allow unauthorized access to data or systems, we ask that you report it to us directly and confidentially so we can address it promptly.

How to Report

Email admin@ehr.ownithealthcare.com with SECURITY in the subject line.

Please submit one finding per report and include:

Reports that cannot be reproduced cannot be remediated, so detailed information is essential.

Guidelines for Researchers

Prohibited Activities

The following activities are not authorized and will be treated as attacks:

Our Commitments

Recognition

OwnIt Health does not offer a paid bug bounty program. With your permission, we will publicly acknowledge researchers who report significant findings and can provide written confirmation of your contribution upon request.

Information for Patients

Patients do not need to provide technical proof to report a concern. If you viewed information that did not belong to you, or your account behaved in a way that concerned you, please contact us at admin@ehr.ownithealthcare.com or 302-615-6105. Every report will be investigated, and we would much rather review a false alarm than miss a genuine concern.