# myDxHub vulnerability disclosure # # myDxHub handles protected health information. If you have found a way to # reach data you should not be able to reach, we want to hear about it before # anyone else does. # # Reporting: email the address below with "Security" in the subject line. # Please include enough detail to reproduce the issue: the URL or endpoint, # the steps you took, and what you saw. # # Please do NOT include patient data in your report. If your finding exposed # someone else's health information, tell us what you were able to reach and # stop there; do not download, retain, or share it, and do not test further # against records that are not your own. # # Good-faith research that follows this policy is welcome, and we will not # pursue action against researchers who report to us privately, avoid privacy # violations and service disruption, do not access or destroy data beyond what # is needed to demonstrate the issue, and give us a reasonable opportunity to # fix it before disclosing publicly. # # We acknowledge reports as quickly as we can and will keep you updated on the # fix. We do not currently run a paid bug bounty program. Contact: mailto:support@mydxhub.com Contact: https://mydxhub.com/contact Expires: 2027-08-01T00:00:00.000Z Preferred-Languages: en Canonical: https://mydxhub.com/.well-known/security.txt