Centers for Medicare and Medicaid Services · Vulnerability Disclosure

Cms Vulnerability Disclosure

Vulnerability disclosure

Centers for Medicare and Medicaid Services publishes a vulnerability disclosure policy for reporting security issues.

MedicareMedicaidHealthcareHealth InsuranceFHIRFederal-GovernmentDrug SpendingProvider DataQuality MeasuresClaims Data
Program:

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-15'
method: searched
source: https://www.cms.gov/vulnerability-disclosure-policy
program:
  published: true
  name: CMS/HHS Vulnerability Disclosure Policy
  url: https://www.cms.gov/vulnerability-disclosure-policy
  http_status: 200
  fetched: '2026-08-15'
  type: coordinated-disclosure
  bug_bounty: false
  platform: null
  note: >-
    CMS publishes a coordinated vulnerability disclosure policy under the federal CISA Binding
    Operational Directive 20-01 regime. It is linked from the footer of every CMS API developer site —
    bcda.cms.gov, ab2d.cms.gov, bluebutton.cms.gov, dpc.cms.gov — as "CMS/HHS Vulnerability Disclosure
    Policy", so a researcher landing on any CMS API property is one click from it. There is no paid
    bug bounty; CMS is a federal agency and the programme is disclosure-and-safe-harbour, not reward.
security_txt:
  served: false
  note: >-
    Probed /.well-known/security.txt on all sixteen CMS and HHS hosts on 2026-08-15 — 404 on every
    host that answered, 403 on ab2d.cms.gov, 401 on marketplace.api.healthcare.gov, and an SPA HTML
    shell (not a document) on qpp.cms.gov and npiregistry.cms.hhs.gov. The policy exists as HTML only.
    Publishing the same policy at /.well-known/security.txt per RFC 9116 is a one-file change that
    would make it machine-discoverable; it is the cheapest security-surface improvement available to
    CMS.
contacts:
  - kind: api-support
    api: CMS Beneficiary Claims Data API (BCDA)
    email: bcapi@cms.hhs.gov
    source: openapi/cms-bcda-openapi.yml info.contact
  - kind: api-support
    api: CMS Blue Button 2.0 API
    email: bluebuttonapi@cms.hhs.gov
    source: npm registry maintainer record for cms-bluebutton-sdk