Health Gorilla · Vulnerability Disclosure

Health Gorilla Vulnerability Disclosure

Vulnerability disclosure

Health Gorilla publishes a security.txt document naming a dedicated security contact address, an OpenPGP encryption key and a policy URL. The finding worth recording is the delivery: the document exists and its content is a valid RFC 9116 field set, but it is served as an HTML page at /home/security-txt rather than as text at /.well-known/security.txt, so no automated scanner or agent following RFC 9116 will ever find it. Its Expires field also lapsed on 2025-12-31, which under RFC 9116 makes the document formally stale.

Health Gorilla runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

HealthInteroperabilityFHIRClinical DataLab OrderingTEFCAQHINHealth Information ExchangeLab ResultsClinical DocumentsSMART on FHIRPatient RecordsHL7
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
security@healthgorilla.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-14'
method: searched
probe: true
source: https://www.healthgorilla.com/home/security-txt
description: >-
  Health Gorilla publishes a security.txt document naming a dedicated security
  contact address, an OpenPGP encryption key and a policy URL. The finding worth
  recording is the delivery: the document exists and its content is a valid RFC
  9116 field set, but it is served as an HTML page at /home/security-txt rather
  than as text at /.well-known/security.txt, so no automated scanner or agent
  following RFC 9116 will ever find it. Its Expires field also lapsed on
  2025-12-31, which under RFC 9116 makes the document formally stale.
disclosure_program: false
bug_bounty: false
contact:
- security@healthgorilla.com
policy:
- https://www.healthgorilla.com/home/privacy-policy
encryption:
- https://healthgorilla.com/pgp-key.txt
preferred_languages: [EN]
expires: '2025-12-31'
expired: true
security_txt:
  published: true
  url: https://www.healthgorilla.com/home/security-txt
  http_status: 200
  served_at_well_known: false
  content_type: text/html
  file: health-gorilla-security-txt.txt
  rfc9116_fields_present: [Contact, Encryption, Policy, Expires, Preferred-Languages]
  findings:
  - >-
    Delivered as an HTML page, not text/plain at /.well-known/security.txt.
    GET https://www.healthgorilla.com/.well-known/security.txt returns the
    Webflow site shell (soft-404), and
    GET https://api.healthgorilla.com/.well-known/security.txt returns 404.
  - >-
    The Contact field is written "mailto: security@healthgorilla.com" with a
    space after the scheme colon, which is not a valid mailto URI.
  - >-
    Expires is 2025-12-31, in the past as of this probe. RFC 9116 states a
    security.txt whose Expires date has passed should not be trusted as current.
  - >-
    Policy points at the general privacy policy rather than a dedicated
    vulnerability disclosure or responsible disclosure page.
bounty_platforms:
  hackerone: not found
  bugcrowd: not found
  intigriti: not found
disclosure_pages_probed:
- {url: 'https://www.healthgorilla.com/security', http_status: 200, result: 'soft-404 site shell — rejected'}
- {url: 'https://www.healthgorilla.com/compliance', http_status: 200, result: 'soft-404 site shell — rejected'}
- {url: 'https://api.healthgorilla.com/.well-known/security.txt', http_status: 404, result: miss}
- {url: 'https://developer.healthgorilla.com/.well-known/security.txt', http_status: 404, result: miss}
- {url: 'https://www.healthgorilla.com/.well-known/security.txt', http_status: 200, result: 'soft-404 site shell — rejected'}
related_security_posture:
  page: https://www.healthgorilla.com/home/company/health-data-security
  certifications: [HITRUST r2, SOC 2 Type 2]
  detail: security/health-gorilla-trust-center.yml
recommendation_for_provider: >-
  Serve the existing document as text/plain at
  https://www.healthgorilla.com/.well-known/security.txt, fix the mailto URI,
  refresh Expires, and point Policy at a dedicated disclosure page. The content
  already exists — only the delivery is missing.
evidence:
- {source: 'https://www.healthgorilla.com/home/security-txt', kind: security.txt, http_status: 200}
- {source: security/health-gorilla-security-txt.txt, kind: harvested-verbatim}
- {source: 'https://www.healthgorilla.com/sitemap.xml', kind: sitemap, note: 'located the real /home/security-txt path'}
x-evidence:
- {url: 'https://www.healthgorilla.com/home/security-txt', http_status: 200, fetched: '2026-08-14'}
- {url: 'https://healthgorilla.com/pgp-key.txt', http_status: 200, fetched: '2026-08-14'}