HealthVerity · Vulnerability Disclosure

Healthverity Vulnerability Disclosure

Vulnerability disclosure

HealthVerity runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

HealthcareUnited StatesLife SciencesReal-World DataIdentity ResolutionDe-IdentificationTokenizationData MarketplaceHIPAAClaims
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
mailto:security@healthverity.com

Source

Vulnerability Disclosure

healthverity-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-15'
method: searched
probe: true
source: https://healthverity.com/vulnerability-disclosure/
policy:
- https://healthverity.com/vulnerability-disclosure/
contact:
- mailto:security@healthverity.com
bug_bounty: false
bug_bounty_note: >-
  HealthVerity does not currently operate a paid bug-bounty program; no
  compensation or rewards are offered for vulnerability reports. No HackerOne,
  Bugcrowd or Intigriti program was found.
safe_harbor: true
safe_harbor_note: >-
  Good-faith researchers who stay within the policy scope are protected from
  civil or criminal action for accidental, good-faith violations.
scope:
- Internet-accessible HealthVerity-owned websites and web applications
- Publicly accessible HealthVerity APIs
- Authentication and authorization issues
- Sensitive-information exposure
out_of_scope:
- Third-party systems
- Denial-of-service attacks
- Social engineering
- Automated scanning that impacts availability
reporting:
  method: email
  address: security@healthverity.com
  acknowledgement: within five business days
  disclosure: coordinated with the researcher
expires: '2027-07-21T00:00:00Z'
evidence:
- source: https://healthverity.com/.well-known/security.txt
  kind: security.txt (live probe, HTTP 200)
  rechecked: '2026-08-15'
- source: https://healthverity.com/vulnerability-disclosure/
  kind: vulnerability disclosure policy page (HTTP 200)
- source: well-known/healthverity-security.txt
  kind: verbatim security.txt harvested into this repo
note: >-
  Re-verified 2026-08-15. The RFC 9116 security.txt at
  https://healthverity.com/.well-known/security.txt still returns HTTP 200 and
  still names both the Contact and the Policy URL. This file preserves the
  fuller policy detail searched from the disclosure page itself; the automated
  probe alone only recovers Contact and Policy.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/healthverity-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.