HealthVerity · Vulnerability Disclosure

Healthverity Vulnerability Disclosure

Vulnerability disclosure

HealthVerity runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

HealthcareUnited StatesLife SciencesReal-World DataIdentity ResolutionDe-IdentificationTokenizationData MarketplaceHIPAAClaims
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
mailto:security@healthverity.com

Source

Vulnerability Disclosure

healthverity-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-15'
method: searched
probe: true
source: https://healthverity.com/vulnerability-disclosure/
policy:
- https://healthverity.com/vulnerability-disclosure/
contact:
- mailto:security@healthverity.com
bug_bounty: false
bug_bounty_note: >-
  HealthVerity does not currently operate a paid bug-bounty program; no
  compensation or rewards are offered for vulnerability reports. No HackerOne,
  Bugcrowd or Intigriti program was found.
safe_harbor: true
safe_harbor_note: >-
  Good-faith researchers who stay within the policy scope are protected from
  civil or criminal action for accidental, good-faith violations.
scope:
- Internet-accessible HealthVerity-owned websites and web applications
- Publicly accessible HealthVerity APIs
- Authentication and authorization issues
- Sensitive-information exposure
out_of_scope:
- Third-party systems
- Denial-of-service attacks
- Social engineering
- Automated scanning that impacts availability
reporting:
  method: email
  address: security@healthverity.com
  acknowledgement: within five business days
  disclosure: coordinated with the researcher
expires: '2027-07-21T00:00:00Z'
evidence:
- source: https://healthverity.com/.well-known/security.txt
  kind: security.txt (live probe, HTTP 200)
  rechecked: '2026-08-15'
- source: https://healthverity.com/vulnerability-disclosure/
  kind: vulnerability disclosure policy page (HTTP 200)
- source: well-known/healthverity-security.txt
  kind: verbatim security.txt harvested into this repo
note: >-
  Re-verified 2026-08-15. The RFC 9116 security.txt at
  https://healthverity.com/.well-known/security.txt still returns HTTP 200 and
  still names both the Contact and the Policy URL. This file preserves the
  fuller policy detail searched from the disclosure page itself; the automated
  probe alone only recovers Contact and Policy.