ModMed · Vulnerability Disclosure

Modernizing Medicine Vulnerability Disclosure

Vulnerability disclosure

ModMed publishes a vulnerability disclosure policy for reporting security issues. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyHealthcareElectronic Health RecordsPractice ManagementFHIRHealth ITInteroperabilityMedical BillingSMART on FHIRTelehealth
Program: security.txt present

Disclosure Policy

Policy

Security Contact

Contact
mailto:security+txt@modmed.com
Contact
mailto:security@modmed.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-04'
method: searched
probe: true
source: https://www.modmed.com/security/ + well-known/modernizing-medicine-security.txt
policy:
- https://www.modmed.com/security/
contact:
- mailto:security+txt@modmed.com
- mailto:security@modmed.com
evidence:
- source: https://www.modmed.com/security/
  kind: coordinated disclosure policy page
  http_status: 200
- source: well-known/modernizing-medicine-security.txt
  kind: security.txt
  http_status: 200
program: Coordinated Security Vulnerability Program
bug_bounty: false
bounty_note: '"ModMed does not offer compensation for reporting potential security vulnerabilities or
  other issues."'
required_submission_fields:
- The affected systems or resource
- Steps to reproduce the issue
customer_path: ModMed customers are asked to contact ModMed Support and state that they have a security
  report for the VDP.
out_of_scope:
- Decompiling, disassembling or reverse-engineering proprietary software
- Viewing, modifying or destroying protected health information or other data
- Attempting unauthorized access to data in violation of applicable law
- Adversely impacting the availability of ModMed systems
security_txt:
  url: https://www.modmed.com/.well-known/security.txt
  http_status: 200
  file: well-known/modernizing-medicine-security.txt
  issue: The Expires field reads 2025-04-30T16:59:00.000Z — the published security.txt is expired and
    should be refreshed (RFC 9116 requires a future Expires).
x-evidence:
  fetched: '2026-08-04'
  urls:
  - url: https://www.modmed.com/security/
    http_status: 200
  - url: https://www.modmed.com/.well-known/security.txt
    http_status: 200
contact_note: security+txt@modmed.com is the /.well-known/security.txt Contact; security@modmed.com is
  published as the iodef contact in the modmed.com CAA record (probed 2026-08-04).