Practice Fusion · Vulnerability Disclosure

Practice Fusion Vulnerability Disclosure

Vulnerability disclosure

Practice Fusion runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyHealthcareElectronic Health RecordsEHRFHIRInteroperabilityMedicalHealth ITSMART on FHIRClinical Data
Program: Hackerone security.txt present

Disclosure Policy

Security Contact

Contact
PandSCompliance@veradigm.com

Source

Vulnerability Disclosure

practice-fusion-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-14'
method: searched
probe: true
source: https://veradigm.com/legal/security-program/
notes: >-
  There is a published security contact but NO published vulnerability
  disclosure programme. Practice Fusion serves no security.txt on any host
  (api.practicefusion.com and www.practicefusion.com both 404), runs no bug
  bounty on HackerOne, Bugcrowd or Intigriti, and publishes no responsible- or
  coordinated-disclosure policy, safe-harbour statement or triage SLA. The only
  route a finder has is the postal address and compliance mailbox on the parent
  company's Security Program page. Recorded as a real, named, reachable security
  contact — and as an explicit absence of everything else, which for an ONC
  Certified Health IT vendor handling PHI is the notable finding.
formal_vdp: false
bug_bounty: false
safe_harbour: false
security_txt: false
policy: []
contact:
- PandSCompliance@veradigm.com
contact_postal: 'Veradigm LLC, 305 Church at North Hills St, Raleigh, NC 27609, Attention: Chief Security Officer'
security_policy_page: https://veradigm.com/legal/security-program/
evidence:
- {source: 'https://veradigm.com/legal/security-program/', http_status: 200, kind: security-policy-page, note: 'names the Veradigm Security Team, the Chief Security Officer and the PandSCompliance mailbox'}
- {source: 'https://www.practicefusion.com/.well-known/security.txt', http_status: 404, kind: security.txt}
- {source: 'https://api.practicefusion.com/.well-known/security.txt', http_status: 404, kind: security.txt}
- {source: 'https://veradigm.com/.well-known/security.txt', http_status: 403, kind: security.txt}
- {source: 'https://www.practicefusion.com/responsible-disclosure/', http_status: 404, kind: disclosure-page}
- {source: 'https://www.practicefusion.com/vulnerability-disclosure/', http_status: 404, kind: disclosure-page}
- {source: 'https://www.practicefusion.com/security/', http_status: 404, kind: disclosure-page}
recommendation: >-
  Publish /.well-known/security.txt (RFC 9116) on www.practicefusion.com and
  api.practicefusion.com with Contact, Policy, Preferred-Languages and Expires —
  a single static file would close the gap for a platform holding 43M+ clinical
  records.
checked: '2026-08-14'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/practice-fusion-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.