Teladoc · Vulnerability Disclosure

Teladoc Vulnerability Disclosure

Vulnerability disclosure

Teladoc publishes a vulnerability disclosure policy for reporting security issues. A dedicated security contact is published.

CompanyHealth TechTelehealthTelemedicineVirtual CareHealthcareBehavioral HealthWebhook
Program:

Disclosure Policy

Security Contact

Contact
emailresponsibledisclosure@teladochealth.com
Contact
form
Contact
pgp_key

Source

Vulnerability Disclosure

teladoc-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-15'
method: searched
source: https://www.teladochealth.com/legal/responsible-disclosure
program:
  name: Teladoc Health Responsible Disclosure
  url: https://www.teladochealth.com/legal/responsible-disclosure
  http_status: 200
  type: responsible-disclosure
  published: true
  bug_bounty: false
  bounty_note: >-
    "Teladoc Health does not provide compensation for finding security
    vulnerabilities", though the policy says the company is open to making
    recommendations that acknowledge meaningful contributions.
contact:
  email: responsibledisclosure@teladochealth.com
  form: null
  pgp_key: null
scope:
  statement: >-
    The process covers all Teladoc Health solutions — the consumer virtual care
    services and the integrated virtual care platform for hospitals and health
    systems.
  brands_and_domains:
  - Teladoc Health
  - BetterHelp
  - BetterSleep
  - BestDoctors
  - myStrength
  - HealthiestYou
  - InTouch Health
  - Livongo
  - MédecinDirect
  - VisitNow
  invited_report_types:
  - Weaknesses in mobile applications
  - Unsecure connections with Teladoc Health services
  - Code injection attacks
  prohibited_testing:
  - Denial of service / distributed denial of service
  - Physical testing of facilities
  - Social engineering
response_commitments:
  acknowledgement: Within 3 business days of receipt of a report.
  coordination: >-
    Teladoc Health confirms whether the vulnerability exists and, when
    appropriate, shares remediation; it commits to coordinating "as openly and
    as quickly as possible".
safe_harbor:
  present: false
  notes: >-
    The policy sets out prohibited testing methods and states that evidence of
    such activity will be investigated, but it does not carry explicit safe
    harbour language protecting good-faith researchers from legal action.
security_txt:
  published: false
  notes: >-
    No /.well-known/security.txt is served. www.teladochealth.com 301s every
    /.well-known/* path; demo.visitnow.org returns a genuine 404. The
    disclosure policy is a human web page only, not a machine-readable RFC 9116
    document.
ethics_hotline:
  url: https://secure.ethicspoint.com/domain/media/en/gui/55037/index.html
  note: Compliance and Ethics Hotline (EthicsPoint), linked from the legal index.
evidence:
- url: https://www.teladochealth.com/legal/responsible-disclosure
  status: 200
- url: https://www.teladochealth.com/legal
  status: 200
- url: https://demo.visitnow.org/.well-known/security.txt
  status: 404
- url: https://www.teladochealth.com/.well-known/security.txt
  status: 301
notes: >-
  The VisitNow brand named in this policy is the same visitnow.org domain that
  serves the Solo External API, which is the provider's own confirmation that
  demo.visitnow.org belongs to Teladoc Health.