Report a security issue
Last updated 17 September 2026
We welcome reports from security researchers and take them seriously — protecting health information is core to what we do. If you believe you've found a vulnerability, please tell us before disclosing it publicly, and we'll work with you to fix it.
How to report
Email security@patientcarecircle.com with enough detail for us to reproduce and assess the issue:
- A clear description and the potential impact.
- Step-by-step reproduction, including affected URLs or endpoints.
- Any proof-of-concept, logs, or screenshots (redact anything sensitive).
- How we can reach you for follow-up.
Scope
In scope: the Patient Care Circle web application and its APIs. Out of scope: our subprocessors' own infrastructure (report those to the respective provider), volumetric denial-of-service, and social-engineering of our staff or users.
Please do
- Test only against accounts you own — never access or use patient information that isn't yours.
- Avoid privacy violations, data destruction, and service disruption; access only the minimum needed to demonstrate the issue.
- Give us reasonable time to remediate before any public disclosure.
Safe harbor
We will not pursue or support legal action against researchers who make a good-faith effort to follow this policy, and we'll treat your report confidentially. If in doubt about whether an action is authorized, ask us first.
What to expect
We aim to acknowledge reports promptly, keep you updated on remediation, and credit reporters who wish to be recognized. A PGP key for encrypted reports is available on request.