Report a security concern safely
We welcome good-faith reports that help protect patients, providers, and the pharmacy. This policy does not authorize access to patient information, provider accounts, pharmacy systems, or third-party services.
Allowed good-faith activity
- Review public pages and report observable security defects.
- Use only accounts and data you own or have written permission to test.
- Stop immediately if you encounter personal, health, prescription, provider, or confidential information.
- Give us reasonable time to investigate before disclosing a report publicly.
Not permitted
Do not use denial-of-service tests, automated high-volume scanning, social engineering, phishing, malware, destructive testing, credential attacks, physical attacks, or testing that could affect pharmacy operations. Do not download, retain, alter, transmit, or disclose data that is not yours.
How to report
Email a concise description, affected public URL, reproduction steps, and potential impact. Do not attach PHI, credentials, exploit payloads containing real data, or other sensitive records. Ask for a protected follow-up channel if sensitive details are necessary.
Email a security reportLast reviewed July 19, 2026. Reports are evaluated individually. This policy does not waive rights or obligations under applicable law.
