The Policy
Reporting a Security Vulnerability
VeriMedic builds software that handles protected health information for emergency medical services agencies. We take security seriously, and we want to hear from you if you find a problem.
If you believe you have found a security vulnerability in a VeriMedic system, email security@getverimedic.com.
We read every report. We'll acknowledge yours within three business days and tell you what we plan to do about it within ten.
What We Ask
Give us enough to reproduce the issue: the affected URL or endpoint, the steps you took, and what you saw. A short video or a few screenshots help. Tell us how you'd like to be credited, or tell us you'd rather not be.
Give us reasonable time to fix the issue before you tell anyone else. Ninety days is our default. If the issue is being actively exploited, say so and we'll move faster. If we're dragging our feet, tell us that too.
Safe Harbor
If you find a vulnerability in good faith and follow this policy, we will not pursue legal action against you. That's a commitment. Here is what it covers.
We will not bring a civil claim against you or refer you for criminal prosecution under the Computer Fraud and Abuse Act, the Pennsylvania or Maryland computer crime statutes, or any comparable state or federal law. We will not bring a claim under the anti-circumvention provisions of the Digital Millennium Copyright Act for work you do to investigate or demonstrate a vulnerability. We consider your research authorized access under those laws.
If a third party brings an action against you for research conducted under this policy, we will make it known that your conduct was authorized.
This protection depends on you acting in good faith. If you deliberately access patient data beyond what a proof of concept requires, exfiltrate data, extort us, or damage our systems, this section does not apply to you.
Nothing here waives any right a VeriMedic customer or patient holds. We speak only for ourselves.
Scope
In scope:
- getverimedic.com and its subdomains
- The CaseSync web application and its API
- The VeriMedic mobile applications
Out of scope:
- Any system operated by a VeriMedic customer, including an EMS agency's own network, computer-aided dispatch system, or electronic patient care reporting vendor
- Third-party services we use but do not control
- Physical security at any VeriMedic or customer facility
- Social engineering of VeriMedic personnel, contractors, or customers
If you aren't sure whether something is in scope, ask before you test.
Rules of Engagement
Do not access, modify, download, or retain protected health information. If you find a path to patient data, stop at the point where you've proved the path exists. Tell us what you found. Don't go through the door.
Do not run denial-of-service tests, automated scanners that generate heavy traffic, or brute-force attacks against production. Do not test in a way that degrades service for an agency running a call.
Do not use another person's account without that person's written consent. Create your own test account if you need one.
Delete any VeriMedic data you obtained during your research once you've sent us your report.
What We Are Most Interested In
Authentication and session handling. Authorization flaws that let one agency see another agency's records. Anything touching patient care reports or body-worn camera footage. Server-side injection. Remote code execution. Exposed credentials or keys.
What We Usually Won't Act On
Missing security headers with no demonstrated impact. Rate limiting on non-authentication endpoints. Output from an automated scanner with no proof of exploitability. Reports about software versions with no working exploit. Self-XSS. Clickjacking on pages with no sensitive action. Absence of SPF, DKIM, or DMARC on domains we don't send mail from. Social engineering findings. Best-practice recommendations unattached to a specific vulnerability.
We'll still read these. We may still fix them. We're telling you in advance that they won't get a fast response.
Rewards
VeriMedic does not run a paid bug bounty program today. We'll credit you publicly on this page if you want that, and we'll tell you honestly what we fixed and when.
Contact
Last updated: September 18, 2026