generated: '2026-09-04' method: searched source: https://www.bostonscientific.com/en-US/customer-service/product-security/responsible-disclosure.html x-evidence: fetched: '2026-09-04' url: https://www.bostonscientific.com/en-US/customer-service/product-security/responsible-disclosure.html http_status: 200 program: exists: true name: Boston Scientific Responsible Disclosure policy_url: https://www.bostonscientific.com/en-US/customer-service/product-security/responsible-disclosure.html landing_url: https://www.bostonscientific.com/en-US/customer-service/product-security.html information_url: https://www.bostonscientific.com/en-US/customer-service/product-security/product-security-information.html contact: email: product.security@bsci.com method: email security_txt: false security_txt_note: >- No /.well-known/security.txt is served on any Boston Scientific host probed — the program is discoverable only as an HTML page. Publishing a security.txt pointing at this same policy URL and contact would make it machine-discoverable at no additional cost. acknowledgement_sla: five (5) business days triage_commitment: >- After triage Boston Scientific commits to sending an expected assessment timeline and to being "as transparent as possible" about remediation timelines and any issues that extend them. bug_bounty: false bug_bounty_note: >- Stated verbatim on the policy page: "at this time, Boston Scientific does not have a bug bounty program in place." safe_harbor: unstated safe_harbor_note: >- No explicit safe-harbor clause. The policy asks that research be conducted in good faith and that testing not cause harm to patients, customers or Boston Scientific. pgp_key: false scope: >- Boston Scientific products that contain software, including on-market medical devices, Software as a Medical Device, implants, capital equipment, and mobile medical applications. scope_note: >- The program is a MEDICAL DEVICE product-security program, not a web/API bug bounty. Its scope is device and SaMD software; no API host or web property is named as in scope. submission_requirements: - Contact information for the reporter - >- A clear description of the potential product security vulnerability and the methods used to exploit it - The network configuration used when identifying the vulnerability - >- Plans or intentions for public disclosure, and whether a vulnerability coordinator (CISA, H-ISAC) has already been contacted, with their tracking number coordinators_referenced: - US Cybersecurity and Infrastructure Security Agency (CISA) - US Health Information Sharing and Analysis Center (H-ISAC)