generated: '2026-08-15' method: searched source: https://www.cms.gov/vulnerability-disclosure-policy program: published: true name: CMS/HHS Vulnerability Disclosure Policy url: https://www.cms.gov/vulnerability-disclosure-policy http_status: 200 fetched: '2026-08-15' type: coordinated-disclosure bug_bounty: false platform: null note: >- CMS publishes a coordinated vulnerability disclosure policy under the federal CISA Binding Operational Directive 20-01 regime. It is linked from the footer of every CMS API developer site — bcda.cms.gov, ab2d.cms.gov, bluebutton.cms.gov, dpc.cms.gov — as "CMS/HHS Vulnerability Disclosure Policy", so a researcher landing on any CMS API property is one click from it. There is no paid bug bounty; CMS is a federal agency and the programme is disclosure-and-safe-harbour, not reward. security_txt: served: false note: >- Probed /.well-known/security.txt on all sixteen CMS and HHS hosts on 2026-08-15 — 404 on every host that answered, 403 on ab2d.cms.gov, 401 on marketplace.api.healthcare.gov, and an SPA HTML shell (not a document) on qpp.cms.gov and npiregistry.cms.hhs.gov. The policy exists as HTML only. Publishing the same policy at /.well-known/security.txt per RFC 9116 is a one-file change that would make it machine-discoverable; it is the cheapest security-surface improvement available to CMS. contacts: - kind: api-support api: CMS Beneficiary Claims Data API (BCDA) email: bcapi@cms.hhs.gov source: openapi/cms-bcda-openapi.yml info.contact - kind: api-support api: CMS Blue Button 2.0 API email: bluebuttonapi@cms.hhs.gov source: npm registry maintainer record for cms-bluebutton-sdk