generated: '2026-08-14' method: searched probe: true source: https://www.eclinicalworks.com/responsible-disclosure-policy/ policy: - https://www.eclinicalworks.com/responsible-disclosure-policy/ contact: - vulnerability@eclinicalworks.com bug_bounty: false platform: null safe_harbour: false security_txt: false summary: eClinicalWorks publishes a Responsible Disclosure Policy asking clients and security researchers to give eCW time to investigate and patch before public disclosure. Reports go to vulnerability@eclinicalworks.com and must include product name, product version, the area of the product where the vulnerability was found, and the conditions under which it was identified, with enough detail for the eCW Security Team to reproduce it. required_report_fields: - Product name - Product version - Area of the product where the vulnerability was detected - Conditions under which the vulnerability was identified - Detail sufficient for the eCW Security Team to reproduce restrictions: - No decompiling, disassembling or reverse-engineering - No modifying or destroying data - No hacking/penetration or unauthorized access to customer data - No adverse impact on eClinicalWorks operations or systems gaps: - 'No RFC 9116 security.txt on any eClinicalWorks or healow host (probed: 404 or soft-200 HTML on every host).' - No bug bounty and no HackerOne/Bugcrowd/Intigriti program. - No stated safe-harbour or legal-protection language — the policy explicitly reserves all rights and claims. - No published response-time or disclosure-timeline commitment. evidence: - source: https://www.eclinicalworks.com/responsible-disclosure-policy/ http_status: 200 kind: disclosure-page fetched: '2026-08-14' - source: https://www.eclinicalworks.com/.well-known/security.txt http_status: 200 kind: soft-404 note: Returns the 129,644-byte homepage HTML, not an RFC 9116 document. fetched: '2026-08-14' - source: https://fhir.eclinicalworks.com/.well-known/security.txt http_status: 404 fetched: '2026-08-14' - source: https://connect4.healow.com/.well-known/security.txt http_status: 404 fetched: '2026-08-14'