generated: '2026-08-14' method: searched description: >- Search for a MEDITECH-run vulnerability disclosure program or bug bounty: security.txt probes across every known host, HackerOne/Bugcrowd/Intigriti directory search, and MEDITECH's own security/support pages. found: false programs: [] evidence: - check: security.txt (RFC 9116) hosts_probed: - {host: ehr.meditech.com, path: /.well-known/security.txt, status: 404} - {host: www.meditech.com, path: /.well-known/security.txt, status: 302, note: redirects to ehr.meditech.com/page-not-found (soft-404)} - {host: greenfield-prod-apis.meditech.com, path: /.well-known/security.txt, status: 404} - {host: greenfield.meditech.com, path: /.well-known/security.txt, status: 200, note: SPA catch-all shell, not a real security.txt -- see well-known/meditech-well-known.yml} result: not published on any host checked. - check: HackerOne url: https://hackerone.com/meditech status: 200 finding: >- The page loads but carries HackerOne's own `class="spec-external-unclaimed"` marker on its meta description ("This community-curated security page documents any known process for reporting a security vulnerability to MEDITECH..."). That class is HackerOne's own signal for an UNCLAIMED community page, not an active MEDITECH-run program -- MEDITECH has not established or claimed a HackerOne program. Recorded as a miss, not a hit, despite the 200 and the MEDITECH-branded page existing. - check: Bugcrowd / Intigriti result: no MEDITECH program found on either platform via web search. - check: MEDITECH support/contact pages urls_checked: - https://ehr.meditech.com/contact - https://ehr.meditech.com/privacy-policy result: no security-contact or responsible-disclosure email/policy published. note: >- An honest zero: MEDITECH publishes no security.txt, no bug bounty, and has not claimed the community-curated HackerOne page that already exists in its name. This does not mean MEDITECH has no internal security process -- only that no PUBLIC vulnerability-disclosure surface was found.