generated: '2026-08-27' method: searched source: https://www.oracle.com/corporate/security-practices/assurance/vulnerability/ docs: https://www.oracle.com/corporate/security-practices/assurance/vulnerability/ description: >- Vulnerability disclosure posture for Oracle Health Data Intelligence. No security.txt is served on any product host and no bug bounty program exists, but Oracle publishes a corporate vulnerability-handling and disclosure policy that covers its products, including this one. program: published: true scope: Oracle corporate, covering Oracle products and cloud services url: https://www.oracle.com/corporate/security-practices/assurance/vulnerability/ probed_status: 200 observed: '2026-08-27' reporting_contact: null reporting_contact_note: >- The page carries "Reporting Vulnerabilities" and "Disclosure Policies" sections, but the page body renders client-side and no contact address is present in the served HTML, so no address is recorded here rather than guessing one. sections_named: - Vulnerability Handling - Security Fixing Policies - Disclosure Policies - Reporting Vulnerabilities - Critical Patch Update and Security Alert programs bug_bounty: false bounty_platform: null note: >- Oracle operates a fixed quarterly Critical Patch Update and Security Alert cadence. No bug bounty program was found on the page or on HackerOne, Bugcrowd or Intigriti. Reports are handled centrally by Oracle, not by the Health Data Intelligence product team. security_txt: served: false probes: - url: https://docs.healtheintent.com/.well-known/security.txt status: 403 - url: https://cernerdemo.api.us-1.healtheintent.com/.well-known/security.txt status: 403 - url: https://www.oracle.com/.well-known/security.txt status: 403 note: >- No RFC 9116 security.txt is served on the documentation host, the API host or the parent brand host, so a researcher cannot discover the reporting channel from the API surface itself. The corporate policy page has to be found by search. gaps: - No security.txt on any host in this provider's surface. - No product-scoped disclosure contact; reporting is routed to a corporate address. - No bug bounty or safe-harbour statement discoverable from the developer portal.