Security and Responsible Disclosure
This policy describes the shared security responsibilities for Healthcare Notes accounts, payments and professional workspaces.
Security design
- HTTPS is required for live use.
- Stripe secrets and webhook signing secrets remain server-side and are not included in downloadable packages.
- Stripe-hosted Checkout receives payment details; signed webhooks control entitlement.
- Protected pages are no-cache and noindex.
- Administrators and members use role-based WordPress access.
- Clinical drafts are session-only by design in this release.
- Rate limiting, nonces, sanitisation and output escaping protect public forms and endpoints.
User responsibilities
- Use a unique password and protect the email account used for password reset.
- Do not share accounts or leave a logged-in clinical workstation unattended.
- Use an approved device and network for workplace activity.
- Avoid patient identifiers and clear the workspace after use.
- Report suspicious login, unexpected billing or credential disclosure promptly.
- Keep the browser, operating system and security software current.
Payment security
Stripe Checkout is used to reduce direct handling of card data. PCI compliance remains a shared responsibility between Stripe, the operator, hosting and configured integrations. Healthcare Notes never requests a full card number by email or support form.
Responsible disclosure
Report a suspected vulnerability privately to maxillarvundi@gmail.com with the affected URL, observed behaviour, reproduction steps and potential impact. Do not include real patient information or other users’ personal data.
Give reasonable time to investigate before public disclosure. We will acknowledge good-faith reports and provide status where possible.
Prohibited security activity
- Accessing, altering or retaining another person’s data.
- Social engineering, phishing, credential theft or denial-of-service testing.
- Automated scanning that materially degrades the service.
- Testing third-party systems such as Stripe or the hosting provider.
- Exfiltrating data to prove a vulnerability.
- Public disclosure before a reasonable remediation opportunity.
Incident response
Suspected incidents are assessed, contained, investigated and remediated according to risk. Affected people and regulators will be notified where required. Access may be temporarily restricted to protect accounts or content.
Authoritative references
Contact
Questions about this policy can be sent to maxillarvundi@gmail.com. Do not include patient information.