{"id":36,"date":"2026-08-14T15:39:36","date_gmt":"2026-08-14T15:39:36","guid":{"rendered":"https:\/\/healthcarenotes.org\/?page_id=36"},"modified":"2026-08-14T15:39:36","modified_gmt":"2026-08-14T15:39:36","slug":"security","status":"publish","type":"page","link":"https:\/\/healthcarenotes.org\/?page_id=36","title":{"rendered":"Security and Responsible Disclosure"},"content":{"rendered":"\t\t<article class=\"fn-public-page fn-policy-page\">\n\t\t\t<header class=\"fn-page-hero\"><span>FLOOR NOTES POLICY<\/span><h1>Security and Responsible Disclosure<\/h1><p>This policy describes the shared security responsibilities for Floor Notes accounts, payments and professional workspaces.<\/p><div class=\"fn-policy-meta\"><span>Effective 14 August 2026<\/span><span>Version 2.0.0<\/span><span>Applies to floornotes.org<\/span><\/div><\/header>\n\t\t\t<div class=\"fn-policy-layout\">\n\t\t\t\t<nav class=\"fn-policy-toc\" aria-label=\"On this page\"><b>On this page<\/b><a href=\"#fn-policy-1\">Security design<\/a><a href=\"#fn-policy-2\">User responsibilities<\/a><a href=\"#fn-policy-3\">Payment security<\/a><a href=\"#fn-policy-4\">Responsible disclosure<\/a><a href=\"#fn-policy-5\">Prohibited security activity<\/a><a href=\"#fn-policy-6\">Incident response<\/a><\/nav>\n\t\t\t\t<div class=\"fn-policy-body\">\n\t\t\t\t\t\t\t\t\t\t\t<section id=\"fn-policy-1\">\n\t\t\t\t\t\t\t<h2>Security design<\/h2>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<ul><li>HTTPS is required for live use.<\/li><li>Stripe secrets and webhook signing secrets remain server-side and are not included in downloadable packages.<\/li><li>Stripe-hosted Checkout receives payment details; signed webhooks control entitlement.<\/li><li>Protected pages are no-cache and noindex.<\/li><li>Administrators and members use role-based WordPress access.<\/li><li>Clinical drafts are session-only by design in this release.<\/li><li>Rate limiting, nonces, sanitisation and output escaping protect public forms and endpoints.<\/li><\/ul>\t\t\t\t\t\t<\/section>\n\t\t\t\t\t\t\t\t\t\t\t<section id=\"fn-policy-2\">\n\t\t\t\t\t\t\t<h2>User responsibilities<\/h2>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<ul><li>Use a unique password and protect the email account used for password reset.<\/li><li>Do not share accounts or leave a logged-in clinical workstation unattended.<\/li><li>Use an approved device and network for workplace activity.<\/li><li>Avoid patient identifiers and clear the workspace after use.<\/li><li>Report suspicious login, unexpected billing or credential disclosure promptly.<\/li><li>Keep the browser, operating system and security software current.<\/li><\/ul>\t\t\t\t\t\t<\/section>\n\t\t\t\t\t\t\t\t\t\t\t<section id=\"fn-policy-3\">\n\t\t\t\t\t\t\t<h2>Payment security<\/h2>\n\t\t\t\t\t\t\t<p>Stripe Checkout is used to reduce direct handling of card data. PCI compliance remains a shared responsibility between Stripe, the operator, hosting and configured integrations. Floor Notes never requests a full card number by email or support form.<\/p>\t\t\t\t\t\t\t\t\t\t\t\t\t<\/section>\n\t\t\t\t\t\t\t\t\t\t\t<section id=\"fn-policy-4\">\n\t\t\t\t\t\t\t<h2>Responsible disclosure<\/h2>\n\t\t\t\t\t\t\t<p>Report a suspected vulnerability privately to maxillarvundi@gmail.com with the affected URL, observed behaviour, reproduction steps and potential impact. Do not include real patient information or other users\u2019 personal data.<\/p><p>Give reasonable time to investigate before public disclosure. We will acknowledge good-faith reports and provide status where possible.<\/p>\t\t\t\t\t\t\t\t\t\t\t\t\t<\/section>\n\t\t\t\t\t\t\t\t\t\t\t<section id=\"fn-policy-5\">\n\t\t\t\t\t\t\t<h2>Prohibited security activity<\/h2>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<ul><li>Accessing, altering or retaining another person\u2019s data.<\/li><li>Social engineering, phishing, credential theft or denial-of-service testing.<\/li><li>Automated scanning that materially degrades the service.<\/li><li>Testing third-party systems such as Stripe or the hosting provider.<\/li><li>Exfiltrating data to prove a vulnerability.<\/li><li>Public disclosure before a reasonable remediation opportunity.<\/li><\/ul>\t\t\t\t\t\t<\/section>\n\t\t\t\t\t\t\t\t\t\t\t<section id=\"fn-policy-6\">\n\t\t\t\t\t\t\t<h2>Incident response<\/h2>\n\t\t\t\t\t\t\t<p>Suspected incidents are assessed, contained, investigated and remediated according to risk. Affected people and regulators will be notified where required. Access may be temporarily restricted to protect accounts or content.<\/p>\t\t\t\t\t\t\t\t\t\t\t\t\t<\/section>\n\t\t\t\t\t\t\t\t\t\t<section class=\"fn-policy-references\"><h2>Authoritative references<\/h2><ul><li><a href=\"https:\/\/docs.stripe.com\/security\/guide\" target=\"_blank\" rel=\"noopener noreferrer\">Stripe integration security guide \u2197<\/a><\/li><li><a href=\"https:\/\/www.oaic.gov.au\/privacy\/notifiable-data-breaches\/preventing-preparing-for-and-responding-to-data-breaches\" target=\"_blank\" rel=\"noopener noreferrer\">OAIC data breach preparation and response \u2197<\/a><\/li><\/ul><\/section>\t\t\t\t\t<section class=\"fn-policy-contact\"><h2>Contact<\/h2><p>Questions about this policy can be sent to <a href=\"mailto:maxillarvundi@gmail.com\">maxillarvundi@gmail.com<\/a>. Do not include patient information.<\/p><\/section>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/article>\n\t\t\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-36","page","type-page","status-publish","hentry"],"brizy_media":[],"_links":{"self":[{"href":"https:\/\/healthcarenotes.org\/index.php?rest_route=\/wp\/v2\/pages\/36","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/healthcarenotes.org\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/healthcarenotes.org\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/healthcarenotes.org\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/healthcarenotes.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=36"}],"version-history":[{"count":0,"href":"https:\/\/healthcarenotes.org\/index.php?rest_route=\/wp\/v2\/pages\/36\/revisions"}],"wp:attachment":[{"href":"https:\/\/healthcarenotes.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=36"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}