Arrow Left Home

Coordinated Vulnerability Disclosure

At Health-RI, we highly value the security and integrity of our systems and services. Despite our efforts, vulnerabilities may still occur. Through this Coordinated Vulnerability Disclosure (CVD) policy, we invite researchers, ethical hackers, and other stakeholders to responsibly report security vulnerabilities so that we can address them promptly.

Collaboration

If you discover a potential vulnerability in a system, service, or infrastructure of Health-RI, we would like to collaborate with you. We kindly ask you to submit your findings in a way that protects the interests of all parties involved. This is not an authorization to perform active, large-scale, or unauthorized testing on our systems (such as penetration tests, (Distriubuted)Denial-of-Service ((D)DOS), or social engineering without consent).

What We Ask of You

When you submit a report:

  • Send an email to servicedesk@health-ri.nl clearly describing the vulnerability. We advise you to encrypt your findings with our PGP key.
  • to prevent the information from falling into the wrong hands.
  • Describe the vulnerability as explicitly as possible: which URL or system is affected, which steps lead to the issue, what the impact is, and, if possible, include a proof-of-concept or reproduction steps.
  • Do not test more systems or data than strictly necessary to confirm the vulnerability.
  • Do not publicly share your findings until the vulnerability has been resolved by us.
  • Avoid using vulnerabilities to alter, delete, or gain unauthorized access to data.
  • Also avoid social engineering attacks, physical intrusions, (D)DoS, or other techniques that may cause major disruption.

What We Promise You

After receiving your report:

  • You will receive an automated acknowledgment of receipt with a ticket number; depending on the nature of the report, a response is given.
  • Your report will be treated confidentially; your personal data will not be shared with third parties without your consent, unless legally required.
  • You may choose to report anonymously or under a pseudonym; however, please note that in such cases we may not be able to contact you for follow-up questions or a reward.
  • After resolution, we may mention you in our “Hall of Fame” as recognition for your contribution.
  • In some cases, we may grant a reward for your report; this is not automatic and will be evaluated on a case-by-case basis based on the quality of the report and the severity of the identified issue.

Scope and Exclusions

Within scope:

  • Systems, services, and applications directly managed by Health-RI.
  • Infrastructure components for which Health-RI is responsible.

Out of scope:

  • Vulnerabilities in third-party systems not managed by Health-RI.
  • Outdated software versions without new exploit evidence, unless they pose a direct risk.
  • Bugs that do not lead to actual abuse (e.g., HTTP 404 errors, minimal content injection without danger).
  • Issues with headers or configurations that are commonly known and not directly exploitable.
  • Social engineering, physical intrusion, or denial-of-service activities without permission.

Legal Notes

Reporting a vulnerability under this policy does not automatically grant you exemption from legal or criminal prosecution. The Public Prosecution Service always retains the right to initiate prosecution. Your actions are entirely at your own risk if you operate outside the terms of this policy.

Share this page…