Nextech Vulnerability Disclosure Policy

Last Modified: 7/28/2026

Overview

Nextech is committed to maintaining the security and privacy of our systems, customers and their sensitive information entrusted to us. We value the efforts of security researchers, the security community and other stakeholders who help us to identify potential security vulnerabilities. If you believe you have discovered a vulnerability affecting Nextech Systems, we encourage you to report it responsibly in accordance with this policy.

 

Reporting a Vulnerability

Report any suspected security vulnerability by emailing:

security-reports@nextech.com

To help us investigate your report, please include a description of the vulnerability and the likely affected system.

 

Responsible Testing

  • Act in good faith and avoid violating the privacy and security of our systems.
  • Avoid the disruption of services and the compromise of data confidentiality, integrity and availability.
  • stop testing and notify us if you encounter sensitive information or unintended access to data.

 

Strictly Prohibited Actions

  • Large-scale, automated or high-volume testing activities.
  • Denial of service (DoS) or distributed denial of service (DDoS).
  • Any violations of applicable laws, regulations and contractual obligations.

No Financial Compensation

Nextech appreciates all responsible disclosure of security vulnerabilities. However, this is not a bug bounty program. There are no financial rewards or monetary incentives for vulnerability submissions.

 

HIPAA / PHI Protections

Because certain Nextech systems may create, receive, maintain, or transmit PHI, all research under this policy must be designed to avoid unauthorized access to, acquisition of, use of, or disclosure of PHI. Researchers must use the minimum information necessary to validate a finding, must not intentionally access patient records or other live clinical data, and must immediately cease activity and notify Nextech if PHI or other sensitive information is encountered. Any incidental exposure to PHI must be treated as confidential and must not be retained, further reviewed, shared, or used for any purpose other than reporting the issue to Nextech.