Last Modified: 7/28/2026
Overview
Nextech is committed to maintaining the security and privacy of our systems, customers and their sensitive information entrusted to us. We value the efforts of security researchers, the security community and other stakeholders who help us to identify potential security vulnerabilities. If you believe you have discovered a vulnerability affecting Nextech Systems, we encourage you to report it responsibly in accordance with this policy.
Reporting a Vulnerability
Report any suspected security vulnerability by emailing:
To help us investigate your report, please include a description of the vulnerability and the likely affected system.
Responsible Testing
Strictly Prohibited Actions
No Financial Compensation
Nextech appreciates all responsible disclosure of security vulnerabilities. However, this is not a bug bounty program. There are no financial rewards or monetary incentives for vulnerability submissions.
HIPAA / PHI Protections
Because certain Nextech systems may create, receive, maintain, or transmit PHI, all research under this policy must be designed to avoid unauthorized access to, acquisition of, use of, or disclosure of PHI. Researchers must use the minimum information necessary to validate a finding, must not intentionally access patient records or other live clinical data, and must immediately cease activity and notify Nextech if PHI or other sensitive information is encountered. Any incidental exposure to PHI must be treated as confidential and must not be retained, further reviewed, shared, or used for any purpose other than reporting the issue to Nextech.