Security Disclosure Policy.
How to responsibly report security vulnerabilities in Synchronize Health systems. Effective: July 2026.
Synchronize Health, LLC ("Synchronize Health") takes the security of our systems seriously. We value the work of security researchers who help us keep our partners, their patients, and our data safe. If you believe you have found a security vulnerability in any Synchronize Health system, we encourage you to report it to us responsibly.
Note: This policy applies only to security vulnerabilities in Synchronize Health systems and the SYNC-PREVENT™ platform. For general inquiries, product support, or privacy-related questions, please contact us at syncup@synchronize.health.
1. Reporting a vulnerability
If you believe you have discovered a security vulnerability, please report it by emailing security@synchronize.health. Please include the following information in your report:
- A description of the vulnerability and its potential impact
- Detailed steps to reproduce the vulnerability, including any tools, URLs, or request parameters used
- Any supporting materials such as screenshots, proof-of-concept code, or network traffic captures
- Your name and contact information (optional)
2. Safe harbor
Synchronize Health supports responsible security research. When conducted in good faith and in accordance with this policy, we consider authorized security research to be:
- Authorized in accordance with the Computer Fraud and Abuse Act (CFAA), and we will not initiate or recommend legal action against you for accidental, good-faith violations of this policy
- Exempt from restrictions in our Terms of Use that would otherwise prohibit security testing, and we waive those restrictions on a limited basis for work performed under this policy
- Lawful, helpful to the overall security of the internet, and conducted in good faith
You are expected, as always, to comply with all applicable laws. If a third party initiates legal action against you for activities conducted in accordance with this policy, we will make this authorization known.
3. Guidelines for security testing
To qualify for safe harbor under this policy, security researchers must:
- Avoid actions that could harm Synchronize Health, our partners, or their patients, including disruption of services, destruction of data, or compromise of user accounts
- Only interact with accounts you own or with the explicit permission of the account holder
- Stop testing and submit a report immediately upon discovery of any patient data, Protected Health Information (PHI), or personally identifiable information (PII)
- Not publicly disclose vulnerability details until Synchronize Health has confirmed the issue has been resolved or 90 days have passed from the initial report, whichever comes first
- Not exploit the vulnerability beyond what is necessary to demonstrate the issue
4. Out of scope
The following activities are outside the scope of this policy and are not authorized:
- Social engineering attacks (including phishing) against Synchronize Health employees, contractors, or partners
- Physical attacks against Synchronize Health offices, facilities, or infrastructure
- Denial-of-service (DoS or DDoS) attacks against any Synchronize Health system
- Automated vulnerability scanning that generates significant traffic volumes
- Accessing, modifying, or deleting data belonging to other users without their explicit consent
- Any activity that violates applicable federal, state, or local law
5. What to expect
After you submit a vulnerability report, Synchronize Health will:
- Acknowledge receipt of your report within five (5) business days
- Assign a team member to evaluate and validate the reported vulnerability
- Work to remediate confirmed vulnerabilities in a timely manner
- Notify you when the vulnerability has been resolved, if you have provided contact information
Synchronize Health does not currently operate a paid bug bounty program. We appreciate the contributions of security researchers and will publicly acknowledge reporters who follow this policy, with their permission.
6. Contact
Security vulnerability reports should be sent to security@synchronize.health. For general inquiries, contact:
Synchronize Health
2645 Executive Park Drive, Ste 301
Weston, FL 33331
syncup@synchronize.health · (954) 670-1266
Draft for legal review. Have counsel review and finalize before publishing.