Cadence Health
Bug bounty Managed triageCadence Health Systems, PBC
Patient portal, clinician workspace and a FHIR R4 gateway. Synthetic records only, and we mean it literally.
- Accepting reports
- $250 – $18,000
- 9 assets in scope
- Launched Jul 2020
- cadencehealth.example
Read the policy · first response 24 hours, seven days a week
Response times
- first response
- 6 hours
- triage
- 1 business day
- reward
- 9 days
- resolution
- 23 days
Program to date
- Resolved
- 1,147
- Total paid
- $1.07M
- Thanked
- 283
- Average
- $3,128
Rewards by severity
Final amounts depend on demonstrated impact, report quality and asset criticality.
| Severity | CVSS | Reward | Typical findings |
|---|---|---|---|
| Critical | 9.0 – 10.0 | $7,000 – $18,000 | Cross-patient record access, authentication bypass on the FHIR gateway, code execution on any host that stores or routes clinical data. |
| High | 7.0 – 8.9 | $2,400 – $6,800 | Clinician session takeover, escalation from patient role to care-team role, unauthenticated read of appointment or medication metadata. |
| Medium | 4.0 – 6.9 | $650 – $2,200 | Stored scripting in the portal message centre, object reference flaws on non-clinical account fields, reuse of a one-time login code. |
| Low | 0.1 – 3.9 | $250 – $600 | Verbose stack traces, missing flags on a non-session cookie, rate-limit gaps on an endpoint that returns nothing clinical. |
In scope
9 assets listed, 8 eligible for a reward. Anything not on this list is out of scope.
| Asset | Type | Max severity | Reward | Notes |
|---|---|---|---|---|
| portal.cadencehealth.example | URL | Critical | Eligible | Patient portal. Only the synthetic sandbox accounts issued to you at onboarding. Five requests per second per host, and no exceptions to that on a weekday morning. |
| fhir.cadencehealth.example | API | Critical | Eligible | FHIR R4 gateway including both SMART launch sequences. No scanners, at all, since August 2023; hand-driven requests only. |
| care.cadencehealth.example | URL | Critical | Eligible | Clinician scheduling and charting workspace. Role escalation into a care team is the highest-value target we have. |
| id.cadencehealth.example | Domain | Critical | Eligible | Identity provider: OIDC flows, step-up authentication, and the single sign-on broker two hundred practices federate into. |
| api.cadencehealth.example | API | High | Eligible | Portal backend. Secure messaging, document retrieval and statements. The document endpoint is the one that went wrong in 2022; it is instrumented accordingly. |
| rx.cadencehealth.example | API | High | Eligible | Prescribing gateway, in scope since June 2026. Sandbox formulary only, and nothing you send leaves our network. |
| example.cadencehealth.patient | Android | High | Eligible | Patient application, current release and one behind. A root-detection bypass on its own is not a finding here. |
| direct.cadencehealth.example | API | Medium | Eligible | Secure messaging bridge to partner directories, frozen since 2024. Caps at Medium and retires with the spring 2027 release. |
| print.cadencehealth.example | URL | High | No reward | Statement rendering run inside our print vendor's environment under their own assessment. Send findings here and we escalate within a day, but no reward attaches. |
Out of scope
| Asset | Why |
|---|---|
| Any production tenant that is not your assigned sandbox | Production tenants hold records belonging to people who never agreed to be part of this. Reaching one is outside scope and outside safe harbor. |
| Partner health-system endpoints reached through the FHIR gateway | Separate legal entities with their own security teams. We cannot authorise testing of their systems and will not accept reports about them. |
| www.cadencehealth.example | Marketing pages in a hosted publishing tool. Different origin, no clinical data, no shared session with the portal. |
| careers.cadencehealth.example | Recruiting software operated by the vendor who sells it. Their disclosure programme covers it. |
| status.cadencehealth.example | Status page run off our network by a third party under their own terms. |
| Practice-owned devices, networks and printers | Clinic property. We have no authority over it and neither do you. |
Findings that will be closed as informative
- Scanner output pasted in with no reproduction behind it.
- Header and cookie configuration findings with no exploitation path shown.
- Self-inflicted scripting, clickjacking on pages with no state change, and reverse tabnabbing.
- Password policy, session lifetime and lockout preferences unaccompanied by a working takeover.
- Mail authentication record opinions with no delivered impersonation.
- Denial of service, stress testing, or anything that slows a chart load. Availability here is clinical safety.
- Findings that require a rooted, jailbroken or already-infected patient device.
- Version banners and library advisories with no reachable path in our code.
- Any report containing real protected health information, which is closed, purged and logged as an incident.
Program policy
Program overview
Cadence Health runs the clinical record platform behind 412 independent practices across fourteen states. Three surfaces matter: the patient portal, the charting and scheduling workspace clinicians sit in all day, and the FHIR R4 gateway that exchanges records with partner systems. All three rest on protected health information, and that one fact is where every rule below comes from.
We have paid since July 2020. Since then: 1,147 reports resolved, 283 researchers thanked, 1,072,904 USD paid, first response inside six hours on average and inside a day on a weekend. We are also the program on this directory most likely to accept a finding and still have a long conversation about how it was found. Read the next section before you touch anything. It is not boilerplate and it is not negotiable.
Testing rules and expectations
February 2022. A researcher found an object reference flaw on the document endpoint and, to establish the pattern, incremented the identifier four thousand one hundred times. Most of what came back was real. We paid the Critical band, because the bug was real and the report was honest. We also spent four months on notification, and two practices left. Everything in this section was written that spring.
Synthetic records only. Onboarding issues you a sandbox tenant seeded from a generated population and reseeded every Sunday. Work there. Production tenants belong to clinics and to the people sitting in their waiting rooms.
The hard stop. If you reach anything that could plausibly be real (a name beside a diagnosis, a date of birth, a member number, a scanned referral), stop at that instant. Do not increment the identifier to confirm the pattern. That single step is what turns a bug into a breach, and it is the only rule here whose violation has ever cost someone a bounty. End the session and tell us within the hour. The shape of the exposure is enough; we confirm the rest from our own logs.
No retention. Nothing retrieved from our systems goes to disk, to cloud sync, to a notes application, to a paste service, to a chat client, to a language model, or to a co-researcher. Minimum proof is the smallest artefact that carries the finding: one identifier, one redacted field, one response header. Five hundred rows prove nothing that one row does not.
Volume and technique. Five requests per second per host. No scanner against the gateway at all, a rule from August 2023 after a weekend scan left two clinics waiting on chart loads. A clinician who cannot open a chart is a patient safety event, not an availability metric. No social engineering of clinic staff, no phishing, no physical attempts.
Proving write access
If you find a way to write, do not prove it by causing damage. Prove it with the smallest change that can be attributed to you and undone in the same minute.
- One or two punctuation characters. Delete a full stop, add a comma. Nothing longer, nothing visible, no payload, no changed number or amount.
- Only on a record you created yourself. Never another user's record, never site content, never anything the public can see.
- Revert within sixty seconds, in the same run, without being asked.
- Capture four states: before, after the change, after the revert, and an independent re-read confirming the revert held.
- If it cannot be reverted, do not change it. Report the write primitive and stop. A row count and a column list already prove database access.
Every request must carry headers that let us separate your traffic from a real attack in our logs:
X-Bug-Bounty: cadence-health
X-Research-Account: <the account you submit the report under>
X-Authorisation-Ref: <engagement or report reference>
X-Request-Id: <unique per request>
User-Agent: sentinel-research/<handle> (+<this page>)
scripts/proof_of_write.py performs exactly this sequence, refuses any host
outside the scope above, refuses a diff longer than two characters, always
attempts the revert, and writes a timestamped evidence file. Run it without
--execute first, then attach the evidence to your report.
Safe harbor
Research inside this policy is authorised research. We will not bring civil action and we will not refer you under computer misuse or health privacy statutes. If anyone else challenges testing that stayed within these rules, we put our authorisation in writing and send it to them ourselves.
Good faith means: you worked in your assigned sandbox, you stopped at the first plausibly real record, you kept the minimum, you did not slow anything down, and you reported promptly and only to us.
Authorisation ends if you reach a production tenant that is not yours, continue past the hard stop, retain or transmit or publish patient information, modify or delete a record, make payment a condition of disclosure, or route the finding to anyone outside Cadence Health before the window closes. If it is voided we tell you and we explain why. We have done that twice and we did not grant it back either time.
Reward decisions
CVSS v3.1 is where scoring starts, not where it ends. A medium-scoring flaw that yields one field from one patient record outranks a high-scoring flaw on a surface with no clinical content. Clinical data is weighted above account metadata at identical technical severity, and a finding on the gateway is weighted above the same finding on the portal because the gateway speaks for several practices at once.
Where two reports collide, the one that established impact first takes the award; a vague earlier note blocks nothing. A chain earns a single award scored on what it achieves end to end, plus up to 30% when it exposes a control failure we had not modelled. A working patch adds 10%.
Disclosure policy
Ninety days from triage confirmation. We extend only when a fix requires a coordinated release with a partner health system, and never by more than a further 45 days. The target date goes to you in writing on the day we ask.
Publish when we ship or when the window closes, whichever is first. Remove every record identifier, tenant name, practice name and hostname, and every screenshot showing a field from a record even where you are certain the record was synthetic. Give us the draft a week before you publish. We read it for redaction and for nothing else.
Report quality
- One issue per report. A chain belongs together; unrelated bugs do not.
- Exact endpoint, method and parameter, with the sandbox tenant identifier you used.
- Numbered steps that work from a clean session, with nothing skipped as obvious.
- Impact in clinical terms: whose data, how much of it, what an attacker does next.
- Minimum proof, redacted, inline. No archives, no external links, no video panning across a list of records.
- Your testing window, start to finish, in UTC, so we can pull the matching request logs.
Hall of fame
Researchers who have reported valid issues to this program.
| # | Researcher | Country | Reports | Points |
|---|---|---|---|---|
| 1 | ecgflatline | Netherlands | 51 | 6,418 |
| 2 | smartlaunch | Sweden | 37 | 5,740 |
| 3 | marrowbyte | Viet Nam | 44 | 5,102 |
| 4 | sutureself | Brazil | 56 | 4,633 |
| 5 | hl7hermit | India | 40 | 4,017 |
| 6 | quietward | Poland | 29 | 3,488 |
| 7 | triage_nurse | Ireland | 33 | 2,955 |
| 8 | cold_chain | Germany | 22 | 2,604 |
| 9 | oidc_orla | Ireland | 18 | 2,130 |
| 10 | vitalsigns | Canada | 25 | 1,806 |
| 11 | chartlock | Malaysia | 15 | 1,472 |
| 12 | scrubsuit | Argentina | 13 | 1,188 |
| 13 | bundle_ref | Egypt | 11 | 917 |
| 14 | wardround | New Zealand | 8 | 655 |
Program updates
-
SMART launch sequences in scope at Critical
Both the standalone and EHR launch flows on the gateway are testable, and sandbox client credentials are issued on request within a day. Two scoping errors were fixed during the closed phase before this opened.
-
Prescribing gateway added to scope
The prescribing surface is in at High with a sandbox formulary that terminates inside our network. Nothing you submit reaches a pharmacy, a directory or a real prescriber.
-
Synthetic population rebuilt and reseeded weekly
Sandbox tenants are reseeded every Sunday from a generated population of 40,000 patients with realistic coding and document history. No real clinical record has ever been loaded into a sandbox tenant.
-
Critical ceiling raised to 18,000 USD
A four-step escalation from a patient account into a care team took a researcher six weeks and paid less than it cost her to find. Critical now tops out at 18,000 and the Low floor moved from 150 to 250.
-
The HL7 v2 listener left scope
The last two practices exchanging over the legacy listener moved to FHIR in September and the listener was retired on the 15th. Messaging bridge findings now belong on the Direct endpoint, which caps at Medium.
-
Reports containing real records are purged on sight
Written down properly after a well-meant submission arrived with three unredacted documents attached. We purge the attachment, tell you what we purged, and score the finding from your description.
-
Scanners banned on the FHIR gateway
An unannounced weekend scan left two practices waiting on chart loads at Monday morning clinic. Nothing was breached and it was still the worst outcome of the year. Hand-driven requests only from now on.
-
Advisory CH-2023-02 published with credit
A session-fixation chain in the portal message centre was fixed in the January release and disclosed with both reporters named. One of them wrote the regression test we still run.
-
Policy rewritten around the hard stop
The February incident produced the rules that now open this page: stop at the first plausibly real record, minimum proof, no retention anywhere, and a sandbox tenant issued before you touch anything.
-
A report reached 4,100 real records
An object reference flaw on the document endpoint was confirmed by incrementing an identifier four thousand one hundred times. We paid the Critical band because the finding was real and the disclosure was honest, then spent four months on notification.
-
Clinician workspace added to scope
Charting and scheduling join the portal. Care-team role boundaries are new ground here and the first three months produced eleven valid escalation reports.
-
Program opened on the patient portal
Portal only, bands from 250 to 6,000 USD, two people reading reports on rotation between other work. Everything else on this page came later and most of it came the hard way.