Product Security at Biodynamik
Biodynamik is committed to the safety and security of the products our patients and clinicians rely on. Security is considered throughout the product lifecycle, from design and development through manufacturing, release, and postmarket support.
We recognize the role that security researchers, clinicians, and customers play in identifying potential vulnerabilities, and we welcome reports. This page explains what our Coordinated Vulnerability Disclosure (CVD) process covers, how to report a potential vulnerability, and what you can expect from us in return.
Scope
This process applies to Biodynamik medical devices and the software and services associated with them, including:
- Biodynamik medical devices and device accessories
- Biodynamik mobile applications
- Biodynamik cloud services and web applications
- The Biodynamik website
This process is not for the following:
- An adverse event, patient injury, or product quality complaint
- A device malfunction, or a request for technical support
- A general enquiry
For any of these, please contact your healthcare provider or your Biodynamik representative.
How to Report a Potential Vulnerability
Use the submission form on this page.
If you need to send information confidentially, submit the form without technical details and tell us you would like a secure channel. We will contact you to arrange one before you send anything further.
Please do not include patient information, personal health information, or personal data belonging to any third party in your report, including in screenshots, logs, or packet captures.
Reports are accepted in English.
What to include
The more of the following you can provide, the faster we can verify and act on your report.
- The product or component affected, and the version or lot number if known
- A description of the potential vulnerability, and how you discovered it
- Steps to reproduce the issue
- Your assessment of the impact, and any suggested remediation
- The environment used for testing — operating system, software and versions, hardware, radio adapter, network configuration, or browser and version as applicable
- Any indication that the issue is already being exploited
- Any plans you have to disclose the issue publicly, including a target date
Proof-of-concept code is helpful and will speed up our triage. Reports consisting only of automated scanner output, without analysis, may take longer to assess.
What We Ask of You
We will work in good faith with researchers who follow these guidelines.
- Do not test on a device that is in use by a patient, and do not conduct testing in a clinical setting.
- Do not return a device to patient use if it has been altered or affected during the course of your testing. Contact us instead.
- Do not access, modify, or delete data in any account, device, or system you do not own or have permission to test.
- Do not perform denial-of-service testing, or any testing likely to degrade the availability of a Biodynamik product or service.
- Do not use social engineering, phishing, or physical attacks against Biodynamik personnel, customers, or facilities.
- Comply with all applicable laws in your location and ours.
- Give us a reasonable opportunity to investigate and remediate before disclosing publicly, and work with us on a mutually agreed disclosure date.
What You Can Expect From Us
- We will acknowledge receipt of your report within 10 business days.
- We will route your report to the appropriate technical team for verification and reproduction. We may contact you for additional information.
- We will confirm whether the vulnerability exists and assess its potential impact. Where a vulnerability is determined to affect patient safety, we will act expeditiously to develop a resolution. Other vulnerabilities will be evaluated and addressed according to the associated risk.
- We will keep you informed as your report moves through our review.
- We will work with you on the timing of any public disclosure, and we will credit your contribution if you would like us to.
- If we are unable to resolve a disagreement or communication difficulty, we may involve a neutral third party — such as CISA, CERT/CC, or the relevant regulator — to help determine how best to handle the matter.
Good-Faith Research
Biodynamik will not pursue legal action against individuals who identify and report potential vulnerabilities in accordance with this policy and in good faith. Biodynamik reserves all rights in the event of activity that does not comply with this policy.
Submitting a report does not create any obligation on the part of Biodynamik, and does not entitle the submitter to compensation. Biodynamik does not operate a bug bounty program.
This policy may be updated from time to time. The version published on this page is the current one.