Programs/Helios Health

Helios Health

VDPSelf-serve triage
Patient portal & clinical scheduling · helios.io

Helios Health runs a vulnerability disclosure program. There is no monetary bounty, but every valid report is credited on our hall of fame and handled with the urgency patient data deserves.

Submit a report
Reward
Recognition
Avg. response
3.1 days
Reports resolved
61
Bounties paid
—
Researchers
27

Scope

In scope
portal.helios.ioWeb
scheduling.helios.ioWeb
Patient records APIAPI
Out of scope
helios.io (marketing)
Third-party clinical integrations
Denial-of-service / volumetric
Any test touching real patient data

Rewards by severity

SeverityExamplesBounty
CriticalRCE, auth bypass, mass data exposureRecognition
HighSSRF, stored XSS, privilege escalationRecognition
MediumIDOR, CSRF on sensitive actionsRecognition
LowReflected XSS, minor info disclosureRecognition

Rules & policy

01

Test only assets listed in scope. Never access, modify or delete data that does not belong to your test account.

02

Use your own test accounts. Stop immediately if you encounter another user's data and report it.

03

No denial-of-service, automated scanning at scale, or social engineering of staff or users.

04

Report each vulnerability once, with clear reproduction steps and evidence. Duplicates are closed against the earliest valid report.

05

Keep findings confidential until Helios confirms a fix and agrees to disclosure. Good-faith research is authorized and will not be pursued legally.

Recent activity

HighAppointment records readable across tenantsResolved · credited
MediumCSRF on care-team invitationResolved · credited
LowVerbose error leaks stack traceResolved · credited

Found something on Helios Health?

Submit a structured report with steps and evidence. Self-serve triage reviews it, and a valid finding is rewarded by severity.

Submit a reportBack to programs