Report a security vulnerability
Korus Health welcomes responsible reports of suspected security vulnerabilities affecting KorFlow or other Korus Health-managed digital services.
Security vulnerabilities can be reported to ppl.korushealth@nhs.net.
Please include a description of the issue, the affected service or component, steps to reproduce it where possible, and any relevant supporting information. Please do not include unnecessary patient-identifiable or confidential information.
We aim to acknowledge vulnerability reports within 2 working days and complete initial triage within 5 working days. Critical vulnerabilities are escalated immediately once identified. High-risk vulnerabilities have a target remediation period of 14 calendar days where technically practicable.
We ask reporters to act responsibly, avoid accessing or altering information beyond what is necessary to demonstrate the issue, and allow Korus Health a reasonable opportunity to investigate and remediate a vulnerability before public disclosure.
