Product security – Coordinated Vulnerability Disclosure Policy

At Haag-Streit, protecting the security of our products is an important part of our commitment to our customers, patients, and partners.

We recognize the valuable role that security researchers, customers, partners, and the broader cybersecurity community play in helping us identify and responsibly address potential security vulnerabilities.

If you believe you have identified a security vulnerability in a Haag-Streit product or service, we encourage you to report it through the channels described below.

Reporting a security vulnerability

This reporting process is intended for cybersecurity vulnerabilities affecting Haag-Streit products, software, firmware, integrated third-party components, and product-related digital services.

In scope

  • Haag-Streit products with digital capabilities
  • Software & firmware developed or maintained by Haag-Streit
  • Embedded or integrated third-party software components supplied as part of Haag-Streit products
  • Product-related digital services operated by Haag-Streit, where applicable.

 

Out of scope

Please use the appropriate Haag-Streit support, quality, or customer service channels for the following matters:

  • Product complaints
  • Adverse events or patient safety incidents
  • Technical support requests
  • Warranty claims
  • General customer service enquiries
  • Privacy or data protection requests.

Responsible disclosure

We ask all reporters to conduct security research responsibly and in good faith. When investigating potential vulnerabilities, please:

  • Act with the intention of improving the security of our products and services
  • Avoid actions that could affect the availability, integrity, or confidentiality of customer systems, products, or data
  • Do not intentionally access, modify, retain, or disclose customer, patient, or other confidential information
  • Limit testing to the minimum necessary to demonstrate the vulnerability & discontinue testing once sufficient evidence has been obtained
  • Do not exploit a vulnerability beyond what is reasonably necessary to validate your findings
  • Do not introduce malware, perform denial-of-service testing, or otherwise disrupt products or services
  • Do not publicly disclose details of the vulnerability until Haag-Streit has had a reasonable opportunity to investigate & where appropriate, provide remediation or mitigation guidance
  • Comply with all applicable laws & regulations.

What you can expect from us

When we receive a vulnerability report, we follow a coordinated process to review, assess, and address the reported issue where appropriate.

Not every report will result in a confirmed vulnerability. If a report cannot be reproduced or falls outside the scope of this policy, we will make reasonable efforts to communicate our findings. Where appropriate, Haag-Streit may provide customers with relevant information about available updates, mitigation measures, or recommended actions.

Coordinated vulnerability disclosure

Haag-Streit supports responsible coordination with security researchers and other reporters to ensure that potential vulnerabilities can be investigated and addressed in a controlled and timely manner.

We ask reporters not to publicly disclose details of a vulnerability until Haag-Streit has had a reasonable opportunity to investigate the report and, where appropriate, provide remediation or mitigation guidance.

Public communication regarding vulnerabilities is managed by Haag-Streit based on the nature of the issue, the affected products, and the need to protect customers.

Safe harbor

Haag-Streit supports responsible security research conducted in good faith and in accordance with this policy.

If you act responsibly, make a genuine effort to avoid harm, protect confidential information, promptly report your findings to us, and comply with this policy, Haag-Streit does not intend to pursue legal action based solely on your security research activities.

This statement does not authorize activities that violate applicable laws, compromise customer or patient data, disrupt products or services, or extend beyond what is reasonably necessary to identify and report a potential vulnerability. Nothing in this policy limits any rights or obligations under applicable law.

End-of-support products

Products that have reached the end of their supported lifecycle may no longer receive security updates.

Where feasible, Haag-Streit may provide mitigation guidance or other recommendations to help reduce potential security risks. Customers are encouraged to use supported product versions to benefit from ongoing security updates and security improvements.

Report a security vulnerability

If you believe you have identified a security vulnerability affecting a Haag-Streit product, please use the reporting form below. The form is the preferred reporting channel because it helps us collect the information needed to review and assess your report.

We appreciate the efforts of the security community in helping us improve the security of our products. Responsible vulnerability reporting contributes to better protection for our customers, patients, partners, and the healthcare professionals who rely on our products.

Security Vulnerability Reporting Form

Please use this form to report a suspected cybersecurity vulnerability affecting a Haag-Streit product, including associated software, firmware, or integrated third-party components.

Please do not include patient data, customer confidential information, or personal data unless it is strictly necessary for Haag-Streit to assess the report.

Alternative reporting method

We recommend using the reporting form above to report a vulnerability, since it ensures we have the required information to process your report. However, if an alternative method is necessary, you may send your report via email.

Email address: product.security@haag-streit.com

Secure communication: For sensitive reports, you may encrypt your email using our PGP public key.