Skip to content

Reporting a security issue

Security

If you think you have found a weakness in our website, patient portal or systems, we want to hear from you.

1.How to report it

Email hello@plexuspsychiatry.com with "Security" in the subject line. Please include:

  • What you found, and where - the web address or part of the system
  • How to reproduce it, step by step
  • What you think the impact could be
  • How we can contact you, if you are happy for us to

Please do not include any patient information you may have come across in your report. Tell us it was visible, and we will look.

2.What we will do

  • Acknowledge your report within 5 working days.
  • Look into it, keep you updated, and tell you when it is fixed.
  • Not take legal action against you for research done in good faith and within the rules below.
  • Credit you, if you would like us to, once the issue is fixed.

We are a small clinic and do not run a paid bug bounty.

3.Please do not

  • Access, change or keep any patient or personal information beyond the minimum needed to show the problem exists
  • Do anything that slows down or interrupts our services, such as load or denial-of-service testing
  • Try to trick our staff or patients (phishing or other social engineering), or test our premises
  • Share details of the problem publicly until we have had a reasonable time to fix it

4.What this covers

This website, our patient portal and our clinician systems. Services we use from other companies - Microsoft Teams, Stripe payments, Doctify reviews - have their own reporting routes; please report problems in those directly to them.

If you are a patient worried that your information may have been exposed, please contact us straight away - this is covered by our privacy notice.