Last updated: October 28, 2025
Responsible Disclosure
BeWell Grace Medical, LLC provides telehealth-only virtual care in Florida. We do not offer in-person visits or walk-ins. Patients must be physically located in Florida at the time of care. BeWell Grace Medical operates on a self-pay only basis.
Keeping our systems secure
Protecting patient privacy, system integrity, and data security is a top priority. We maintain administrative, technical, and organizational safeguards across our website, telehealth platforms, and internal systems.
We welcome responsible disclosure of security vulnerabilities so we can investigate and remediate issues promptly. This policy explains how to report potential security concerns and what to expect from us.
How to report a security issue
If you believe you have identified a security vulnerability affecting BeWell Grace Medical systems, report it directly to our security team:
- Email: [email protected]
Please include the following in your report:
- A clear description of the vulnerability and potential impact
- Steps to reproduce the issue, including URLs or endpoints
- Relevant screenshots, logs, or timestamps
- The date, time, and method used during testing
What to report
- Security weaknesses in web or telehealth applications
- Authentication or authorization flaws
- Unintended data exposure risks
- API or integration security issues
Responsible testing guidelines
- Stop testing immediately if you encounter any personal or medical data
- Do not access, modify, or exfiltrate patient, provider, or employee information
- Do not disrupt services or degrade system performance
- Do not perform denial-of-service, phishing, social engineering, or physical testing
- Use the least intrusive method necessary to demonstrate the issue
- Allow reasonable time for investigation and remediation before public disclosure
Compensation
BeWell Grace Medical does not offer bug bounties or monetary compensation for vulnerability reports. We appreciate ethical researchers who follow this policy and help us improve system security. With your consent, significant contributions may be acknowledged.
What to expect from us
- Receipt acknowledgment within 3 business days
- Validation and internal review of the reported issue
- Follow-up communication if additional information is needed
- Confirmation once remediation is complete, when appropriate
Confidentiality and coordination
If you provide contact information, we will communicate respectfully and in good faith. We ask that vulnerabilities not be publicly disclosed until we have had a reasonable opportunity to investigate and address the issue.
Related policies
Emergency notice
BeWell Grace Medical does not provide emergency care. If you believe there is an immediate threat to life or safety, call 911 or contact local emergency services.
If a clinician recommends an in-person evaluation, it means with another provider, clinic, or hospital—not BeWell Grace Medical.
