Coordinated Vulnerability Disclosure Policy

1. Purpose

The purpose of this policy is to describe how Freenome shall perform and document the disclosure of cybersecurity vulnerabilities within Freenome products and services that contain medical device software. This policy guides compliance with section 524B(b)(1) of the FD&C Act, as referenced in the FDA’s Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions issued September 27, 2023.

2. Scope

The scope of this policy applies to all Freenome products and services that contain medical device software.

3. Coordinated Vulnerability Disclosure Policy

The following coordinated vulnerability disclosure policy will be posted on Freenome’s website.

3.1. Website Content Addressing Freenome’s Policy

Welcome to Freenome’s Coordinated Vulnerability Disclosure Page

Freenome has mechanisms in place to identify and address vulnerabilities in its products and respond to the requirements of its customers and patients as well as authorities. At Freenome, we are committed to protecting and securing information associated with Freenome connected medical devices and information in order to protect the security and safety of patients and to comply with federal, state, and local laws.

This page describes Freenome’s process for receiving reports related to potential cyber security vulnerabilities in its products and the company’s standard practice for informing customers and other required stakeholders of verified vulnerabilities.

If you have discovered a security vulnerability, we appreciate your help in disclosing it to us in a responsible manner.

Reporting a Vulnerability

We welcome reports from security researchers, industry partners, academia, and other users. To report a security vulnerability in our products, please use the following guidelines.

How to Report

  • Please contact us by sending an email to productsecurity@freenome.com. We will work with you to determine a secure solution to share your findings with us.
  • Once the secure form of communication has been established, please provide as much information as possible about the vulnerability, such as the following:
    • Product name, URL, or affected version information
    • The type of vulnerability (e.g., buffer overflow, SQL injection, cross-site scripting, etc.)
    • A description of the vulnerability and how it can be reproduced
    • The potential impact of the vulnerability
    • Any steps, tools, code, or scripts to reproduce the vulnerability
    • Reporter’s contact information
    • Time and date of discovery

What to Expect

  • Acknowledgment: We will acknowledge receipt of your vulnerability report within 5 business days.
  • Communication: We will keep you informed of the progress towards a fix and full announcement, and we may contact you for additional information about the vulnerability.
  • Confidentiality: Please keep your findings confidential between us until a fix has been developed and deployed.
  • Safe Harbor: We aim to keep all parties safe. If you follow these guidelines when reporting an issue to us, we commit not to pursue legal action against you.
  • Freenome is dedicated to reading and providing responses to reports of potential software security vulnerabilities in a timely manner.
  • Publishing vulnerability advisories: Freenome intends to publish vulnerability advisories to enable users to identify vulnerable products and services and take action to remediate confirmed vulnerabilities.

Our Commitment

Upon receiving a vulnerability report, Freenome commits to the following:

  • Promptly acknowledging receipt of your report
  • Providing an estimated timeline for addressing the vulnerability
  • Notifying you when the vulnerability is fixed
  • As Freenome’s diagnostic products are provided as a service, no external distribution of the software is needed.

Recognition

While we do not have a formal bug bounty program, we recognize and appreciate the effort and contribution of security researchers.

Legal Notice

This policy is intended to encourage the responsible disclosure of vulnerabilities and not to give permission to act in any manner that is inconsistent with the law or to conduct penetration testing on Freenome systems without explicit permission.

Thank you for helping to keep Freenome and our users safe.

4. References

Document Identifier Title
N/A “Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions.” Center for Devices and Radiological Health, et al., Food and Drug Administration, U.S. Department of Health and Human Services, September 27, 2023.

5. Appendices

Not applicable

6. Attachments

Not applicable

7. Change History

Rev Changes Authors
1 New document. George Morris
2 Changes under section 3.1 to clarify Freenome’s intent to have a Cybersecurity Coordinated Vulnerability Disclosure Page, updates to section “What to Expect” to change the acknowledgement time from 3 to 5 days, include publishing vulnerability advisories, updates to section “Recognition” to remove acknowledgements on our website. Document formatting updated to align with current template. Mahitha Thammareddy

You are leaving this website

By selecting this link, you are leaving the Freenome website and will be directed to another web page.