ORCA-CDS is a downtime-continuity tool for viewing Epic order sets. It does not connect to a live EHR, does not place orders, and does not handle patient data — the extracted dataset is order-set template metadata only (see the README's Data & Privacy section). Even so, it is deployed in clinical environments, so security reports are taken seriously.
Please do not open a public GitHub issue for security vulnerabilities. Instead, email the corresponding author (proctors@chop.edu, the contact listed on the published paper -- see CITATION.cff) with:
- A description of the issue and its potential impact
- Steps to reproduce, if applicable
- Any suggested remediation
We aim to acknowledge reports within 5 business days.
In scope: the React/Vite application, the Python data-processing pipeline, and the SQL extract query as published in this repository.
Out of scope: your own Epic environment, your Snowflake/Clarity data warehouse configuration, and any infrastructure you use to host your deployment — these are your institution's responsibility to secure.