Skip to content

Security: Stephonomon/orca-cds

Security

SECURITY.md

Security Policy

ORCA-CDS is a downtime-continuity tool for viewing Epic order sets. It does not connect to a live EHR, does not place orders, and does not handle patient data — the extracted dataset is order-set template metadata only (see the README's Data & Privacy section). Even so, it is deployed in clinical environments, so security reports are taken seriously.

Reporting a Vulnerability

Please do not open a public GitHub issue for security vulnerabilities. Instead, email the corresponding author (proctors@chop.edu, the contact listed on the published paper -- see CITATION.cff) with:

  • A description of the issue and its potential impact
  • Steps to reproduce, if applicable
  • Any suggested remediation

We aim to acknowledge reports within 5 business days.

Scope

In scope: the React/Vite application, the Python data-processing pipeline, and the SQL extract query as published in this repository.

Out of scope: your own Epic environment, your Snowflake/Clarity data warehouse configuration, and any infrastructure you use to host your deployment — these are your institution's responsibility to secure.

There aren't any published security advisories