medicare-pricer is an open, self-contained Medicare pricing library — it
reprices a claims extract against published Medicare fee schedules and foots the
result into a report. It touches no network and holds no secrets. We still take
the security of the code and its users seriously.
Please do not open a public issue for security vulnerabilities.
Report privately to security@receiptshealth.com. Include:
- a description of the issue and its impact,
- the affected version or commit,
- steps to reproduce (a minimal proof of concept if you have one), and
- any suggested remediation.
You can expect an acknowledgement within 3 business days and a substantive response within 10 business days. We practice coordinated disclosure: we'll work with you on a fix and a disclosure timeline, and we're happy to credit you in the release notes unless you'd rather stay anonymous. Please give us a reasonable window to ship a fix before any public disclosure.
In scope — anything in this repository: the claims-CSV parser, the pricing and repricing logic, fee-schedule vintage handling, report footing, and their handling of untrusted input (a malformed or malicious CSV, numeric-overflow or rounding abuse, path handling, dependency risk).
Out of scope — the hosted Receipts Health service that consumes this library. Authentication, secrets, storage, and the operational PHI boundary live in a separate, private deployment plane and are not part of this repo.
- No credentials or secrets. The library is offline: a CSV in, a report out. Nothing here reads a key or reaches a network.
- No PHI. This is a pricing library over CPT/HCPCS codes and fee schedules, not patient data. Test fixtures are synthetic. If you ever find real patient data in this repo or its history, treat it as a security incident and report it privately.
- Treat every input CSV as untrusted; run in an environment you control.
- Keep dependencies current (
uv sync); we monitor advisories for the pinned set.