Skip to content

Security: Receipts-Health/medicare-pricer

Security

SECURITY.md

Security Policy

medicare-pricer is an open, self-contained Medicare pricing library — it reprices a claims extract against published Medicare fee schedules and foots the result into a report. It touches no network and holds no secrets. We still take the security of the code and its users seriously.

Reporting a vulnerability

Please do not open a public issue for security vulnerabilities.

Report privately to security@receiptshealth.com. Include:

  • a description of the issue and its impact,
  • the affected version or commit,
  • steps to reproduce (a minimal proof of concept if you have one), and
  • any suggested remediation.

You can expect an acknowledgement within 3 business days and a substantive response within 10 business days. We practice coordinated disclosure: we'll work with you on a fix and a disclosure timeline, and we're happy to credit you in the release notes unless you'd rather stay anonymous. Please give us a reasonable window to ship a fix before any public disclosure.

Scope

In scope — anything in this repository: the claims-CSV parser, the pricing and repricing logic, fee-schedule vintage handling, report footing, and their handling of untrusted input (a malformed or malicious CSV, numeric-overflow or rounding abuse, path handling, dependency risk).

Out of scope — the hosted Receipts Health service that consumes this library. Authentication, secrets, storage, and the operational PHI boundary live in a separate, private deployment plane and are not part of this repo.

What is not in this repository, by design

  • No credentials or secrets. The library is offline: a CSV in, a report out. Nothing here reads a key or reaches a network.
  • No PHI. This is a pricing library over CPT/HCPCS codes and fee schedules, not patient data. Test fixtures are synthetic. If you ever find real patient data in this repo or its history, treat it as a security incident and report it privately.

Running it safely

  • Treat every input CSV as untrusted; run in an environment you control.
  • Keep dependencies current (uv sync); we monitor advisories for the pinned set.

There aren't any published security advisories