HotDoc

  • $50 – $8,000 per vulnerability
  • Partial safe harbor

Patient Credentials

Hello Researchers!

We've updated how you can get patient credentials for this program. Please take a look at the below steps and please let us know if you have any questions!

How to get patient credentials, bypassing email, mobile phone and strong password verification:

  1. Go to https://staging.hotdoc.com.au/patients/new
  2. Enter an email address
  3. Enter a password with confirmation (for the purposes of testing, we are not enforcing strong password requirements here)
  4. A demo patient will be created
  5. You can now log into the patients portal at https://staging.hotdoc.com.au/

Please note:

  • The credential generation feature is out of scope, as it is visible for the Bug Bounty deployment only - in production, patients must verify their mobile number.
  • Whilst creating a few accounts for testing purposes is fine, please do not create more than a handful of accounts in a short amount of time (especially with an automated tool) as the demo data seeding process is quite intensive.

If you have any questions, please reach out to support@bugcrowd.com.