This policy protects FHIR Pilot, test environments and third parties. It applies to the website, requests, connected runs, zero-access reviews and deliverables.
1. Authorised use only
You may request testing only for environments you own or are explicitly authorised to test. You must accurately identify the environment as non-production and comply with its owner’s rules, rate limits and test-data policy.
2. Prohibited data
You must not submit or expose PHI, patient-identifiable information, production records, payment-card data, government identifiers, credentials, private keys, access tokens, endpoint URLs or confidential payloads through the public website or ordinary email.
3. Prohibited technical activity
You must not use FHIR Pilot to access an unauthorised third-party system; evade authentication or security controls; scan private networks; execute denial-of-service activity; introduce malware; perform destructive write operations; exploit a vulnerability; or test production. Production testing is not part of the current service.
4. No misrepresentation
You must not remove scope or limitation labels, present a report as certification, imply regulatory approval, falsify evidence, or claim that a limited result proves compatibility beyond the recorded version, profile, checks, endpoint and time.
5. Zero-access evidence
Evidence supplied for review must be sanitised. Remove patient identifiers, payload bodies, hostnames, tokens and other secrets. You remain responsible for confirming that submitted evidence can lawfully be shared.
6. Enforcement
We may reject, suspend or terminate any request that appears unsafe, unlawful, unauthorised or outside scope. We may preserve limited records and cooperate with lawful requests where necessary to investigate misuse or protect affected parties.
7. Reporting concerns
Report suspected misuse to support@digitalcognitivesolutions.com. Include a request or report reference if available, but do not send credentials, PHI or exploit payloads by email.