NHS England takes security and the protection of private data extremely seriously. If you believe you have found a vulnerability or other issue which has compromised or could compromise the security of our systems and/or private data managed by our systems, please do not hesitate to contact us using the methods outlined below.
PLEASE NOTE: Email and HackerOne are our preferred methods of receiving reports.
If you wish to notify us of a vulnerability via email, please include detailed information on the nature of the vulnerability and any steps required to reproduce it.
You can reach us at:
If you are registered with HackerOne and have been admitted to the NHS Programme, you can report directly to us at: https://hackerone.com/nhs
You can send your report to the National Cyber Security Centre, who will assess your report and pass it on to NHS England if necessary.
You can report vulnerabilities here: https://www.ncsc.gov.uk/information/vulnerability-reporting
We also accept bug reports via OpenBugBounty: https://www.openbugbounty.org/
If you have general enquiries regarding our cybersecurity, please reach out to us at [email protected]