Report a security vulnerability
Write to us as soon as you see something, even if the picture is incomplete. If a vulnerability is being actively exploited, a legal clock starts the moment we become aware — the sooner we know, the sooner clinics get a fix.
Outside business hours the mailbox alerts our on-call engineer. You do not need to notify any authority yourself — we handle the statutory reporting. We confirm every report and tell you how we assessed it.
This mailbox is the single point of contact for reporting vulnerabilities in MedITEX products with digital elements, as provided for in Article 13 (17) of Regulation (EU) 2024/2847 — the Cyber Resilience Act.
What to put in the first message
Send what you have. Partial information within the hour is worth more than a complete analysis next week.
Product, version, and the affected module or interface
Whether it is being exploited, and what tells you so
When you first saw it, and whether it is still ongoing
Which clinic sites or countries you believe are affected
Anything you have already done to contain it
How we reach you for questions in the next few hours
This address is for security vulnerabilities in MedITEX products. Anything concerning personal data goes to datenschutz@nexus-meditex.de





