EuroClinics. European healthcare marketplace
  • Clinics
    By specialtyDental · Cardiology · Dermatology · 40+ more By cityMadrid · Paris · Berlin · Istanbul · 27 countries Top-ratedHand-picked clinics this week Health tourismTreatment + travel packages
    Browse all clinics
  • Doctors
    By languageEN · DE · FR · ES · IT · PT · NL · TR By specialty15+ medical specialties Top-ratedVerified credentials · 4.7★+ average Telemed-readyVideo consults, prescription delivery
    Find a doctor
  • Hospitals
    24/7 emergencyTrauma-level I, II, III hospitals JCI-accreditedInternational quality standard International patientsVisa support · multilingual desk Specialty centresCancer · transplant · cardiac · neuro
    All hospitals
  • Pharmacies
    24/7 pharmaciesOpen right now, every night On-call tonightDesignated night-shift roster Travel vaccinationsYellow Fever-authorized centres EU e-prescriptionCross-border eHDSI accepted
    Find a pharmacy
  • Homecare
    Skilled nursingIV therapy, wound care, post-op Palliative careDignity-first home support Postnatal & lactationIBCLC consultants, newborn nurses 24/7 on-callSame-day urgent response
    All homecare providers
Log in Get started
EuroClinics
Clinics Doctors Hospitals Pharmacies Homecare
Pricing For clinics Contact
Log in Get started

Security disclosure policy

Last updated: 2026-05-18

Our commitment

EuroClinics SL welcomes responsible reports of security vulnerabilities and operates a coordinated vulnerability disclosure (CVD) programme aligned with ISO/IEC 29147:2018 and the Directive (EU) 2022/2555 (NIS2) requirements for coordinated disclosure.

Any system at the domains euroclinics.net, *.euroclinics.net is in scope, plus the mobile apps once released. Acıbadem-style or partner-operated sub-domains (when partner-controlled) are out of scope unless we explicitly include them.

How to report

Email: security@euroclinics.net

PGP key + security.txt: /.well-known/security.txt

Please include: a concise description, affected URLs / endpoints, reproduction steps, screenshots or PoC, and any suggested mitigation. Do NOT include real patient data — use a test account or describe the issue abstractly.

Our response

Acknowledgement: within 24 business hours.

Triage + severity assignment (CVSS 4.0): within 5 business days.

Fix targets — Critical: 7 days · High: 30 days · Medium: 60 days · Low: 90 days.

Public disclosure: coordinated within a 90-day window from triage, extendable by mutual agreement.

CVE assignment requested where applicable.

Safe harbour

Provided you act in good faith and within the rules below, EuroClinics SL will not pursue civil or criminal action against you and will not authorise any action against you under the Computer Fraud and Abuse Act-equivalent statutes (e.g. art. 197 ff. Código Penal in Spain, §202a StGB in Germany).

Rules: do not access more data than necessary to demonstrate the issue; do not exfiltrate, modify, or destroy data; do not disrupt service; do not attempt social-engineering or physical attacks; do not test on production patient accounts.

Bug bounty

Discretionary rewards for novel, high-impact reports — typical range €100 to €5,000 (Critical with full exploit chain).

Public hall-of-fame for contributors who consent.

Bounties paid via SEPA / Wise; cryptocurrency available for researchers in jurisdictions where banking is impractical.

Out of scope

Issues already publicly disclosed, denial-of-service, social engineering of staff, physical intrusion, third-party services where we are not the responsible party, and theoretical issues without practical impact.

Self-XSS, clickjacking on pages without sensitive actions, missing security headers without demonstrable exploit — accepted but typically not rewarded.

Reporting an actual breach (NIS2 / GDPR)

If you believe you have evidence of an actual data breach (not just a vulnerability), please mark your email subject "[BREACH-NOTIFY]". Such reports trigger our incident-response procedure and may invoke GDPR Art. 33 (72-hour DPA notification) and NIS2 Art. 23 (24-hour CSIRT notification).

EuroClinics

European healthcare marketplace. Verified clinics, transparent pricing, instant booking — across 27 countries.

EuroClinics SL · Madrid, Spain · GDPR-by-design · EU data residency

Marketplace

  • Clinics
  • Doctors
  • Hospitals
  • Pharmacies
  • Homecare
  • Specialties
  • Cities
  • Health tourism

For providers

  • For clinics
  • For doctors
  • Pricing

Company

  • About
  • Careers
  • Press
  • Blog

Trust & legal

  • Legal notice (Imprint)
  • Terms of service
  • Privacy policy
  • Cookie policy
  • Data processing agreement
  • Accessibility statement
  • Patient rights
  • Trust & Safety
  • DSA transparency

Help & reach us

  • Contact
  • Help centre
  • Your data rights (GDPR)
  • Complaints procedure
  • Speak-up (whistleblower)
  • Security disclosure

Languages

  • English
  • Deutsch
  • Français
  • Español
  • Italiano
  • Português
  • Nederlands
  • Türkçe
© 2026 EuroClinics.net — EuroClinics SL · CIF B-12345678. All rights reserved. Made in the EU · 🇪🇺 · GDPR · DSA · NIS2 compliant

Cookies

We use essential cookies for the site to work. With your consent we also use analytics + marketing cookies to improve EuroClinics. You can change your choice any time on the cookies page.