YourPHR is a self-hosted Personal Health Record viewer — a community continuation of Fasten OnPrem (GPL v3). It stores and displays Protected Health Information (PHI) and personally identifying information (PII), so security and privacy are first-order concerns.
When reporting a bug or a vulnerability — in a GitHub issue, a security advisory, logs, screenshots, or attached files — never include real patient data, personal identifiers, access tokens, secrets, or database files. Reproduce with synthetic data only (e.g. Synthea-generated FHIR bundles). A leak of real PHI is irreversible. If you believe real PHI has actually been exposed somewhere, say so privately (see below) — but do not attach the data itself.
Please report security vulnerabilities privately, not in a public issue:
- Preferred: GitHub private vulnerability reporting — go to the repository's Security tab → Report a vulnerability (GitHub Security Advisories). This keeps the report private until a fix is ready.
- Include: the affected version/commit, a synthetic-data reproduction, the impact, and any suggested fix.
We aim to acknowledge reports within a few days and to coordinate a fix and a disclosure timeline with you. There is no paid bug-bounty program.
YourPHR ships from main (rolling release). Security fixes land on main and the published ghcr.io/jwilleke/yourphr:main-<N> images — run the latest. Older image tags are not separately patched.
- Never commit secrets, keys,
.env, real FHIR bundles, or the SQLite DB. See the "NEVER commit personal health data or unencrypted secrets" section ofAGENTS.md.*.db,/db/,.env,certs/, and key files are gitignored — keep them that way. The.env.*.exampletemplates are committed and must never hold a real value. - DB encryption is on by default. There is no default
jwt.issuer.key— a strong one is generated and persisted at<data>/.jwt_issuer_keyon first start. Pin your own viaYOURPHR_JWT_ISSUER_KEYonly if you have a reason to. - The app is meant to run behind your own authentication and network controls (e.g. a reverse proxy / forward-auth) on a trusted network — it is not hardened for direct exposure to the public internet.
Built on Fasten OnPrem by Jason Kulatunga (@AnalogJ) and contributors (GPL v3); attribution retained.