Skip to content

Security: BUMED-USAMRICD-University-of-Washington/NVIDIA-Rendering-for-Carestreem-Kodak

Security

SECURITY.md

Security Policy (SECURITY.md)

🚨 CRITICAL DEFENSE NOTICE

This repository contains tools, configurations, or research intended exclusively for U.S. Service Members serving within a military medical command (e.g., Navy BUMED, DHA) or participating in an ROTC detachment embedded at an accredited University Hospital (e.g., University of Washington).

All contributors and users are strictly bound by the Uniform Code of Military Justice (UCMJ), operational security (OPSEC) guidelines, and institutional research policies.


🔒 Operational Security (OPSEC) Guidelines

To maintain national security and protect military health infrastructure, you must adhere to the following rules prior to any interaction with this repository:

  • No Unclassified/PII Leakage: Never upload Protected Health Information (PHI), Personally Identifiable Information (PII), or operational troop movements.
  • No Classfied Data: This repository is strictly for Unclassified / Controlled Unclassified Information (CUI) handling software. Absolutely no Secret, Top Secret, or higher-tier network data may ever touch this repository.
  • Sanitize Code: Remove all local IP addresses, server names, specific base names, and credentials/API keys before creating a pull request.
  • Profile Disclosure: If your personal GitHub profile explicitly lists your deployment status, unit, or precise military location, use an anonymized or institutional GitHub account for contributions.

🛡️ Supported Versions

Only the latest active release branch of our software is supported with security updates.

Version Supported Notes
v2.x Current active deployment baseline.
v1.x EOL. Upgrade to v2.x immediately.

⚠️ Reporting a Vulnerability

DO NOT open a public GitHub issue for security vulnerabilities or OPSEC breaches.

If you discover a software vulnerability, an unintentional leak of sensitive operational data, or a potential infrastructure risk, follow this secure reporting pipeline:

  1. Isolate: Stop using the affected branch immediately in any local laboratory or medical simulation network.
  2. Encrypt & Report: Draft an email detailing the vulnerability. Encrypt the message using the authorized organization PGP public key (found in the root directory or requested from leadership).
  3. Submit: Send the report directly to the VTCNL Inter-Agency Review Board or your designated Military Command Information Assurance (IA) officer.
  4. Triage: A secure response team will evaluate the bug within 48 hours and provide a remediation path via a private security advisory.

⚖️ Compliance & Governance

By interacting with this repository, you certify that your access aligns with:

  • DoD Instruction 8500.01 (Cybersecurity)
  • HIPAA / Privacy Act of 1974 guidelines regarding medical data
  • Your specific ROTC Detachment or Medical Command local computing regulations

There aren't any published security advisories