Security & data handling

What this application does with data, how it is reached, and how to report a problem. Last reviewed 2026-08-28.

What the application is

QUIC Egram Analyzer is a research instrument for electrophysiology studies. It captures unipolar intracardiac electrogram waveforms from a cardiac mapping system's display, extracts the waveform, and records the landmark annotations a reviewer confirms. It is used by clinical investigators as a measurement and record-keeping tool.

What data it holds

Where the data goes

Who can reach what

Transport and browser hardening

Reporting a vulnerability

Reports are welcome and will not be met with legal action for good-faith research: testing that avoids degrading service, avoids accessing or retaining anyone else's data, and gives us a reasonable chance to fix the issue before it is published.

Contact: security@quicscore.org. Machine-readable details are at /.well-known/security.txt (RFC 9116). We aim to acknowledge a report within three business days.

What this is not

This application is not a certified medical device, is not FDA cleared, and is not offered as a diagnostic tool. It is research software, and the scoring algorithm is patent pending (OHSU docket 3528-1). No claim of HIPAA, SOC 2, or HITRUST certification is made or implied. The controls described above are engineering measures in this application; a deployment's overall compliance posture also depends on the host, the network, and the institution's own agreements, which are outside this software.