Report a Security Concern
Found something that doesn't look right? Tell us right away. Fast, clear reporting helps us protect the agencies and individuals who rely on this platform.
How to report
Report suspected unauthorized access, data exposure, account compromise, or another security concern immediately through the designated security contact. Do not include protected client information in an unsecured message.
Designated security contact
Send your report to the designated security contact:
Security Contact
support@doddagencypro.com
Include “Security” in the subject line. Do not include client information, passwords, or security codes.
Reports are routed through the support inbox to the appropriate security and privacy personnel.
| Role | Assigned to | Contact |
|---|---|---|
| Security Official | Assigned personnel | support@doddagencypro.com |
| Privacy Official | Assigned personnel | support@doddagencypro.com |
What to include
The more detail you can safely share, the faster we can respond. Where possible, include:
- A short description of what you observed and why it concerns you.
- When you first noticed it (date and approximate time).
- Where you saw it (page, feature, email, or system involved).
- Whether you believe an account, device, or credential may be compromised.
- How we can reach you for follow-up (name, role, and a phone number or email).
What not to include
Do not include protected client information in an unsecured message. Please leave out:
- Client or individual names, dates of birth, or Medicaid IDs.
- Diagnoses, service notes, or other protected health information (PHI/ePHI).
- Passwords, full credentials, or security codes.
- Screenshots or attachments that reveal protected client information.
If a security concern cannot be described without protected client information, say so in your message and the designated security contact will arrange a secure channel before you share any details.
What happens next
- 1
Acknowledge
The designated security contact confirms receipt and, where appropriate, asks clarifying questions through a secure channel.
- 2
Assess & contain
The team reviews the report, determines severity, and takes appropriate steps to contain a suspected exposure or compromise.
- 3
Investigate
The concern is investigated by the appropriate personnel, and relevant evidence is preserved.
- 4
Notify & remediate
Where required, affected agency customers and individuals are notified consistent with the HIPAA Breach Notification Rule and current HHS OCR guidance, and corrective action is tracked to completion.
A shared responsibility
DODD Agency Pro includes technical and administrative controls intended to support protected workflows. Where an executed BAA applies, it defines the parties' responsibilities. Prompt reporting of security concerns is an important part of that shared responsibility, and we appreciate you taking the time to help.
Last updated: August 12, 2026