Ohio’s Turn-Key DODD Compliance Platform.Not affiliated with the Ohio Department of Developmental Disabilities
Security

Report a Security Concern

Found something that doesn't look right? Tell us right away. Fast, clear reporting helps us protect the agencies and individuals who rely on this platform.

How to report

Report suspected unauthorized access, data exposure, account compromise, or another security concern immediately through the designated security contact. Do not include protected client information in an unsecured message.

Designated security contact

Send your report to the designated security contact:

Security Contact

support@doddagencypro.com

Include “Security” in the subject line. Do not include client information, passwords, or security codes.

Reports are routed through the support inbox to the appropriate security and privacy personnel.

RoleAssigned toContact
Security OfficialAssigned personnelsupport@doddagencypro.com
Privacy OfficialAssigned personnelsupport@doddagencypro.com

What to include

The more detail you can safely share, the faster we can respond. Where possible, include:

  • A short description of what you observed and why it concerns you.
  • When you first noticed it (date and approximate time).
  • Where you saw it (page, feature, email, or system involved).
  • Whether you believe an account, device, or credential may be compromised.
  • How we can reach you for follow-up (name, role, and a phone number or email).

What not to include

Do not include protected client information in an unsecured message. Please leave out:

  • Client or individual names, dates of birth, or Medicaid IDs.
  • Diagnoses, service notes, or other protected health information (PHI/ePHI).
  • Passwords, full credentials, or security codes.
  • Screenshots or attachments that reveal protected client information.

If a security concern cannot be described without protected client information, say so in your message and the designated security contact will arrange a secure channel before you share any details.

What happens next

  1. 1

    Acknowledge

    The designated security contact confirms receipt and, where appropriate, asks clarifying questions through a secure channel.

  2. 2

    Assess & contain

    The team reviews the report, determines severity, and takes appropriate steps to contain a suspected exposure or compromise.

  3. 3

    Investigate

    The concern is investigated by the appropriate personnel, and relevant evidence is preserved.

  4. 4

    Notify & remediate

    Where required, affected agency customers and individuals are notified consistent with the HIPAA Breach Notification Rule and current HHS OCR guidance, and corrective action is tracked to completion.

A shared responsibility

DODD Agency Pro includes technical and administrative controls intended to support protected workflows. Where an executed BAA applies, it defines the parties' responsibilities. Prompt reporting of security concerns is an important part of that shared responsibility, and we appreciate you taking the time to help.

Last updated: August 12, 2026