15 Headers

HTTP Security Headers

Status
Strict-Transport-Security
Good
max-age=31536000; includeSubDomains
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Good
nosniff
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
  • Consider adding 'preload' to HSTS for maximum security
  • Add Content-Security-Policy header to prevent XSS attacks
  • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
  • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
  • Consider adding Permissions-Policy to control browser features

Performance Headers

2 headers
Connection
Performance
close
Vary
Performance
Accept-Encoding

Caching Headers

3 headers
Cache-Control
Caching
no-cache, no-store, must-revalidate
Expires
Caching
-1
Pragma
Caching
no-cache

Content Headers

2 headers
Content-Length
Content
104753
Content-Type
Content
text/html; charset=utf-8

Server Headers

1 headers
Server
Server

CORS Headers

0 headers
No CORS headers found

Cookies Headers

1 headers
Set-Cookie
Cookies
__HL-RequestVerificationToken=CfDJ8JEeYMBcyppAjyU-qyW_thTXdmdj8k6DF2H15HF4XfHp9-gp0H-2ex38iQC9zhmEgHjCbfN5Ofz034hJdAOiChSS7onmvoXeFX_FkKeXvQai4PEMB62FhoFaT2PV0TIVYaXwvzcr9SvccKCTqmp7g2E1; path=/; secure; HttpOnly

Other Headers

4 headers
Content-Security-Policy-Report-Only
Other
img-src https://higherlogicdownload.s3.amazonaws.com/CHANGEHEALTHCARE/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/CHANGEHEALTHCARE/ https://img.youtube.com/vi/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net https://higherlogiclongterm.s3.amazonaws.com/CHANGEHEALTHCARE/ blob: https://d132x6oi8ychic.cloudfront.net 'self' *.trustarc.com *.truste.com; style-src https://d132x6oi8ychic.cloudfront.net 'unsafe-inline' https://higherlogiccloudfront.s3.amazonaws.com https://cdn.jsdelivr.net/jquery.slick/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://d2x5ku95bkycr3.cloudfront.net/ https://ajax.googleapis.com/ajax/libs/jqueryui/ https://use.fortawesome.com/ https://static.filestackapi.com/picker/ https://fonts.googleapis.com/ https://d3uf7shreuzboy.cloudfront.net/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/CHANGEHEALTHCARE/ https://higherlogicdownload.s3.amazonaws.com/CHANGEHEALTHCARE/ https://higherlogiclongterm.s3.amazonaws.com/CHANGEHEALTHCARE/ 'self'; font-src https://fonts.googleapis.com/ https://fonts.gstatic.com/ https://cdn.jsdelivr.net/jquery.slick/ https://higherlogiccloudfront.s3.amazonaws.com https://higherlogicdownload.s3.amazonaws.com/CHANGEHEALTHCARE/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/CHANGEHEALTHCARE/ 'self' https://higherlogiclongterm.s3.amazonaws.com/CHANGEHEALTHCARE/ https://maxcdn.bootstrapcdn.com/font-awesome/ https://d2x5ku95bkycr3.cloudfront.net https://d132x6oi8ychic.cloudfront.net data: *.trustarc.com *.truste.com; script-src-elem https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d3uf7shreuzboy.cloudfront.net/ https://static.filestackapi.com/picker/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d2x5ku95bkycr3.cloudfront.net/ https://cdnjs.cloudflare.com/ajax/libs/prism/ https://www.gstatic.com/recaptcha/ https://static.filestackapi.com/filestack-js/ 'self' https://ajax.aspnetcdn.com/ajax/ 'unsafe-eval' 'unsafe-inline' *.trustarc.com *.truste.com https://cdn.jsdelivr.net/; media-src https://higherlogiclongterm.s3.amazonaws.com/CHANGEHEALTHCARE/ https://higherlogicdownload.s3.amazonaws.com/CHANGEHEALTHCARE/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/CHANGEHEALTHCARE/ https://higherlogicstream.s3.amazonaws.com/CHANGEHEALTHCARE/ 'self' https://d132x6oi8ychic.cloudfront.net; script-src https://higherlogiclongterm.s3.amazonaws.com/CHANGEHEALTHCARE/ https://higherlogicdownload.s3.amazonaws.com/CHANGEHEALTHCARE/ https://ajax.aspnetcdn.com/ajax/ https://cdn.jsdelivr.net/jquery.slick/ https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-ui-1.13.3.min.js https://d132x6oi8ychic.cloudfront.net https://cdn.informz.net 'unsafe-eval' https://use.fortawesome.com/ https://higherlogic-holdingpen-us-east-1.s3.amazonaws.com/CHANGEHEALTHCARE/ https://cdnjs.cloudflare.com/ajax/libs/prism/ 'unsafe-inline' https://d2x5ku95bkycr3.cloudfront.net/ https://higherlogiccloudfront.s3.amazonaws.com https://static.filestackapi.com https://d2x5ku95bkycr3.cloudfront.net/HigherLogic/jquery/jquery-3.7.1.min.js https://d3uf7shreuzboy.cloudfront.net/ 'self' *.trustarc.com *.truste.com *.trustarc.com *.truste.com 'unsafe-inline' 'unsafe-eval' https://*.trustarc.com;; frame-src https://www.google.com/recaptcha/ https://www.recaptcha.net/recaptcha/ https://api.connectedcommunity.org/ 'self' https://www.youtube.com/embed/ https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/ 'self' *.trustarc.com 'self' *.truste.com; connect-src https://upload.filestackapi.com https://static.filestackapi.com https://cloud.filestackapi.com/folder/list/ 'self' https://hl-managedservices.informz.net https://d3uf7shreuzboy.cloudfront.net/ blob: *.truste.com *.trustarc.com; worker-src 'self'; default-src 'self'; base-uri 'self'; frame-ancestors https://*.connectedcommunity.org/ 'self'; object-src 'none'; manifest-src 'self';
Correlation-Id
Other
65ceaa05-d36c-4ddb-af8d-14d5d132e9ee
Date
Other
Fri, 23 Jan 2026 21:27:39 GMT
P3p
Other
CP="IDC DSP COR CUR ADMo OUR IND PHY ONL COM STA"

Recommendations

Enable compression (gzip/brotli) to improve performance