Skip to content
搜索以了解InterSystems产品和解决方案,职业机会等。

Alert: HS2022-01: Multiple InterSystems IRIS for Health & HealthShare Alerts

March 1, 2022

There are 22 alerts in the HealthShare HS2022-01 Alert communication. The Alert Summary is in the table below, and the detail is contained in the attached document: HS2022-01-Communication

AlertProduct & Versions AffectedRisk Category
HS2022-01-01: Vaccination Dates Misrepresented in Some CircumstancesAll versions of:
Information Exchange
Unified Care Record
Personal Community
HealthShare Health Connect
InterSystems IRIS for Health

3-Medium Risk
(Operations)

2-Low Risk
(Clinical Safety)

HS2022-01-02: Invalid Handling of Multiple Reference Ranges in CDA and C-CDA DocumentsAll versions of:
Information Exchange
Unified Care Record (through 2021.1)
3-Medium Risk
(Clinical Safety)
HS2022-01-03: Security Check for Emergency Access to Patient Records Fails to Occur in Some SituationsAll versions of:
Information Exchange
Unified Care Record (through 2020.2)
3-Medium Risk
(Privacy)
HS2022-01-04: Security Vulnerability in Unified Care Record 2020.2.0Unified Care Record:
2020.2.0 (Build 8620)
4-High Risk
(Security)
HS2022-01-05: Customers on Unified Care Record 2020.2 and 2021.1 Must Install a Patch Before Upgrading to a Later Version

Version 2020.2, 2021.1 of:
Unified Care Record
Clinical Viewer
Health Insight
Patient Index
Personal Community
Care Community

Version 2020.2, 2021.1, 2021.2, 2021.3 of:
Provider Directory

4-High Risk
(Operations)
HS2022-01-06: Configuring the Classic Clinical Viewer Requires Outdated Third-Party SoftwareAll versions of:
Unified Care Record (Classic Clinical Viewer only)
4-High Risk
(Security)
HS2022-01-07: Users may not be able to Log Out of Clinical ViewerAll versions of:
Information Exchange
Unified Care Record (through 2020.2)
4-High Risk
(Privacy)
HS2022-01-08: Access Gateway Aggregation Cache Grows over TimeUnified Care Record:
2020.1, 2020.2, 2021.1, 2021.2
2-Low Risk
(Operations)
HS2022-01-09: Incompatibility in HL7toSDA3 Customizations when Upgrading from HealthShare 15.03 or earlierInformation Exchange:
15.03 or earlier (when upgrading to Unified Care Record)
Not Rated
HS2022-01-10: IHE Endpoints should use Appropriate CredentialsAll versions of:
Information Exchange
Unified Care Record
3-Medium Risk
(Security)
HS2022-01-11: ODS Namespace Reactivation Can Result in Prolonged DowntimeUnified Care Record:
2019.1, 2019.2

4-High Risk
(Operations)

1-Very Low Risk
(Clinical Safety)

HS2022-01-12: Upgrade of ODS may Require Manual Intervention to CompleteUnified Care Record:
2020.1 (when upgrading to version 2020.2)
5-Very High Risk
(Operations)
HS2022-01-13: ODS Audit Data Inaccessible after Upgrade to Version 2020.1Unified Care Record:
2019.1 or 2019.2 (when upgrading to 2020.1)
3-Medium Risk
(Privacy)
HS2022-01-14: System-wide and Facility-level Clinical Consent Policies Ignore Event DatesAll versions of:
Information Exchange
Unified Care Record (through 2021.1)
2-Low Risk
(Privacy)
HS2022-01-15: FHIR Requests Not Being Evaluated Properly for ConsentUnified Care Record:
2020.1
4-High Risk
(Privacy)
HS2022-01-16: FHIR “$everything” Operation Can Return Unconsented DemographicsAll versions of:
Information Exchange
Unified Care Record (through 2021.1)
3-Medium Risk
(Privacy)
HS2022-01-17: FHIR Index Performance Issue Can Cause ODS Instability

Information Exchange:
2018.1

Unified Care Record:
2019.1, 2019.2

5-Very High Risk
(Operations)
HS2022-01-18: Security Vulnerability in FHIR Gateway/FHIR Server

Unified Care Record:
2021.1

InterSystems IRIS for Health:
2021.1

3-Medium Risk
(Security)
HS2022-01-19: FHIR Server Does Not Verify Token Revocation

Unified Care Record:
2020.1, 2020.2, 2021.1

InterSystems IRIS for Health:
2020.4, 2021.1

HealthShare Health Connect:
2020.4, 2021.1

3-Medium Risk
(Security)
HS2022-01-20: OAuth Token Scope Not Applied in FHIR Batch Transaction BundlesInterSystems IRIS for Health:
2021.1

3-Medium Risk
(Privacy)

2-Low Risk
(Security)

3-Medium Risk
(Operations)

HS2022-01-21: FHIR Server Interoperability REST Client does not Properly Clean Up Data

InterSystems IRIS for Health:
2020.2, 2020.3

HealthShare Health Connect:
2020.2, 2020.3

4-High Risk
(Operations)
HS2022-01-22: Security Issue in Patient IndexAll versions of:
Patient Index (through 2021.2)
4-High Risk
(Security)

This post is part of the HealthShare HS2022-01 Alert communications process. The same information is also distributed:

If you have any questions regarding this alert, please contact the Worldwide Response Center (WRC).

最新警报和通知

Aug 21, 2024
InterSystems 已修复了一个缺陷,在极少数情况下,该缺陷可能导致多卷数据库出现数据库损坏或 错误。只有被截断的数据库才存在风险。
Jun 03, 2024
从发布InterSystems IRIS®数据平台2022.3开始,InterSystems修改了许可证强制执行机制,以包括REST和SOAP请求。由于这种变化,在升级后,使用REST或SOAP的非处理器核数的许可证环境下,用户可能会遇到更高的许可证消耗。要确定此警报是否适用于您的InterSystems许可证,请按照下面链接的FAQ中的说明进行操作。
May 01, 2024
InterSystems has corrected an issue that can cause a small number of SQL queries to return incorrect results. See below for the specifics on impacted queries.
Nov 14, 2023
There are 10 alerts in the HealthShare HS2023-02 Alert communication. An alert summary for each issue is shown is in the table below. Details for each alert are contained in the attached document: HS2023-02-Communication.
Jun 17, 2023
InterSystems 已纠正导致进程内存使用量增加的缺陷。
May 11, 2023
InterSystems已经解决了影响Caché、Ensemble、HealthShare、InterSystems IRIS、InterSystems IRIS for Health、HealthShare HealthConnect和TrakCare的安全漏洞。 这些漏洞影响到InterSystems所有版本的产品。
Apr 28, 2023
InterSystems 已修复了一个缺陷,该缺陷可能会导致使用 IBM POWER8 或更高版本的 POWER 处理器的 AIX 系统上的数据库和Journal日志文件损坏。只有在使用数据库或Journal日志加密时才会触发此缺陷。
Apr 11, 2023
InterSystems已修复一个缺陷,该缺陷在罕见情况下会导致ECP客户端不稳定。
Apr 06, 2023
InterSystems 已修复一个导致SQL查询返回不正确结果的缺陷。该缺陷存在于以下产品和基于这些产品的任何InterSystems产品中。