Skip to content
Use the search to find information about InterSystems products and solutions, career opportunities, and more.

Advisory: Inadvertent Exposure of PHI Possible when Exporting Classes from HealthShare

This problem affects the following products:

  • All HealthShare® products, version 2024.1 and above

Requirements:

  • Any customer that exports a persistent class

InterSystems IRIS® versions 2023.1 and later improve SQL performance by storing certain metadata with class definitions.The metadata may include a histogram of property values present in each column.In most cases, this may not be a problem as access to this data is limited to those with administrative access to the database.

However, authorized users may export persistent classes in order to examine properties. The default export of persistent classes includes the histogram of values, potentially revealing those values to anyone who looks at the exported class. These values could include Personal Health Information (PHI), like Patient ID, medications, or other information.

To guard against unintended exposure of PHI, all exports of persistent classes from systems containing PHI must use the following export flag to prevent the metadata from being exported to the file:
/exportselectivity=0

RELATED TOPICS

Latest Alerts & Advisories

03 dec 2025
As customers upgrade InterSystems IRIS® for Health and HealthShare® Health Connect, some have encountered a problem related to mirroring HSSYS, which is caused by a simple misconfiguration. This advisory explains how to avoid that problem.
19 nov 2025
The 2025.3 release of InterSystems IRIS® data platform, InterSystems IRIS® for HealthTM, and HealthShare® Health Connect is now Generally Available (GA). This is a Continuous Delivery (CD) release.
19 nov 2025
Updated Nov 25, 2025 to reflect the complete list of fixes required for ad hoc requests.
10 okt 2025
This alert supersedes the version issued on October 7, 2025. The original alert listed incorrect affected and fixed versions.
07 okt 2025
Risk Category & Score Explicit Requirements DP-443396 InterSystems IRIS® data platform InterSystems IRIS® for Health HealthShare® Health Connect versions 2024.1.0 – 2024.1.4, 2024.2.0, 2024.3.0, and 2025.1.0, and 2025.1.1 HealthShare® Unified Care Record versions 2024.2 and 2025.1 Wrong Results: Low Risk Using Common Table Expressions in Dynamic SQL
07 okt 2025
Risk Category & Score Explicit Requirements HSHC-5268 HealthShare® Health Connect and InterSystems IRIS® for Health versions 2025.1.1 Functional: Medium Risk Occurs when performing SDA3 -> FHIR transformations involving the Encounter resource.
07 okt 2025
This alert has been corrected - please see: October 10 - Correction Notice: Updated Alert for DP-442892
30 sep 2025
In InterSystems IRIS, InterSystems IRIS for Health, and HealthShare Health Connect, versions 2025.1.1 and 2025.2.0, the new “ Mirror Database Download” functionality does not include certain globals.
24 sep 2025
Risk Category & Score Explicit Requirements DP-444551 InterSystems IRIS® data platform InterSystems IRIS® for Health HealthShare® Health Connect versions 2025.1.0, 2025.1.1, and 2025.2