Skip to content
Telusuri untuk mempelajari tentang produk dan solusi InterSystems, peluang karier, dan banyak lagi.

Advisory: Inadvertent Exposure of PHI Possible when Exporting Classes from HealthShare

This problem affects the following products:

  • All HealthShare® products, version 2024.1 and above

Requirements:

  • Any customer that exports a persistent class

InterSystems IRIS® versions 2023.1 and later improve SQL performance by storing certain metadata with class definitions.The metadata may include a histogram of property values present in each column.In most cases, this may not be a problem as access to this data is limited to those with administrative access to the database.

However, authorized users may export persistent classes in order to examine properties. The default export of persistent classes includes the histogram of values, potentially revealing those values to anyone who looks at the exported class. These values could include Personal Health Information (PHI), like Patient ID, medications, or other information.

To guard against unintended exposure of PHI, all exports of persistent classes from systems containing PHI must use the following export flag to prevent the metadata from being exported to the file:
/exportselectivity=0

RELATED TOPICS

Latest Alerts & Advisories

16 April, 2026
Advisory ID Product & Versions Affected Risk Category & Score Explicit Requirements IF-9262 InterSystems IRIS® for Health
15 April, 2026
Advisory ID Product & Versions Affected Risk Category & Score Explicit Requirements IF-9396 InterSystems IRIS® for Health
06 April, 2026
Product & Versions Affected Risk Category & Score Explicit Requirements HSIEC-12800 InterSystems IRIS® for Health
26 Maret, 2026
The 2026.1 release of InterSystems IRIS® data platform, InterSystems IRIS® for HealthTM, and HealthShare® Health Connect is now Generally Available (GA). This is an Extended Maintenance (EM) release.
18 Maret, 2026
Product & Versions Affected Risk Category & Score Explicit Requirements DP-449126 InterSystems IRIS® data platform
17 Maret, 2026
Product & Versions Affected Risk Category & Score Explicit Requirements DP-448888 Products:
27 Februari, 2026
The problem affects the following versions of HealthShare Provider Directory: