This problem affects the following products:
- Unified Care Record, all versions up to and including 2026.1
- InterSystems EMPI or HealthShare Patient Index, all versions
Requirements:
- A Unified Care Record federation that uses InterSystems EMPI or HealthShare Patient Index as the MPI.
A vulnerability exists in the Registry management portal that could allow unintended display of patient identifiers to authorized administrative users. The correction was implemented in HSPI-5502 and will be included in version 2026.2 of InterSystems EMPI and all future product releases.
The correction is also available as an ad hoc patch for InterSystems EMPI. Affected customers should contact the InterSystems Worldwide Response Center (WRC) to request the correction.







































