There are 6 alerts in the HealthShare HS2026-01 Alert communication. Alert Summaries are shown in the table below. Alert details are contained in the PDF document: HS-2026-01-Alert-Document
| Alert | Product & Versions Affected |
Risk Category
|
HS2026-01-01: Unsafe Permission Granted to All Care Community Users | HealthShare Care Community versions prior to 2025.2 | 4-High Risk (Security) |
HS2026-01-02: User Authentication from the FHIR Server APIs is not Logged | HealthShare Unified Care Record, InterSystems IRIS for Health, InterSystems Health Connect versions 2020.2 and later | 4-High Risk (Security) |
HS2026-01-03: Federated SSO Regressions in HealthShare Version 2025.2 | Unified Care Record, Clinical Viewer, Provider Directory, Health Insight, InterSystems EMPI version 2025.2 | 4-High Risk (Operational) |
HS2026-01-04: FHIR Search with Chained Parameters May Reveal Unauthorized Data | HealthShare Unified Care Record, InterSystems IRIS for Health, InterSystems Health Connect versions 2024.1 and later | 4-High Risk (Privacy) |
HS2026-01-05: FHIR Server Reset May Cause Unavailability of Management Portal Pages | InterSystems IRIS for Health, InterSystems Health Connect 2024.2, 2024.3, 2025.1 2025.1.1 | 4-High Risk (Operational) |
HS2026-01-06: FHIR SQL Builder Doesn't Account for FHIR Interactions HardDelete() Method | InterSystems IRIS for Health: 2024.1.0 – 2024.1.4 2025.1.0 – 2025.1.1 2025.2.0 | 3-Medium Risk (Privacy) |
This post is part of the HealthShare Alert communications process. The same information was also distributed by email and posted on the
WRC Distribution Page for InterSystems Documents.
If you have any questions regarding this alert, please contact the
Worldwide Response Center (WRC).







































