Skip to content
Search to learn about InterSystems products and solutions, career opportunities, and more.

Advisory: Web Gateway Apache Web Server Logs Request PHI and Potentially the JWT Token Credential

This problem affects all versions of the following products:

  • InterSystems IRIS® for Health
  • InterSystems Health Connect™
  • HealthShare Unified Care Record®
  • HealthShare® Information Exchange

Requirements:

  • InterSystems FHIR Server with web gateway

Default web gateway containers use a logging format that may expose PHI to administrators reviewing access logs. The FHIR standard allows query parameters (including PHI) to be added directly to query URLs.

Customers are encouraged to assess and modify their web gateway logging configuration to avoid query strings and sensitive fields. Where possible, customers are also encouraged to use FHIR POST queries with sensitive parameters in the request body rather than the URL. See the FHIR search specification for more information.

Latest Alerts & Advisories

Feb 10, 2026
This problem affects all versions the following products prior to 2025.2:
Feb 10, 2026
This problem affects the following products:
Feb 10, 2026
This problem affects all versions of Unified Care Record and Information Exchange.

Sign Up Today

Receive notifications on support alerts, critical issues,
fixes, and product releases.
*Required Fields
Highlighted fields are required
*Required Fields
Highlighted fields are required
By submitting this form, you give consent to receive notifications concerning support alerts, critical issues, important updates, fixes, and product releases via email. In addition, you consent to your business contact information being entered into our CRM solution that is hosted in the United States, but maintained consistent with applicable data protection laws.
**By clicking here, you give consent to be contacted for news, updates and other marketing purposes related to existing and future InterSystems products, offerings, and events.