Opens in a new tab

The Overlooked Healthcare Attack Surface: 1,057 FHIR Endpoints and 656 HL7 Systems Found Without Sending a Single Packet

September 28, 2026

By Adrian Cheek, Senior Cybercrime Researcher

For a decade, everyone hunting exposed healthcare infrastructure has looked at the same protocol: DICOM. Open PACS servers spilling X-rays onto the public internet make for a good headline, and the research has been thorough.

But DICOM moves images. The rest of the patient record including admissions, lab orders, results, medications, and the API traffic that patient portals run on, moves over two other protocols entirely: HL7 and FHIR. They are the connective tissue of every hospital. And almost nobody has measured what they look like from the outside.

A 2026 internet-scale study confirmed the blind spot: researchers stood up a honeypot that impersonated DICOM, HL7, and FHIR services and watched who came knocking. The DICOM endpoint was scanned every day. The HL7 and FHIR endpoints, across nine months, drew no observable scanning at all.

So we looked, without touching a single one of them, and found 1,057 FHIR endpoints and 656 HL7 systems sitting in plain sight across North America. What that data shows is a layer with a very different security posture than the imaging story everyone already knows, and in the case of HL7, a more dangerous one.

Key Findings About FHIR Endpoints and HL7 Systems

  • Open FHIR endpoints outnumber guarded ones 3:1. Across 1,057 confirmed FHIR endpoints, 45 answered a request with no authentication challenge at all, against just 15 that demanded credentials. Exposed beats guarded by three to one. In the US the ratio is 40 to 2.
  • HL7 is worse, because the risk is writing, not reading. HL7 v2.x has no authentication by design and exists to push messages into hospital systems. A reachable listener is not a data leak waiting to happen; it is an open input for forged orders, altered results, and tampered medication records. We confirmed 656 HL7 hosts, 17 on live messaging ports.
  • Most FHIR traffic is in the clear. 626 of 1,057 endpoints (59%) run without transport encryption, though much of that is HTTP-by-design rather than stripped TLS.
  • Known-critical bugs are sitting in the open. 28 endpoints run versions of HAPI FHIR carrying CVE-2024-51132 or CVE-2024-52007, both rated 9.8.
  • All of this was found passively. Every number here came from data that was already public. The reconnaissance an attacker would run to find these same systems is the reconnaissance we ran: passive, repeatable, and invisible to the target.

Identity-First-Threat Intelligence

Combine the Knowledge of Exposures with Flare’s Leaked Credential Database

Use Flare to access the infostealer credential database and check which credentials are circulating. Combine this with confirmed exposures to find and delete valid old passwords.

✓ Our collection includes illicit communities spanning the dark web and Telegram
✓ Access to 159M+ stealer logs
Try the Free Trial →

The Number Worth Sitting with

Out of every confirmed, public-facing FHIR endpoint we could see, the ones that answer a stranger’s request with no authentication challenge outnumber the ones that ask for credentials by three to one, at 45 to 15. Narrow it to the US and the gap widens further: 40 open, two guarded.

This finding matters, because it points at the real problem. FHIR is not insecure by nature. The standard ships with SMART-on-FHIR and OAuth 2.0 built in. But a specification is not self-enforcing. Somebody has to turn authentication on, and across the exposed population, most did not. The weakness is not the protocol. It is the deployment.

Transport tells a softer version of the same story. Most of the plaintext we saw sits on HTTP ports by configuration, not because someone stripped TLS off a secure service. That is real, but partly an artifact of how these systems get stood up. Authentication is not an artifact. An endpoint that hands over a resource to anyone who asks made a choice, or failed to make one.

There is a second layer to this that we are measuring next. An open FHIR endpoint is a finding on its own. An open endpoint at an organization whose valid credentials are already circulating in leaked-credential data is an active exposure, not a theoretical one. Cross-referencing the confirmed-exposed operators against that data is the defined next phase of this work, and it will be reported in aggregate.

HL7 Is the Door You Did Not Know Was Open

The FHIR story is about reading data you should not be able to reach. The HL7 story is worse, and it runs the other direction.

HL7 v2.x is old, is everywhere, and it was built for a world where the network was trusted and the wire was private. It has no authentication. It transmits in plaintext. And critically, it is a protocol designed to push: to write messages into the systems that run a hospital. Admissions, discharges, transfers, lab orders and results, and medication records.

So when an HL7 listener is reachable from the internet, the threat is not that someone reads a record. It is that someone writes one. A forged order. An altered result. A changed dose. The same 2026 study that ran the honeypot found that none of the HL7 endpoints it identified used any genuine authentication. The option exists in the standard, and effectively nobody turns it on. We confirmed 656 HL7 hosts across North America, 123 of them in the US and 40 in Canada, with 17 sitting on live messaging ports.

Tampering with a record is a patient-safety event with a security cause. It does not show up in a breach-notification letter, because nothing was stolen. It shows up at the bedside.

What Is Actually Running Out There

The confirmed FHIR population is not a mystery stack. One server dominates it.

HAPI FHIR, the open-source workhorse of the ecosystem, is 655 of the identifiable endpoints, roughly 62% of everything we could fingerprint. That concentration cuts both ways. It means one patch cycle covers most of the field, and it means one old version leaves a lot of doors ajar: 28 of these run releases old enough to carry CVE-2024-51132 or the CVE-2024-52007 XXE flaw, both scored 9.8. OpenEMR accounts for another 44.

A Tale of Two Countries

Scope here is North America, with the full global set carried as the denominator. The two countries do not look alike on the one metric that counts.

The US and Canada are not comparable markets here. The Cures Act compels US organizations to expose patient-facing FHIR APIs, with information-blocking penalties for failing to, while Canada has no federal equivalent and, in most provinces, no FHIR mandate at all. A larger mandated footprint, built against deadlines and often bolted onto legacy HL7 estates, is a plausible driver of the gap. With only 15 confirmed Canadian endpoints, this is a hypothesis the series can test, not a conclusion.

What Healthcare Security Teams Can Do

The hard part is knowing the exposures are there. Once you do, the moves are straightforward:

  • Get these interfaces off the internet. Most of this exposure is a routing or firewall mistake, not a deliberate deployment. Segmentation is one lever; firewalls, reverse proxies, VPNs, and private connectivity are others. Unnecessary reachability is the root cause.
  • Turn on the authentication the standard already gives you. FHIR ships with SMART-on-FHIR and OAuth 2.0. An endpoint that answers with no challenge is the finding. Fix that first.
  • Never leave HL7 in the clear. Wrap MLLP in TLS, a VPN, or IPsec. An unauthenticated plaintext write-channel into your clinical systems is not something to leave facing the internet.
  • Patch HAPI, and know your versions. The CVEs here are 9.8s with public detail. Inventory what you run.
  • Watch your own outside edge, continuously. This is the part where passive measurement changes. Because it never touches production, you can run it on a schedule instead of booking a scanning window once a year. The reconnaissance an attacker does against you is reconnaissance you can do against yourself, every day, without asking anyone’s permission.

The Next Door

DICOM exposure drew a decade of attention because it was visible, scannable, and produced alarming screenshots of patient X-rays online. HL7 and FHIR have drawn almost none, despite carrying the data that actually drives clinical decisions. We’ve documented that healthcare’s front door is already sitting in public scan data in the US and Canada for anyone who cares to look, and that the imaging layer leaks in ways the sector has been slow to close.

This is the next door. It is not the imaging story everyone tells. It is the messaging layer underneath it – the one that writes to the chart, moves the orders, carries the record between systems. Compared with DICOM, it has drawn almost no observable attention. We found it in data that was already public, without sending a single packet at a single hospital. The same publicly indexed information is available to defenders and adversaries alike; the difference is who uses it first.

The organizations that come through this intact will be the ones that start treating HL7 and FHIR as what they are: the part of the attack surface that writes directly to the patient record.

Identity-First-Threat Intelligence

Combine the Knowledge of Exposures with Flare’s Leaked Credential Database

Use Flare to access the infostealer credential database and check which credentials are circulating. Combine this with confirmed exposures to find and delete valid old passwords.

✓ Our collection includes illicit communities spanning the dark web and Telegram
✓ Access to 159M+ stealer logs
Try the Free Trial →

Share article