LifePoint Informatics Patient Portal
A flaw in LifePoint Informatics Patient Portal versions prior to 3.5.15 allows authenticated users to access sensitive patient information beyond their authorization level. The vulnerability stems from insufficient access controls, permitting a user with valid portal credentials to disclose HIPAA-protected personally identifiable information (PII). LifePoint Informatics deployed the fix (version LPI 3.5.15) in February 2022 as a hosted service update; organizations do not need to perform manual patching.
- Valid Patient Portal login credentials (username/password)
- Network access to the Patient Portal interface
- Knowledge of or ability to enumerate patient record identifiers
Patching may require device reboot — plan for process interruption
/api/v1/advisories/16660519-6ab6-4828-ac8e-15f34d826431Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.