Potential Protected Information
 
 

Significant Events Report Displays Incorrect Password Details

Issue ID: 45180

Versions Affected

NextGen® Ambulatory v.5.7, v. 5.7 UD1 and v.5.8

The Issue

NextGen Healthcare has identified an issue on the Significant Event report where failed password details are displayed in clear text instead of being encrypted to avoid being seen by other users. This issue could allow users access to the system using the information displayed on the report.

Example

In this example, the user attempts to log into NextGen Ambulatory EHR with an incorrect password. The user successfully logs into the system and navigates to File > Reports > Significant Events. In the Significant Events Report Filter, select Sig Events Msgs from the Settings List. The user clicks the File Open icon and launches the Significant Events Message pop-up. The user searches for Invalid Login Attempt – Username/Password in the Available Message field, adds it to the Included Message field, and clicks OK. The user selects Columns from the Settings List and selects the Sig Msg, Pre Mod, and Post Mod check boxes and clicks OK to generate the report. The user sees the incorrect password attempts are clearly displayed on the report.

screen1

screen2

screen3

screen4

Actions Required


There is no workflow workaround for this issue.

Until this issue is fixed, users may remove the rights to the Significant Event report.  The user should navigate to:  System Administrator > Groups > Rights > Operations > EHR Reporting Tool > Significant Events Reporting and remove the rights to the report.

Status

This issue will be fixed in a future update. Clients who are experiencing this issue can link their practice to existing known issues on the Client Support Center website (http://csc.nextgen.com), under the Known/Fixed Issues tab by selecting the affected product and searching by Issue ID and clicking Add Me!!

All information regarding NewsFlashes can be found on the Client Support Center website (http://csc.nextgen.com), in the NewsFlash Archive section under the Known/Fixed Issues tab.

Thank you for your continued support.
NextGen Healthcare

 
 
 
 

If you no longer wish to receive NewsFlashes, click on the following link: Unsubscribe from NewsFlashes

NextGen Healthcare 795 Horsham Road, Horsham, PA 19044, 215.657.7010

This email and its attachments, if any, may contain confidential or proprietary information and are intended solely for authorized use by the intended recipient(s) only. Any other use of this email is prohibited. If you have received this email in error, you are hereby notified that any retention, disclosure, copying, forwarding, distribution (in whole or in part and whether electronically, written and/or orally) and/or taking of any action in reliance on this email, its contents and/or any attachments thereto is strictly prohibited. If you received this email in error, please notify the sender by replying to this message and permanently delete this email, and any attachments thereto, from your system immediately.