Legend
| A new feature | |
| An existing feature has changed | |
| A bug fix | |
| A performance improvement | |
| A security issue has been corrected |
| Released | 2026-11-19 |
| Codename | TBD |
| HAPI FHIR | Smile CDR 2026.11.R01 is based on HAPI FHIR 8.14.0, and includes all changes and fixes included in this version. Please see the HAPI FHIR ChangeLog for details about what has changed. |
MySQL is no longer a supported database platform for Smile CDR, and the MySQL JDBC driver is no longer shipped with the product. MySQL had been deprecated since 2021.11.R01 because of its performance limitations. Any node whose Cluster Manager, FHIR Storage, Audit Log or Transaction Log database is configured with the MYSQL_5_7 driver type will fail to start after upgrading.
The clients handed out by SmileHarness in cdr-public-test-utils now issue on a single pooled HTTP client per harness, rather than each building one of their own. The following are visible to tests written against the previous release.
getAdminJsonClient(), getHL7V2RestClient(), getNpmPackageClient() and getOutboundSmartClient()
previously each built a cookie store of their own, so a login through one was invisible to the others.
They now all issue on the harness's HTTP client and share its cookie store, which is what lets a multi-request login flow work across them. The FHIR clients from getFhirClient(...) are unaffected —
they are HAPI IGenericClients with their own transport.
Check any test that asserts a request is rejected. On the shared session such a request can now be answered as whoever logged in last, so it may pass for the wrong reason. Build it with
fhirAnonymousRequest(...) or anonymousRequest(...), which send no cookies, or call
harness.clearCookies() first. See
Sessions, Cookies and Harness Lifecycle.
HL7V2RestClient no longer follows redirectsHL7V2RestClient.build(baseUrl, username, password) previously used Spring's auto-detected request factory, which follows redirects. It now uses the same client as every other Smile test client, which has redirect handling disabled — so a 3xx is returned as-is, matching AdminJsonRestClient and
NpmPackageClient. A test that relied on the redirect being resolved must follow the Location header itself.
The client is now AutoCloseable. One you build yourself with build(...) owns the connection pool behind it and should be closed when the test is done with it. One obtained from a harness borrows the harness's pool, so closing it leaves that pool up for the harness's other clients.
RequestFactoryUtil.buildSmileRequestFactory() removedUse RequestFactoryUtil.wrap(...) instead, passing a client you own — or, inside a test, the one
SmileHarness.getHttpClient() already holds, so the resulting RestClient shares the harness's session and pool:
RestClient restClient = RestClient.builder()
.requestFactory(RequestFactoryUtil.wrap(harness.getHttpClient()))
.baseUrl(baseUrl)
.build();
SmileHarness gained methods and is now AutoCloseableThe interface declares the new request builders (fhirRequest, fhirAnonymousRequest, request,
adminJsonRequest, anonymousRequest, getHttpClient, clearCookies, close). A custom implementation of SmileHarness must implement them; tests that only use the interface need no change.
SmileCdrContainer.getHarness() caches its harnessIt returns the same harness on every call instead of a new one, and closes it when the container stops —
so you do not need to close a container-supplied harness yourself. A harness reads the node's module configuration once, when it is built; after changing module configuration through the Admin JSON API, call
container.refreshHarness() and use the harness it returns.
MockHttpServer removedThe class was an empty placeholder and had no implementation to replace.
Debugging a Smile CDR server's JavaScript Execution Environment in a dockerized environment will now no longer work in all cases.
This is due to a security fix. Check the documentation for details.
|
The Persistence module now warns at startup when Search Parameter Seeding patterns disable built-in terminology SearchParameters on |
|
|
A FHIR endpoint secured with SMART on FHIR must serve its |
|
|
Smile CDR now supports running in a container with a read-only root filesystem. When read-only filesystem mode is enabled, logging is routed to |
|
|
An MDM module configured with |
|
|
Entries in the SMART Outbound Security module's |
|
|
Generally Available (GA) Releases are stable for production. A non-GA release (eg: PRE releases) will now log a warning on startup. Additionally a banner warning will appear in web-admin console. |
|
|
The CDA Exchange+ module now supports Instruction entries in the Plan of Treatment section. These entries map to |
|
|
Added a property "ignore placeholder resources". If set true, MDM matching will skip placeholder resources during matching (by default, this is false to preserve existing functionality). |
|
|
Added configuration options to set warning and max thresholds for MDM matching. For how MDM matching, deduplication and bundle matching handle a resource that reaches the max threshold, see Resources Omitted From MDM Matching. |
|
|
The CDA Exchange+ module maps a Comment Activity entry embedded within a Medication Activity onto the |
|
|
The CDA Exchange+ module now supports mapping from an Instruction entry relationship within a Medication Activity entry onto corresponding fields of the MedicationStatement and MedicationRequest resources. |
|
|
The CDA Exchange+ module now supports the Procedure Activity Act entry in the Procedures section. These entries map to |
|
|
The CDA Exchange+ module now supports a Comment Activity entry embedded within a Procedure Activity Procedure element. |
|
|
The CDA Exchange+ module now supports Advance Directive Observations and Advance Directive Organizers within the Advance Directives section. |
|
|
The CDA Exchange+ module now supports the Assessment Scale Observation as an entry in the Functional Status section. |
|
|
The CDA Exchange+ module now supports a Comment Activity entry embedded within a Family History Observation element. |
|
|
The CDA Exchange+ module now supports the Health Status Observation as an entry in the Health Concerns Section. |
|
|
The CDA Exchange+ module now supports the Precondition for Substance Administration element within a Medication Activity entry, for the data import path only. |
|
|
The CDA Exchange+ module now supports the Medical (General) History section as a narrative-only section. |
|
|
|
|
|
The Test Utilities REST clients now name their connection-pool ownership at the call site. |
|
|
Smile CDR now includes a |
|
|
Added unauthenticated |
|
|
Added an unauthenticated |
|
|
Added a |
|
|
The Pre-Assigned Patient Identifier Systems and Document Repository features now work on any FHIR Storage (RDBMS) module with a Patient ID Partitioning mode enabled. Previously these features only worked when MegaScale was in use. |
|
|
Previously, when SAML authentication was enabled on a Web Admin Console module, the console login page offered no way to initiate the SAML login flow; users had to browse directly to the |
|
|
Azure Blob Storage binary storage can now authenticate using Azure Managed Identity or Workload Identity instead of a stored account key, client secret or SAS token. See External Object Storage for details. |
|
|
The Batch Job endpoint response for fetching batch jobs by filters ( |
|
|
|
|
|
Request and Response validation for the |
|
|
The MDM documentation now describes the concurrency risks of raising the MDM module's |
|
|
Previously, when using the |
|
|
The documentation search in the Web Admin Console help pages now queries the same hosted documentation search index as smilecdr.com, returning results for the running Smile CDR version grouped by page and section. The search requires outbound HTTPS access to the documentation search service; when it cannot be reached the search shows a "search unavailable" message. |
|
|
The HL7v2 MLLP inbound listener now supports an optional |
|
|
The HL7v2 MLLP inbound listener now supports an optional |
|
|
The HL7v2 MLLP inbound listener now supports an optional |
|
|
The |
|
|
The Prior Auth PAS module's |
|
|
MySQL is no longer a supported database platform, and the MySQL JDBC driver is no longer shipped with Smile CDR. Modules configured with the |
|
|
Previously the swagger ui request to list openid connect servers ( |
|
|
Previously, downloading the system configuration bundle with Include Logs enabled from the Admin Console (or the |
|
|
Previously, a bulk export initiated by a SMART client holding a filtered read-only scope, such as |
|
|
Previously, when using Pulsar as the message broker, a restarted module (e.g. MDM) could be unable to send messages, because Pulsar rejected its new producer while the old one still held the same name, and the old producers stayed connected until Smile CDR shut down. Pulsar now names each producer, and a module closes its producers, including those used by Realtime Export, channel retry and the transaction log broker, when it shuts down. A |
|
|
Previously, when a document Bundle was created in a transaction with MegaScale Document Repository mode enabled, a |
|
|
The |
|
|
Previously, when the target (ingesting side) of a P2P |
|
|
Previously, a search that was automatically narrowed to a very large number of compartments (for example for a user with tens of thousands of |
|
|
Previously, |
|
|
Package loading now matches HTTP redirect targets against the package URL whitelist before following them. See Package URL Redirects for details. |
|
|
The FHIR Storage module now restricts the locations from which NPM packages (Implementation Guides) can be loaded. Previously packages could be loaded from any file, classpath, or remote URL. Administrators must now configure a whitelist of permitted URL prefixes via the |
|
|
Channel Import and the Smile Camel processors can now restrict which FHIR partitions an inbound message may access, closing a cross-partition read/write escape when configured. Set the permitted partitions via the Channel Import module's new |
|
|
Previously, a JavaScript Execution Environment script could call |
|
|
Previously, the JavaScript Execution Environment |
|
|
Previously, the |
| Released | 2026-09-14 |
| Codename | Evolution |
| HAPI FHIR | Smile CDR 2026.08.R02 is based on HAPI FHIR 8.12.1, and includes all changes and fixes included in this version. Please see the HAPI FHIR ChangeLog for details about what has changed. |
The mechanism used to import the LOINC CodeSystem has been completely redesigned for better performance and visibility. See Uploading LOINC for information about the new mechanism.
To fix duplicate resources appearing on multiple pages of paginated Patient/$everything responses (GL-8701), the FHIR Gateway now uses the HAPI default BASED_ON_INCLUDES bundle-inclusion rule (previously BASED_ON_RESOURCE_PRESENCE).
A side effect of this fix is that the gateway no longer relays referenced resources that a target server attaches to a search response on its own initiative.
_include or _revinclude are unaffected; the resources each target returns as search.mode = include still come through._include or _revinclude.Patient/$everything has the same include set as before; the only observable difference is that cross-page duplicates no longer occur.The MDM endpoints on the JSON Admin API (under /mdm/{module_id}/...) are deprecated as of 2026.08.PRE and are scheduled for removal in 2028.08.R01 or later (GL-8729). They are flagged deprecated: true in the generated OpenAPI spec.
Use the corresponding FHIR $mdm-* operations on the cdr-endpoint-fhir module instead, so requests pass through the platform's full authorization model. See the JSON Admin API MDM Deprecation Migration guide for the full endpoint mapping.
The mdm-algorithms and mdm-metrics endpoints on the JSON Admin API are not deprecated.
The deprecated CDA Exchange module (module.cda.type=CDA_EXCHANGE) has been removed.
See CDA Exchange Plus for configuration details.
The FHIR_OP_INITIATE_BULK_DATA_IMPORT permission is no longer implicitly granted through SMART authorization. To grant this permission in a SMART session, use the callback function onSmartScopeAuthorityNarrowing().
Spring LDAP has been updated to address CVE-2026-41720. An LDAP bind that supplies a distinguished name together with an empty password is an unauthenticated bind under RFC 4513, and is now rejected. Note that user authentication in the LDAP Inbound Security Module is unaffected, as empty passwords were already rejected before reaching Spring LDAP.
What this does affect is the module's system user connection, which is used to search the directory.
Before upgrading, check whether ldap.systemuser.dn is configured while
ldap.systemuser.password is left blank. Such a module will no longer start.
To resolve, either set a password for the system user, or clear ldap.systemuser.dn so that the module connects to the directory anonymously. A blank DN together with a blank password remains a valid anonymous connection and is unaffected.
The Sandbox functionality in the AppSphere module has been deprecated. Clients are advised to set up a separate AppSphere module in their lower environments for developers to register account and application(s) for testing purposes.
| Released | 2026-08-27 |
| Codename | Evolution |
| HAPI FHIR | Smile CDR 2026.08.R01 is based on HAPI FHIR 8.12.0, and includes all changes and fixes included in this version. Please see the HAPI FHIR ChangeLog for details about what has changed. |
The mechanism used to import the LOINC CodeSystem has been completely redesigned for better performance and visibility. See Uploading LOINC for information about the new mechanism.
To fix duplicate resources appearing on multiple pages of paginated Patient/$everything responses (GL-8701), the FHIR Gateway now uses the HAPI default BASED_ON_INCLUDES bundle-inclusion rule (previously BASED_ON_RESOURCE_PRESENCE).
A side effect of this fix is that the gateway no longer relays referenced resources that a target server attaches to a search response on its own initiative.
_include or _revinclude are unaffected; the resources each target returns as search.mode = include still come through._include or _revinclude.Patient/$everything has the same include set as before; the only observable difference is that cross-page duplicates no longer occur.The MDM endpoints on the JSON Admin API (under /mdm/{module_id}/...) are deprecated as of 2026.08.PRE and are scheduled for removal in 2028.08.R01 or later (GL-8729). They are flagged deprecated: true in the generated OpenAPI spec.
Use the corresponding FHIR $mdm-* operations on the cdr-endpoint-fhir module instead, so requests pass through the platform's full authorization model. See the JSON Admin API MDM Deprecation Migration guide for the full endpoint mapping.
The mdm-algorithms and mdm-metrics endpoints on the JSON Admin API are not deprecated.
The deprecated CDA Exchange module (module.cda.type=CDA_EXCHANGE) has been removed.
See CDA Exchange Plus for configuration details.
The FHIR_OP_INITIATE_BULK_DATA_IMPORT permission is no longer implicitly granted through SMART authorization. To grant this permission in a SMART session, use the callback function onSmartScopeAuthorityNarrowing().
Spring LDAP has been updated to address CVE-2026-41720. An LDAP bind that supplies a distinguished name together with an empty password is an unauthenticated bind under RFC 4513, and is now rejected. Note that user authentication in the LDAP Inbound Security Module is unaffected, as empty passwords were already rejected before reaching Spring LDAP.
What this does affect is the module's system user connection, which is used to search the directory.
Before upgrading, check whether ldap.systemuser.dn is configured while
ldap.systemuser.password is left blank. Such a module will no longer start.
To resolve, either set a password for the system user, or clear ldap.systemuser.dn so that the module connects to the directory anonymously. A blank DN together with a blank password remains a valid anonymous connection and is unaffected.
The Sandbox functionality in the AppSphere module has been deprecated. Clients are advised to set up a separate AppSphere module in their lower environments for developers to register account and application(s) for testing purposes.
|
The Web Admin Console User Management page now includes a Show Disabled Users toggle. When enabled, disabled user accounts appear in the listing alongside active accounts, allowing administrators to re-enable them directly through the Modify action. Previously, disabled users were hidden from the listing and could only be re-enabled via the JSON Admin endpoint. |
|
|
Added the |
|
|
Added a new compressed token indexing strategy for token search parameters that can reduce overall database storage by up to 20%. The strategy is configurable on the persistence module via the new |
|
|
MegaScale repositories now support basic searching across multiple shards (i.e. searches where the requested partition list contains partitions spanning multiple database instances). This functionality has some limitations, described here. |
|
|
A new built-in |
|
|
FHIR Storage (RDBMS) modules have a new ID Sequence Pooling Strategy setting. The default preserves the existing behaviour. The new |
|
|
The |
|
|
Added custom scheduled jobs, allowing batch jobs and Camel routes to be invoked on a recurring Quartz schedule via the JSON Admin API or web admin UI. For more details see Custom Scheduled Jobs Overview. |
|
|
Added the ability to capture system log lines emitted during a transaction and attach them as a |
|
|
Module configuration property |
|
|
Added the AWS MSK IAM library to the Smile CDR distribution to make it easier for SmileFactory Deployer to integrate with Smile CDR. |
|
|
The HL7 v2.x inbound listener script now supports a new optional callback, |
|
|
The |
|
|
Added new roles and permissions for the Provider Access API and Terminology Mapping applications in Smile Portal. |
|
|
Added a new configuration option |
|
|
The Prior Auth CRD module now validates the |
|
|
The importer used to import the LOINC CodeSystem has been completely redesigned to use a batch process instead of a hidden background task. This means that LOINC importing now has much better performance and much better job visibility. See Uploading LOINC for information on the new importer. |
|
|
When a missing-translation-suggestion |
|
|
Added a preview West Coast Informatics (WCI) missing-translation-suggestion provider. |
|
|
A new |
|
|
Smile Portal can now host customer web applications packaged as web-jars placed in |
|
|
Added job instance ID to FHIR request transaction logs for P2P module operations. When a P2P operation such as $invoke-export, $bulk-member-match and $provider-member-match starts a batch job, the job instance ID is now captured as an additional property in the transaction log, enabling direct linking between the originating FHIR request and its corresponding batch job. |
|
|
Added Bulk Batch Replication module type ( |
|
|
A Danger check has been added that fails a merge request when a changelog entry added in the MR is placed in the wrong version directory for the target branch. The expected directory is derived from the project pom version (for example a |
|
|
Added a |
|
|
Added a new transaction log step |
|
|
The Transaction Log JSON Admin API |
|
|
The System to System Data Exchange module now includes the configured |
|
|
Added job instance ID to FHIR request transaction logs for Bulk Data export operations. When a $export or $davinci-data-export operation starts a batch job, the job instance ID is now captured as an additional property in the transaction log, enabling direct linking between the originating FHIR request and its corresponding batch job. |
|
|
The CDA Exchange module now supports a new |
|
|
The Hl7v2 Inbound module now supports a new MDM Deduplication mode. When enabled, the FHIR transaction bundle produced from an inbound HL7v2 message is processed through the |
|
|
The logged response from the Prior Auth CRD flow now contains the name of the dynamic Camel route used, enabling downstream correlation between CRD and DTR requests. |
|
|
A new Camel processor, |
|
|
A new |
|
|
When the Cluster Manager boots with a Kafka message broker, the Kafka client now introspects the broker and logs the broker's version information and the lower and upper bounds of client compatibility at INFO level. This information is also included in the cdr-system-config ZIP export from the admin JSON endpoint, in a new file called |
|
|
The |
|
|
The |
|
|
Added an opt-in auto-approval mechanism to the appSphere module. When the new |
|
|
appSphere developers can now generate an approved application's OIDC client secret on demand from the Developer Portal. It is returned exactly once, only its hash is persisted, and it inherits the expiry of the secret it replaces, which is invalidated immediately. Stored plaintext secrets have been removed (the |
|
|
The PATIENT_ID and BUCKETED_PATIENT_ID partition modes now support conditional references to Patient resources, as well as auto-creating placeholders for these references when there is no matching Patient. This depends on storage that supports an all-partition search. Patient entries referenced by urn placeholders or by inline match URLs are resolved to a concrete Patient independently of entry order, an unmatched conditional Patient is created with a server-assigned id when the server id strategy is UUID, duplicate conditional creates of the same match URL within one bundle consolidate into a single Patient that is guarded against concurrent duplicate creation, and each entry's OperationOutcome reports the outcome of the caller's original request. |
|
|
The transaction log emitted by the summary/completion step of the |
|
|
The |
|
|
Member Match operations now support providing multiple business identifiers using the |
|
|
The |
|
|
The |
|
|
The compressed token index's dictionary table |
|
|
A new setting has been added to the Subscription modules. |
|
|
Token searches against the compressed token index now match all of their hashes with a single |
|
|
The deprecated CDA Exchange module ( |
|
|
The |
|
|
Smile CDR now provides a docker image that is based on Redhat Universal Base Image 9, in addition to the current offering that is based on Alpine Linux. It can be retrieved by adding the |
|
|
The MDM endpoints in the JSON Admin API ( |
|
|
The CRD service ext-coverage-information extension has been updated for Da Vinci CRD v2.2.0 compliance. New sub-extensions are now supported: info-needed, doc-purpose, expiry-date, billingCode, and reason. The doc-needed sub-extension now supports multiple instances (the removed 'both' value is replaced by repeating doc-needed entries). The detail sub-extension now includes a mandatory category field. |
|
|
Updated the order-dispatch CDS hook prefetch template to align with the latest IG recommendations. The prefetch now uses individual resource type queries with FHIRPath expressions on context.dispatchedOrders instead of the previous bundled query format. |
|
|
The System to System Data Exchange module now resolves the OAuth2 token endpoint for every outbound token request using a single precedence rule. When the OIDC Server definition sets |
|
|
Spring LDAP has been updated to address CVE-2026-41720. An LDAP bind that supplies a distinguished name together with an empty password is now rejected before it reaches the directory server. User authentication in the LDAP Inbound Security Module is unaffected, as empty passwords were already rejected before reaching Spring LDAP. This does affect the module's system user connection: deployments that configure |
|
|
Previously, requesting an access token from the SMART Outbound |
|
|
Previously, if a user account had the FHIR_EXTENDED_OPERATION_ON_ANY_INSTANCE permission assigned and authenticated via a SMART access token, the server would return an HTTP 500 Internal Server Error. This has been fixed. |
|
|
Fixed a bug in App Gallery where the forgotten password flow would consistently fail with |
|
|
Previously, the |
|
|
Fixed a bug in System-to-System Data Exchange's |
|
|
Previously, the authWellKnownConfigUrl field on the OIDC Server definition was ignored during JWKS resolution, and the well-known URL was always assembled from the issuer. Now, when set, it is used exactly as configured (including any query string) to discover the jwks_uri. The JWKS source priority is unchanged: inline JWKS Text, JWKS File, JWKSet URL, configured well-known URL (new), and finally issuer-assembled well-known discovery. |
|
|
Previously, the Java interceptor registered at the |
|
|
The CDS service now correctly processes order-dispatch hook requests. The dispatchedOrders context field is now read as an array of FHIR references (per the CDS Hooks specification) in addition to the legacy Bundle format. The optional fulfillmentTasks context field is now parsed and passed to the $r5.apply invocation under the fulfillmentTasks parameter, enabling fulfillment-aware CQL evaluation. |
|
|
Processing an inbound HL7v2 ADT^A29 (Delete Person Information) message against a DSTU3 persistence endpoint failed with a HAPI-0529 error because the patient-deactivation bundle entry carried a |
|
|
When an HL7v2 VXU message processed in DSTU3 mode supplies only a manufacturer name in RXA-17, |
|
|
Previously, MegaScale partition lookups and connection-pool initialization bound a hardcoded null partition, ignoring |
|
|
Previously, paging through a FHIR Gateway response of Patient/$everything or Patient/[id]/$everything could return the same resource on more than one page; this has been corrected. A side effect of the fix is that the FHIR Gateway no longer relays referenced resources that a target server attaches to a search response on its own initiative; clients that want included resources must request them with _include or _revinclude. Searches that already use _include or _revinclude are unaffected. |
|
|
Previously, a user authority configured with |
|
|
Processing an inbound HL7v2 ADT^A29 (Delete Person Information) message against a DSTU3 persistence endpoint no longer fails with a HAPI-0541 error. The deactivate-patient bundle entry was missing a fullUrl, leaving the auto-generated MessageHeader.focus reference unresolvable. |
|
|
The User Management page in the Admin UI now correctly enables the last-page navigation link. Previously, the user search query used a Slice (which does not count total results), so the pagination controls could not determine when the last page had been reached. The query now returns a Page with a total count, enabling all pagination links to reflect the correct state. |
|
|
The ETL Importer and other script-runner callers no longer perform a database lookup on every processed row to determine whether a script is configured; the result is now cached and re-read only when scripts are reloaded. This removes a per-row database round-trip during large CSV imports. |
|
|
For order-dispatch CDS hook requests, the resolved order resources referenced by dispatchedOrders are now passed as draftOrders parameters to the $r5.apply invocation. This ensures CQL evaluation has access to the full order resources when dispatchedOrders is provided as a string array. |
|
|
Previously, requests from the Package Registry Swagger UI were rejected with 403 Forbidden response without prompting for authentication credentials. This has been fixed. Unauthenticated requests to protected paths now return HTTP 401 with a Basic authentication challenge prompting the user to enter credentials. Once the user enters valid credentials, the request is processed and the appropriate response is returned based on the user's permissions. |
|
|
Failed rows processed by the ETL Importer ( |
|
|
Under high-concurrency ingestion, MegaScale deployments that resolve references across shards (different databases) could deadlock — ingest threads would hold a connection in the source shard's pool while waiting indefinitely on the target shard's pool, eventually exhausting both. Concurrent cross-shard reference resolutions are now bounded by a new setting, |
|
|
Previously, Smile CDR unconditionally appended |
|
|
In the CDA Exchange+ module, when exporting a CDA document, the child elements of the CD datatype were rendering in an invalid order. This has been fixed. |
|
|
Previously, the default section narrative in CDA documents generated by the CDA Exchange+ module contained |
|
|
In the CDA Exchange+ module, when exporting a document that includes Medication Activity entries, the child elements of |
|
|
When a row failed during an ETL Importer CSV import that was submitted without a file name, the failure entry in the Transaction Log displayed the file name as |
|
|
Fixed an issue where a synchronous $mdm-clear request (using the Prefer: wait=N header) returned HTTP 500 on DSTU3 and R5 deployments. Synchronous $mdm-clear now returns a successful response on DSTU3, R4, and R5 deployments. |
|
|
Fixed a bug where resources with a non-repeating identifier element (e.g. Composition, which has 0..1 cardinality on identifier) would cause a DataFormatException during $sdh.s2s.invoke-export ingestion if the resource already had an identifier populated. The identifier addition is now skipped for non-repeating identifier fields that are already populated, preserving the original identifier value. |
|
|
Previously, the |
|
|
When tokenization was enabled, a conditional create whose conditional URL used the FHIR-spec bare query form (e.g. |
|
|
The appSphere Developer Portal FHIR sandbox feature has been withdrawn following a security review, along with the sandbox OIDC client REST endpoints and the |
|
|
Added audit logging to Forgot Password flow to be in compliance with HIPPA. |
|
|
Previously, in MegaScale Patient ID Partition mode, writing a resource that referenced a non-Patient resource in a patient compartment by a client-assigned or UUID id failed because the reference target could not be resolved, even though it existed. Such references are now resolved correctly and the write succeeds. |
|
|
Previously, the |
|
|
Previously, the Download Search Results button on the Audit Log (User Actions) page in the Web Admin Console failed with an HTTP 500 error. This has been fixed. |
|
|
Previously, when the |
|
|
appSphere developers updating their own email address from the Developer Portal no longer require the global |
|
|
Fixed a potential race condition when two threads or cluster nodes simultaneously initialized the cluster cache synchronization entry for the same cache. |
|
|
Previously, when System Log capture was enabled and Transaction Log events were stored in a Transaction Log Persistence module, processing a request that captured System Logs threw a |
|
|
Previously, invoking |
|
|
Previously, submitting a self-registration request in the CDR Developer Portal (App Gallery) that failed validation would return an HTTP 500 error. Invalid registration now fails gracefully while providing failure feedback. |
|
|
Previously, the Communication resources used to cache CRD responses when using the |
|
|
Previously, in MegaScale Patient ID Partition mode, reviving a deleted resource with a client-assigned or UUID id failed with a HAPI-1326 error when the resource had ever been referenced from a resource on another shard. Reviving such a resource now succeeds. Genuinely deleted resources are still reported as gone. |
|
|
A matched Patient returned by a custom match function with a bare (type-less) resource id is now type-qualified when building the group member entity reference and the persisted Consent's patient and performer references; previously the type-less Consent references caused the request to fail. The provider-access consent opt-out evaluation now also honors an active opt-out Consent for a member whose matched Patient carries a bare resource id; previously the type-less id never matched the stored Consent's type-qualified patient reference and the member was returned as matched despite having opted out. |
|
|
Previously, a node running the Audit Log OpenTelemetry or Transaction Log OpenTelemetry module would fail to start if 'node.security.strict' was enabled. This has been fixed. |
|
|
Previously, the MDM bundle match de-duplication mode in the HL7v2 inbound module would fail for some messages. The bundle update was rewriting references in conditional create queries, but not conditional update queries. The bundle update was also not handling http-escaped characters correctly. Both problems have been fixed. |
|
|
Previously, on MegaScale deployments, a FHIR transaction Bundle could be rejected with |
|
|
|
|
|
The Prior Authorization CRD module now correctly passes through arbitrary |
|
|
Previously, the |
|
|
Previously, the $provider-member-match operation required Consent.policy.uri to be present and set to a valid HRex consent policy value (#sensitive or #regular). This requirement comes from the HRex Consent profile, but the PDex Provider Consent profile used by $provider-member-match treats both Consent.policy and Consent.policy.uri as optional. Members were incorrectly placed in the ConsentConstrainedMembers group even when all other matching validations passed. The default consent policy validation is now skipped for $provider-member-match operations, aligning with the PDex Provider Consent profile. The existing HRex consent policy validation remains unchanged for $member-match and $bulk-member-match operations. Custom consent validation scripts, if configured, continue to take precedence for all operation types. |
|
|
Previously, a LiveBundle rule configured to track a reference shared across partitions could fail to find matching resources when the shared resource lived in a different partition than the caller. This has been fixed. |
|
|
Fixed a bug in Prior Auth CRD where the Order Select request failed with a 500 Internal Server Error when the DraftOrders bundle contained orders not included in the selection. The server now processes only the selected orders and uses non-selected orders in the DraftOrders bundle as additional context. |
|
|
Previously, module configuration items that load a file resource failed module startup with a |
|
|
|
|
|
Module config |
|
|
Previously, configuration items that were loaded as resources (such as seeded OIDC Clients/Servers) could refer to a URL to load the resource from. This has been removed, and only resources on the classpath, or files on disk can be referred to this way. |
|
|
Changes have been made to the Password Reset Flow of the Local Security module. Each password reset token may be used precisely once. If an invalid code is entered, the existing token is invalidated and a new password reset must be requested. Furthermore, the token now has an expiry time of one(1) hour, instead of 24 hours. |
|
|
The URL-scheme restriction introduced in #8682 (which prevents seeded resources from referencing remote URLs) now also applies to child module contexts. Previously, module-level Spring contexts did not inherit the parent context's |
|
|
Previously, LiveBundle operations that resolve a specific subscriber, resource, or tracking ID resolved LiveBundle data across all partitions instead of the caller's own. These lookups are now scoped to the caller's partition. |
|
|
Improved the consistency of permission enforcement for the server-level |
|
|
The FHIR_OP_INITIATE_BULK_DATA_IMPORT permission is no longer implicitly granted through SMART authorization. |
|
|
Patched code that could've been vulnerable to XXE injection. |
|
|
Previously, the OpenID Connect token endpoint re-fetched a client's key set from its configured JWKS Url on every client-authentication request. The key set is now cached, and a key rotation at that URL is picked up without waiting for the cache to expire. Where a JWKS Url is configured, it is the only key source used for that client: any Public JWKS Keystore on the same client definition is ignored. The new OIDC HTTP Client: JWKS Fetch Failure Cache (secs) setting controls how long a failed fetch is remembered. |
|
|
Updated CdrAuthorizationInterceptor to omit Group and List resources if requesting user only has permissions on TYPE for patient compartment. |
|
|
Previously, LiveBundle operations that query LiveBundle data based on group or watchlist tokens were not scoped to the caller's partition and could return data from other partitions. These lookups are now scoped to the caller's partition. |
|
|
The console colour library used by the CLI and the server control client has been migrated from the deprecated |
|
|
Logback has been upgraded from 1.5.25 to 1.6.3 to support the replacement Jansi library: the console colour configuration now uses logback's |
|
|
|
| Released | 2026-07-22 |
| Codename | Synchronicity |
| HAPI FHIR | Smile CDR 2026.05.R02 is based on HAPI FHIR 8.10.1, and includes all changes and fixes included in this version. Please see the HAPI FHIR ChangeLog for details about what has changed. |
Two large breaking changes are included in this release.
let MyType = Java.type('com.example.MyType');) must now manually allowlist the fully-qualified class names desired, via the class_allowlist property. Warning: allowlisting classes that expose host capabilities (e.g. java.lang.Runtime, java.lang.ProcessBuilder, java.lang.System, java.io.File, java.net.URLClassLoader, javax.script.ScriptEngineManager) effectively re-enables the sandbox escape this release fixes. Allowlist only the classes your scripts strictly need.customerlib/ directory.This release introduces support for MDM expansion with search and $everything operation when PatientId partitioning mode is enabled (GL8366). However, this change breaks some MDM features when using MongoDB as the persistence layer.
The following MDM features are no longer functional:
$everything operations$everything operationsThese features remain fully operational when using any supported RDBMS (PostgreSQL, SQL Server, Oracle, MySQL).
Due to the upcoming sunset of MongoDB support and the absence of clients running MongoDB with the MDM module in production environments, these broken features will not be fixed.
We have upgraded our Camel dependency version from 4.10.x to 4.18.x. As a result, kebab-case is no longer supported in Camel routes.yaml files. Please ensure camel case is used instead.
| Released | 2026-05-21 |
| Codename | Synchronicity |
| HAPI FHIR | Smile CDR 2026.05.R01 is based on HAPI FHIR 8.10.0, and includes all changes and fixes included in this version. Please see the HAPI FHIR ChangeLog for details about what has changed. |
Two large breaking changes are included in this release.
let MyType = Java.type('com.example.MyType');) must now manually allowlist the fully-qualified class names desired, via the class_allowlist property. Warning: allowlisting classes that expose host capabilities (e.g. java.lang.Runtime, java.lang.ProcessBuilder, java.lang.System, java.io.File, java.net.URLClassLoader, javax.script.ScriptEngineManager) effectively re-enables the sandbox escape this release fixes. Allowlist only the classes your scripts strictly need.customerlib/ and scripts/ directories.This release introduces support for MDM expansion with search and $everything operation when PatientId partitioning mode is enabled (GL8366). However, this change breaks some MDM features when using MongoDB as the persistence layer.
The following MDM features are no longer functional:
$everything operations$everything operationsThese features remain fully operational when using any supported RDBMS (PostgreSQL, SQL Server, Oracle, MySQL).
Due to the upcoming sunset of MongoDB support and the absence of clients running MongoDB with the MDM module in production environments, these broken features will not be fixed.
We have upgraded our Camel dependency version from 4.10.x to 4.18.x. As a result, kebab-case is no longer supported in Camel routes.yaml files. Please ensure camel case is used instead.
|
The FHIR Gateway module now supports proxying the $validate-code, $lookup, $translate, and $validate operations (both type-level and instance-level) to configured backend targets using the existing operationRoutes mechanism. Previously these operations were not recognized by the Gateway's resource provider and requests would fail to route. Parameters bodies submitted via POST are forwarded to the target server, enabling terminology and validation workflows to be routed through the Gateway. |
|
|
The CDA Exchange+ module will attempt to infer resource authorship by cascading author data from ancestor nodes in the CDA document when no local author element is present in the entry being processed. |
|
|
The MDM matching architecture now supports custom matching and similarity algorithms. Users can implement and deploy their own matching logic via customer JARs. See Custom MDM Matching Algorithms for details. |
|
|
Added |
|
|
The Transaction Log Broker module can now send messages using buffered flushes instead of a single-threaded executor. This significantly improves throughput under high concurrency, especially when message broker latency is non-trivial. See the Transaction Log Broker documentation for more details. |
|
|
Added new permissions for controlling access to Smile Portal applications.
|
|
|
For Prior Auth CRD module, The |
|
|
The System Config endpoint now includes comprehensive database statistics in the exported zip file. This feature collects database metadata, connection pool statistics, and performance metrics from all modules with datasources. See System Config Endpoint for more information. |
|
|
MDM expansion on search and |
|
|
The Camel HTTP Endpoint allows users to invoke Camel routes via HTTP calls. See the documentation for details. |
|
|
Smile Portal Web Admin Console apps (e.g. User Management, Module Config) are now shown or hidden based on the permissions granted by the user's assigned Role. |
|
|
Two new Smile Camel processors have been added for terminology operations. The |
|
|
The HL7 v2.x Inbound module now supports the |
|
|
When the CDA Exchange+ module cascades authorship data within a document being imported, the FHIR elements inherited from an ancestor resource may include data types that are not valid for the target field. These invalid elements will be filtered out before populating the field, to ensure that the generated resources are valid. |
|
|
When the CDA Exchange+ module cascades authorship data within a document being imported, if the target field has a bounded maximum cardinality, the collection of authors will be truncated to the target size. References to Practitioner or PractitionerRole will be prioritized over references to non-human agents such as Device or Organization. Otherwise, the elements will be selected in the order that they occur in the source CDA document. |
|
|
Added new AppSphere roles and permissions to Smile Portal. The AppSphere module now exposes three separate application types (Admin Console, Developer Portal, and Application Gallery), each with dedicated roles. These roles control access to the corresponding AppSphere components within Smile Portal. |
|
|
Transaction logs now support configurable capture of HTTP request and response headers. Two new module settings, |
|
|
Added new MDM UI roles and permissions to Smile Portal. The MDM-related modules (MDM, MDM Dashboard, and MDM Comparison) are now exposed as a single MDM UI application type with dedicated roles. These roles control access to MDM functionality within Smile Portal. |
|
|
The system role is bypassing consent checks when consent enforcement is enabled. Internal consent resource lookup for consent checking now runs with the system role via Roles.runAsSystem(). Other internal processes requiring interaction with DAOs will also need to be updated with the same approach. |
|
|
Kafka users running batch jobs with long running steps could exceed the Kafka |
|
|
A new REST endpoint |
|
|
The Transaction Log REST API response now includes a |
|
|
The |
|
|
When the |
|
|
Added a new FHIR Endpoint admin role to Smile Portal. Users assigned the FHIR_ENDPOINT_ADMIN role are granted access to the FHIR Endpoint application within Smile Portal along with FHIR superuser permissions. |
|
|
The Smile Portal custom external application configuration now supports an optional |
|
|
When installing an NPM package through the Package Registry module, adding the header |
|
|
The Admin JSON API now includes several new endpoints for audit and transaction logs. New |
|
|
The |
|
|
The |
|
|
|
|
|
The |
|
|
Added |
|
|
Smile Portal now supports FHIRWeb as a distinct application type with a dedicated |
|
|
Added a preview missing-translation suggestion pipeline: codes that in-place translation cannot map via ConceptMap |
|
|
Added two activation methods for In-Place Code Translation: automatic translation of every stored Observation via module configuration, and a Camel processor for route-based translation. |
|
|
Added in-place code translation: |
|
|
Added asynchronous Task coordination for the missing-translation suggestion pipeline: unmapped codes are deduplicated into a FHIR Task, matched by a channel-based Subscription, and resolved by a configured suggestion provider whose candidates are written back onto the Task. |
|
|
The Admin JSON API now includes a new |
|
|
The |
|
|
Added a new Cluster Manager configuration property (ag.interceptors.expose_oidc_client_secret) that, when enabled, includes the OIDC client secret in the AGConsoleJson passed to AG_APPLICATION_STATUS_UPDATING and AG_APPLICATION_STATUS_UPDATED interceptor pointcuts. |
|
|
A new Delta Lake Export module ( |
|
|
The FHIR Gateway's |
|
|
Two new configuration properties have been added to the Persistence module to control ValueSet $expand operation result sizes:
|
|
|
Enhanced performance for patient linkage in |
|
|
Improved performance of HL7 v2.x message ingestion by avoiding deep cloning the original HL7 v2.x message on every call. A new |
|
|
In the |
|
|
A performance bottleneck in the Camel module when writing to the transaction log has been removed. |
|
|
The |
|
|
Prior Authorization modules (PAS/CRD) now handle Camel route exceptions more consistently, propagating FHIR exceptions directly to clients while wrapping unexpected errors. Documentation added for error handling best practices in custom Prior Auth Camel routes. |
|
|
Previously, PAS and CRD modules were only able to support parsing |
|
|
Updates the |
|
|
The DaVinci CRD and PAS Camel route entry points have been renamed to |
|
|
CDS hook services registered via PriorAuthCRD module now supports configuration to include arbitrary extension properties in their hook definition files. Note: the |
|
|
For PriorAuth CRD Module, The DaVinci CRD max-cards and coverage-info extension handling has been moved out of the cqlToCrdResponseProcessor Camel processor into two new standalone processors: daVinciMaxCardsProcessor and daVinciCoverageInfoProcessor. These must now be explicitly added to CRD Camel routes after cqlToCrdResponseProcessor to apply card limiting and coverage-info filtering. Previously, these extensions were hard-coded and automatically applied within cqlToCrdResponseProcessor; that implicit behaviour has been removed. |
|
|
GraalVM Javascript execution environments may no longer read files from disk arbitrarily. Only files in |
|
|
GraalVM Javascript execution environments may no longer instantiate arbitrary Java types. Instead, any Java types that scripts need to instantiate must be manually allow-listed via the new class_allowlist property |
|
|
Previously, the Terms of Service agreement page (/signin-tos) could return an HTTP 500 error when a user submitted the agree form after their authentication session had already expired (for example, by agreeing from another browser tab). The endpoint now redirects to the sign-in page when no active authentication is present. |
|
|
The "Boot cycle detected" error message now includes the names of the modules that form the dependency cycle, making it easier to diagnose and resolve circular module configuration issues. |
|
|
Previously, accessing extra components on composite HL7v2 field types (such as PL and CE) in the JavaScript execution environment was not supported and would fail. This has been fixed: composite HL7v2 types now support extra component access, consistent with primitive types. |
|
|
Previously, the "TLS: Disable SNI checking for debugging" setting had no effect on outbound client connections. When the destination hostname did not match the server certificate (e.g. connecting via IP address instead of hostname), the connection would fail with a certificate mismatch error even with the setting enabled. The setting now correctly bypasses hostname verification for all outbound connections that use a custom TLS configuration, including HL7 v2.x over HTTP and outbound OAuth2/SMART authentication requests. |
|
|
The default REST-hook endpoint URL validation regex has been corrected. Previously, the regex incorrectly allowed URLs with invalid schemes such as |
|
|
When operating MegaScale in Patient ID Partition Mode with Auto-Create Placeholder Reference Targets enabled, auto-creation of an Ancillary Resource resulting from the creation of a Patient Compartment Resource resulted in a failure. This has been corrected. |
|
|
Previously, the outbound HL7 v2 mapper incorrectly populated IN1-13 (Plan Expiration Date) with the Coverage period start date instead of the period end date. In addition, NK1-9 (End Date) was silently populating NK1-8 a second time instead of being populated from the patient contact period end. Both issues have been corrected so that IN1-13 and NK1-9 are now populated from the corresponding end elements. This only affects outbound HL7 v2 messages and does not require any data migration. |
|
|
Users with MODULE_ADMIN_FOR_MODULE permission for specific modules could not access those modules in the Web Admin Console despite having proper permissions. This has been fixed. |
|
|
Previously, in MegaScale PATIENT_ID partition mode, performing a FHIR Patch on a Patient resource by identifier within a transaction bundle returned a 400 error (HAPI-2616). This has been fixed. |
|
|
Previously, setting the password encoding scheme to any PBKDF2 option would cause user password updates to fail. This would exhibit in the Web Admin Console as though nothing had occurred, and in the logs, there would be a DataIntegrityViolationException. This has been fixed. Also, a new stronger option, PBKDF2_256_310000_RND, has been added and is the recommended choice for new deployments. |
|
|
Fixed the JavaScript documentation for adding contained resources without the TransactionBuilder API. The '#' prefix for contained resource references was incorrectly placed on the resource id instead of on the reference element. |
|
|
Previously, built-in SearchParameters required for system operation ( |
|
|
Previously, when tokenization was enabled, chained searching (e.g. finding Observations by a Patient's identifier) would return no results even when matching data existed. This has been fixed. |
|
|
Previously, re-creating a deleted resource would raise an exception when the system operates in PatientID partitioning mode. This issue has been fixed. |
|
|
Previously, PriorAuth CRD module would fail to start when CDA Exchange+ module was also configured. This behaviour has been fixed. |
|
|
Previously, when processing an appointment-book CDS Hook request, the Prior Authorization Coverage Requirement Discovery (CRD) Module would map the |
|
|
Prevent commons-logging from being transitively included on the runtime classpath. spring-jcl (from spring-core) and jcl-over-slf4j already provide the commons-logging API. |
|
|
The $mdm-link-history operation operation was throwing a NullPointerException when used in conjunction with Patient ID Partition Mode. This has been fixed |
|
|
When exporting CDA documents through the CDA Exchange+ module, assignedAuthor elements were being rendered with multiple ID's. This issue has been fixed by making sure the appropriate caches are being cleared between elements. |
|
|
Previously, FHIR Gateway pagination could return duplicate or missing resources when used with MegaScale targets and interceptors which perform identifier expansion. The pagination processor now correctly uses the SELF link returned by the target response bundle, which reflects interceptor modifications such as identifier expansion, preventing incorrect page link generation. |
|
|
Previously, modifications to the pattern properties for enabling and disabling search parameters would be ignored in specific scenarios. This issue is resolved. Follow the link to access documentation regarding enable/disable patterns for SearchParameters. |
|
|
When a tokenization rule's status was set to DISABLED after running detokenization, the TokenizationSearchInterceptor still tokenized search parameter values, causing searches to return no results. The fix filters DISABLED rules from the search interceptor's rule map, aligning search behavior with the existing write-side filtering. |
|
|
Update documentation on P2P, Prior Authorization and Provider Access |
|
|
Previously, the Consent hook CONSENT_BUILD_FIXED_STATIC_POLICY was declared using |
|
|
Previously, subscription system processes (activation, matching, registration, async delivery, and SearchParameter cache refresh) were bypassing consent to avoid failures in consent interceptors due to missing authentication using a flag in RequestDetails#userData. The fix has been updated to instead run these processes as a system user in order to enable them to bypass consent. |
|
|
Previously, initialization system processes (validation support, search parameter, tokenization and MDM subscription), as well as async system processes (MDM message handling, HL7v2 inbound/outbound message processing, validation resource fetching) ran without a security context. These processes now run with an authenticated ROLE_SYSTEM principal, ensuring consent and security interceptors can properly evaluate authorization. |
|
|
Previously on the Smile CDR documentation site, search results in the left sidebar were being clipped at the bottom of the sidebar and the last entries could not be scrolled into view. This has been fixed and the results list now fits within the visible area and is fully scrollable. |
|
|
Previously, the |
|
|
Previously, searching for a Patient by identifier in MegaScale PATIENT_ID or BUCKETED_PATIENT_ID partition mode would return a 400 error when the identifier system matched a pre-resolvable patient identifier system, but no Patient existed with that identifier system. This has been fixed so that the search now correctly returns an empty Bundle. |
|
|
Previously, HL7v2 inbound message processing could fail with a |
|
|
The FHIR Gateway |
|
|
Previously, when request validation was enabled and Implementation Guide profiles were installed, Bundle resources could produce spurious REFERENCE_REF_CANTMATCHCHOICE validation errors. This was caused by a missing isSuppressMessageId delegation in the validator policy advisor, which has been corrected. |
|
|
Previously, the Subscription Submitter was ignoring the |
|
|
Previously, when using MegaScale Patient ID partitioning mode, conditional PATCH and DELETE operations using a patient identifier (e.g., Patient?identifier=Patient|123) would create a phantom UUID mapping if the patient did not already exist. This has been fixed. |
|
|
Previously, when using MegaScale Patient ID partitioning mode, a conditional DELETE on a non-existent patient would return a confusing diagnostic message referencing a system-generated UUID. The response now returns a clear message indicating that no resource matching the requested URL was found. |
|
|
Warning messages in the view detail panel of batch jobs was no longer present during regression testing. I've fixed this by re-introducing the html field with its corresponding binding. |
|
|
Previously, performance tracing interceptors could add large HTTP response headers, causing HTTP 431 "Response Header Fields Too Large" errors for requests with many or complex trace entries (e.g. large identifier resolution queries). Individual trace header values are now truncated to approximately 4KB, and the cumulative size of all trace headers on a single response is capped at 7KB (leaving headroom for standard response headers), to prevent this error. |
|
|
Previously, the System to System data exchange batch job for |
|
|
Three FHIR Gateway interceptor defects affecting bulk export operations have been corrected. First, the |
|
|
Previously, the |
|
|
Previously, in the PriorAuth CRD module, using a CDS Hook request inside the JavaScript API would result in incomplete serialization of the |
|
|
In the FHIR Gateway module, two issues with operation forwarding have been fixed:
|
|
|
In the HTTP Camel Endpoint module, the Content-Length header of the response was not always accurate. This has been fixed. |
|
|
Previously, the Camel HTTP endpoint module was not making use of the context path configuration parameter. This has been fixed. If the request URL does not begin with the configured context path, the endpoint will return a |
|
|
Previously, the profile for |
|
|
Fix #null references in $provider-member-match response groups. When member Patient resources in the request payload have no id , the response was producing invalid #null references in the extension and a missing member.entity.reference on the affected group members |
|
|
Previously, in MegaScale environments with |
|
|
Fixed duplicate entries in the Web Admin documentation sidebar and search. Previously, every page under the Configuration Categories chapter (from Web Admin Console Settings through User Self Registration) was listed twice. Each configuration category page now appears exactly once. |
|
|
Previously, the Terms of Service agreement page could return an error when the OAuth2 client session was no longer available at the time the user submitted their agreement (for example, when opened in another tab). The endpoint now redirects to the sign-in page in this scenario. |
|
|
Previously, |
|
|
Fix parameter validation for the |
|
|
Fixed a broken module link in the transaction log column on the Web Admin Console OpenID Connect Clients and Servers pages. Clicking the module link now correctly navigates to the module's runtime status page instead of returning a 404. |
|
|
Fixed an issue with the |
|
|
The |
| Released | 2026-02-19 |
| Codename | Prologue |
| HAPI FHIR | Smile CDR 2026.02.R01 is based on HAPI FHIR 8.8.0, and includes all changes and fixes included in this version. Please see the HAPI FHIR ChangeLog for details about what has changed. |
This release introduces a database migration that breaks our zero-downtime guarantee for a subset of users matching all the following criteria:
Previously, when using client-assigned FHIR resource IDs that differ only in case, for example:
PUT /Patient/PatientA PUT /Patient/patientA
would either result in two versions of the same resource, or have the second request would fail. However, by the FHIR spec, this should create 2 distinct resources. This behaviour has now been corrected as part of this HAPI-FHIR issue.
Fixing this requires a database migration that is not compatible with zero-downtime upgrades.
If you meet the criteria above, and want to determine if your database is affected, run the following diagnostic SQL query to check:
SELECT CASE CHARINDEX('_CI_', COLLATION_NAME) WHEN 0 THEN 0 ELSE 1 END FROM INFORMATION_SCHEMA.COLUMNS WHERE TABLE_SCHEMA = SCHEMA_NAME()
AND TABLE_NAME = 'HFJ_RESOURCE'
AND COLUMN_NAME = 'FHIR_ID'
Users who see:
1 use case-insensitive collation and are affected0 are unaffectedIf the case-sensitive FHIR ID behaviour is not required for your use case, and you wish to preserve zero-downtime upgrades, you may bypass this migration by using the following smileutil command:
bin/smileutil migrate-database ...<args>... --skip-versions 8_8_0.20251208.10,8_8_0.20251208.20,8_8_0.20251208.30,8_8_0.20251208.40,8_8_0.20251208.50
See the migrate database docs for more information.
|
CDA Exchange+ module now supports exporting History and Physical Notes with LOINC code 34117-2. |
|
|
Subjective narrative section is now supported on import and export of CDA documents through CDA Exchange+ module. |
|
|
Objective narrative section is now supported on import and export of CDA documents through CDA Exchange+ module. |
|
|
When importing a CDA document through CDA Exchange+, depending on the contents of the author header it will either create a PractitionerRole, Practitioner, Device or Organization as the composition's author. |
|
|
Added two new permissions: |
|
|
The documentation system now supports YAML Front Matter in markdown files, enabling automatic cross-linking between related pages. Each documentation page can specify its id, title, tags, and related pages in Front Matter metadata. The system automatically generates tag pages and displays related articles in a sidebar, improving documentation navigation and discoverability. |
|
|
Added support for Oracle Database 23ai. The Oracle JDBC driver has also been upgraded to version 23.6.0.24.10 to support the new database version. The feature also include fixes to prevent the driver from leveraging Oracle 23 newly added support for boolean type which would break schema based initialization and future migrations. |
|
|
Added remote debugging support to |
|
|
Added support for parameterized consent policies in the Consent Module. Parameterized policies allow configuration through URL query parameters (e.g., |
|
|
The |
|
|
A new interceptor has been added to the MDM module that automatically enables MDM expansion for bulk export operations when the user has the |
|
|
A new |
|
|
CDA Exchange+ module now supports exporting Progress Notes with LOINC code 11506-3. |
|
|
a new |
|
|
Integrate the P2P batch job transaction log steps into the new Transaction Log |
|
|
A new $sdh.pdex.member-provider operation that will return a bundle of Organizations representing a member's attributed healthcare providers. |
|
|
A new |
|
|
Added connection pool configuration settings for tuning external object storage (AWS S3, Azure Blob Storage, MinIO) performance. See External Object Storage Performance Tuning for more information. |
|
|
Course of Care narrative section is now supported on import and export of CDA documents through CDA Exchange+ module. |
|
|
Enabled custom processing for |
|
|
The CDA Exchange+ module now uses the uri |
|
|
Added a system property for the unusual case where tenant IDs were populated before the maximum tenant limit was configured. |
|
|
PatientMergeProcessor has been added to enable resource $merge FHIR operation for Patient and other resource types in message-driven workflows. |
|
|
ReplaceReferencesProcessor has been added to enable $replace-references for updating resource references across the database in message-driven workflows. |
|
|
Add the ability to configure the Prior Auth CRD Module CDS Hooks with a JSON file containing the CDS Hook definitions. |
|
|
The Bulk Patch and Bulk Patch Rewrite History operations are now partition aware, and can work correctly in a MegaScale environment. |
|
|
Add the ability to configure the Smile Portal Module's custom applications with a JSON file containing the App definitions. |
|
|
Add a property to the security session classes to hold 'purpose' and 'actor' for use in the CDR consent infrastructure. See Example: Using Consent Purpose and Actor. |
|
|
Physical Exam narrative section is now supported on import and export of CDA documents through CDA Exchange+ module. |
|
|
Interventions narrative section is now supported on import and export of CDA documents through CDA Exchange+ module. |
|
|
Health Status Evaluations/Outcomes narrative section is now supported on import and export of CDA documents through CDA Exchange+ module. |
|
|
Two new search normalization modes have been added to Smile CDR repository tokenization. These new modes allow elements of type |
|
|
Add a $next-question operation to the PAS module to allow dynamic Camel routing for Adaptive Questionnaire Requests. With centralized dynamic routing, the updated QuestionnaireResponse will be returned based on the Questionnaire's canonical url. |
|
|
Updating logging messages and their corresponding types in CDA Exchange+ module to better reflect errors and warnings. |
|
|
The |
|
|
Three new Camel processors have been added to enable FHIR operations in message-driven workflows: ExpandValueSetProcessor (ValueSet $expand), ValueSetValidateCodeProcessor and CodeSystemValidateCodeProcessor (code validation against ValueSets and CodeSystems). |
|
|
The enhanced mappings for |
|
|
For Prior Auth CRD module, the default Camel processors now supports processing of |
|
|
Previously, the member-match services used by bulk member match directly would not return operation outcomes when matches could not be performed successfully. Now, when a member match is not found, multiple matches are found or the member match cannot proceed due to an unsupported consent, an operation outcome is returned with the nature of the failure. |
|
|
The |
|
|
The enhanced mappings for |
|
|
It is now possible to perform a FHIR Bulk Export ( |
|
|
For System to System Data Exchange Module, |
|
|
The FHIR Storage module Tokenization feature now supports the FHIR PATCH operation. |
|
|
When importing a CDA document, if an author contains both an assigned person and an assigned authoring device, the authoring device element will be ignored given that it's incorrect CDA format. The author will be mapped as either a practitioner or a practitionerRole. |
|
|
A custom troubleshooting logger has been added for the System to System Data Exchange module. |
|
|
Added support for Snowflake as a target database for Real-Time Export (RTE). A new |
|
|
Clicking on section link icons in the documentation now copies the URL to the clipboard and displays a brief 'Link copied!' notification. |
|
|
Prior Auth Modules (CRD, DTR, PAS) and System to System Data Exchange Module moved from Experimental to Trial. |
|
|
Enhanced patient linkage in |
|
|
Moving to a new maturity model. Updating doc tags and maturity enums. |
|
|
The CDA Exchange+ module will only attach a |
|
|
The CDA Exchange+ module will now use lenient matching rules on CodeableConcept fields when merging resources, which will reduce the incidence of duplication of semantically equivalent codes. |
|
|
Previously, for PriorAuth CRD module, the default |
|
|
Previously, when a Camel Route had an exception in the PAS and CRD modules, only a high level exception message was returned to the client, making it hard to troubleshoot. Now, more details about the underlying cause of the error are returned. |
|
|
The prior-auth CRD error message for missing patient has been improved. Additionally, the endpoint will no longer return a 404 when an internal resource cannot be found. |
|
|
The CDA Exchange+ module now supports both the 'entries optional' and 'entries required' variants of the Advance Directives section. |
|
|
In the CDA model, an Allergy-Intolerance Observation may have multiple |
|
|
The CDA Exchange+ module has been updated to apply the new author filtering rule (previously applied only to |
|
|
For System to System Data Exchange Module, |
|
|
In the Prior Auth CRD module, the default |
|
|
Snowflake database driver support has been isolated to the Real-Time Export (RTE) module. The |
|
|
Section numbers (e.g., '3.0.1', '7.0.2') have been removed from documentation page headings, breadcrumb navigation, and the table of contents for a cleaner presentation. |
|
|
Previously, subscriptions would not trigger when resources are deleted even when the send-delete extension is enabled. This has been fixed. |
|
|
The logic to skip property substitution (using |
|
|
Previously, chained reference searches by users with |
|
|
Previously, when writing tests using |
|
|
Add missing agent.type in provenance record in $invoke-export operation |
|
|
Previously, when creating Consent and Subscription Matcher modules with subscriptions enabled in the persistence module, consent checking was performed for |
|
|
Previously, modules that threw an Exception during |
|
|
Previously, when sending an HTTP request for an unsupported resource type, the HTTP error response message would always include Patient as a supported resource type, even when Patient was not included in the resource type whitelist. This has now been fixed. |
|
|
Previously, the CDA Exchange+ module would fail to import a CDA document that contained a Basic Occupation Observation if that observation was missing its |
|
|
When importing and/or exporting through CDA Exchange+ module, the status value for encounter resources was incorrectly mapped or not mapped at all. This has been fixed by correcting the encounter status source and target mappings. |
|
|
Previously, restarting a module that has delegated validation to a different one via VALIDATION_SUPPORT could potentially cause errors during validation. This has been fixed |
|
|
Previously, when the CDA Exchange+ module was generating a document for export, it would throw an exception and abort processing if it encountered a reference that it could not resolve. This has been changed to log a warning message, skip the broken reference, and carry on processing the rest of the document. |
|
|
Fix for CDA export, encounter type when absent, will now display as code with nullFlavor NI. |
|
|
A new search parameter normalization mode |
|
|
Fixed an issue in the FHIR Gateway where duplicate records could appear when paginating through sorted search results. The fix ensures deterministic ordering by resource ID when computing page boundaries. |
|
|
Changes to the user session would sometimes not propogate through to batch jobs. This could affect consent calculations. This has been corrected. |
|
|
Fixed the problem where the transaction log broker was throwing an NPE for prior-auth CRD Camel transaction logs when no Camel from endpoint was defined |
|
|
Previously, the CDA Exchange+ module would not include the Problem Section (entries required) as a mandatory section in a Consultation Note document, but it would include the Procedures Section (entries required) as a mandatory section. This has been fixed. |
|
|
Previously, the CDA Exchange+ module was using a deprecated LOINC code when generating Care Plan documents. The document definition has been updated to use code 18776-5. |
|
|
Previously, the |
|
|
Previously, the 'On this page' table of contents on changelog pages displayed 'undefined' for Upgrade Notes sections. This has been fixed. |
|
|
A regression was introduced in 2025.11.R01 which caused authentication that used the AWS Security Token Service to fail. This was due to a version update of the aws-advanced-jdbc-wrapper dropping the dependency. This dependency is now included manually in Smile CDR. |
|
|
Previously, when MDM module was running and tokenization was enabled in persistence, creating a Patient resource that linked to an existing golden resource would fail with error. This has been fixed. |
|
|
Fixed the Consent Demo tutorial to correctly allow access to Patient resources when the patient compartment is blocked. Previously, blocking access to resources in a patient's compartment would incorrectly also block access to the Patient resource itself. |
|
|
When using a repository with Tokenization enabled, if a rule is set to QUIESCE status and new data is stored with this rule in place, performing an Update Tokenization job could tokenize previously non-tokenized data. This has been corrected. |
|
|
Previously, Megascale batch bundle operations that included conditional URLs could abort the entire bundle if one or more entries contained a mismatched conditional URL. This fix ensures that resources are processed on a per-entry basis and only failing entries return appropriate errors. |
|
|
Previously, the CDA Exchange+ module was rendering an extra |
|
|
There was a bug in the Authorization Logging that reported |
|
|
Previously, the CDA Exchange+ module was not enforcing the US Core 5.0.1 constraint that a |
|
|
When using MegaScale in named partition modes, numeric resource IDs were allowed to override the requested named partition name/ID, leading to failures. This has been corrected. |
|
|
When exporting Allergy Intolerance through CDA Exchange+ module, the effective date will now include the low element with nullFlavor NI for FHIR R4. This will fix the validation errors encountered with allergy concern act. |
|
|
Fix for import issue using cda-to-fhir SDH operation where a SimpleQuantity type value has a missing leading zero. i.e .5 instead of 0.5. |
|
|
When exporting an encounter through CDA Exchange+ module, if period is null then the effective date of that encounter will now display as nullFlavor NI. |
|
|
When exporting medication activity through CDA Exchange+ module, the data type of effective date time will be displayed as TS and if it's an effective period it will be displayed as IVL_TS. |
|
|
A misconfigured migration caused FHIR Storage modules to fail to start if configured for Database Partition Mode on a non-Postgres database. |
|
|
Previously, an |
|
|
Fixed FHIR Gateway pagination to no longer return an invalid previous link on the first page of search results when one of the gateway targets has no data in Request Tenant Partition Selection Mode. |
|
|
Removed mapping of issued field from Observation resource due to it being mapped incorrectly from author time. |
|
|
Updating ID mapping for author organization to correctly map the ID instead of setting it to null. |
|
|
Previously, the CDA Exchange+ was failing to create |
|
|
Previous work in the CDA Exchange+ module to enhance the mapping of |
|
|
When exporting Allergy Intolerance through CDA Exchange+ module, a validation error would trigger on the Allergy Concern Act section with status code completed. This issue has been fixed by populating the missing effectiveDate property with a nullFlavor NI whenever clinical status is inactive. |
|
|
Previously, when a FHIR Storage module was configured to use validation support from a parent module, the |
|
|
Fixed the |
|
|
Previously, when Megascale was enabled, POST bundle requests threw a NullPointerException if a resource reference did not include a Partition ID. This has been fixed. |
|
|
Previously, PriorAuth CRD module would fail to start when CDA Exchange+ module was also configured. This behaviour has been fixed. |
|
|
Previously, the CDA Exchange+ module would throw an exception while attempting to export an Encounter resource if |
| Released | 2026-03-27 |
| Codename | Euphoria |
| HAPI FHIR | Smile CDR 2025.11.R08 is based on HAPI FHIR 8.6.8, and includes all changes and fixes included in this version. Please see the HAPI FHIR ChangeLog for details about what has changed. |
| Released | 2026-03-19 |
| Codename | Euphoria |
| HAPI FHIR | Smile CDR 2025.11.R07 is based on HAPI FHIR 8.6.7, and includes all changes and fixes included in this version. Please see the HAPI FHIR ChangeLog for details about what has changed. |
| Released | 2026-03-05 |
| Codename | Euphoria |
| HAPI FHIR | Smile CDR 2025.11.R06 is based on HAPI FHIR 8.6.6, and includes all changes and fixes included in this version. Please see the HAPI FHIR ChangeLog for details about what has changed. |
| Released | 2026-02-25 |
| Codename | Euphoria |
| HAPI FHIR | Smile CDR 2025.11.R05 is based on HAPI FHIR 8.6.5, and includes all changes and fixes included in this version. Please see the HAPI FHIR ChangeLog for details about what has changed. |
This release fixes a regression from 2025.11.R03 in which the DQM module would fail to boot if configured.
| Released | 2026-02-02 |
| Codename | Euphoria |
| HAPI FHIR | Smile CDR 2025.11.R04 is based on HAPI FHIR 8.6.3, and includes all changes and fixes included in this version. Please see the HAPI FHIR ChangeLog for details about what has changed. |
This release fixes a regression from 2025.11.R03 in which the DQM module would fail to boot if configured.
| Released | 2026-03-20 |
| Codename | Amplification |
| HAPI FHIR | Smile CDR 2025.08.R04 is based on HAPI FHIR 8.4.3, and includes all changes and fixes included in this version. Please see the HAPI FHIR ChangeLog for details about what has changed. |