Cybersecurity: 24/7/365

Blog

Mirth Connect Alternatives After the License Change
by 4MEDNET Team
October 5, 2026
Integration & Development

Somewhere in your organization, lab results arrive in the electronic health record (EHR) without anyone retyping them. Admissions reach the billing system on their own. Something is moving those HL7 messages, and there is a fair chance it is Mirth Connect.

In March 2025 that something stopped being free to upgrade. If you run Mirth Connect yourself, or a vendor runs it for you, you now have a decision to make. This guide covers what changed, how to tell whether it affects you, and how each alternative to Mirth Connect compares.

What changed with Mirth Connect

Mirth Connect is a healthcare integration engine owned by NextGen Healthcare. For years it was the default open-source interface engine, and plenty of healthcare organizations built their healthcare interoperability on it.

On March 19, 2025, NextGen announced that Mirth Connect 4.6 and every later release would be commercial only. The open-source license ended with Mirth Connect 4.5.2, released in September 2024 as the last open-source release. The source code for new versions is no longer public.

NextGen gave open-source users three paths: stay on their current version, move to 4.5.2, or buy a license and upgrade to 4.6. Its announcement does not say that 4.5.2 will keep receiving security fixes.

Who uses Mirth Connect?

Mostly organizations with more integration than staff. Mid-size hospitals and health systems run it to connect the EHR to labs, radiology and billing. Reference labs use it to send results back to the ordering practice, and imaging centers use it for both HL7 and DICOM traffic.

Health-tech vendors are the group most often missed. Many products that exchange data with an EHR carry Mirth inside them, so a practice can depend on it without ever having installed it. Health information exchanges and public health reporting feeds use it too.

Small practices rarely run their own copy. Their exposure comes through those vendors, which is why the checks further down start with a phone call rather than a server.

Is Mirth Connect still free?

Version 4.5.2 and earlier remain free to run under their original open-source license. Nothing forces you off them, and they keep working.

What you do not get is a future. Every fix and feature after 4.5.2 requires commercial licensing. NextGen does not publish its prices; licenses are quoted directly or through resellers. One integration consultancy, Saga IT, estimates commercial Mirth at "low-to-mid five figures" a year for a single production instance. Treat that as a vendor's estimate, and get a real quote before you budget.

Why staying on Mirth 4.5.2 is a security decision

An integration engine is not a background utility. It holds credentials and encryption keys for your EHR, your lab and your billing system, and it handles protected health information all day.

Mirth Connect has already been a target. CVE-2023-43208, an unauthenticated remote code execution flaw in versions before 4.4.1, was added to the CISA Known Exploited Vulnerabilities catalog on May 20, 2024. Attackers were using it in the wild against healthcare systems.

So check your version first. Anything older than 4.4.1 is exposed to a flaw that is being exploited today. And 4.5.2 is a version with no committed patch path, which is the same problem as any end-of-life software in your practice. It is fine today and a liability the first time a new flaw is found.

How to tell whether you depend on Mirth

Many organizations run Mirth without knowing it, because a vendor installed it inside an interface. Three checks find most of it.

  1. Ask your interface vendors directly. Your lab, imaging and EHR integration vendors know which engine carries your feeds. Ask which product and which version.
  2. Look at your servers. A Mirth deployment usually shows up as a service called Mirth Connect, with an administrator console that opens on port 8443 by default.
  3. Read your contracts. If a vendor supplied the engine, the agreement should say who pays for the license now and who applies security updates.

If a vendor runs Mirth for you, the licensing change is their problem to solve, but the risk is still yours. Their engine touches your patient data, which puts this squarely inside vendor risk management.

The Mirth Connect alternatives, compared

There are four realistic paths. The first two keep your existing channels; the last two mean rebuilding them.

OptionLicenseYour existing channelsBest fit
Commercial Mirth Connect 4.6+Paid, from NextGenUpgrade in placeTeams that want vendor support and accept the cost
Eclipse Open Integration EngineOpen source (MPL 2.0)Designed to run them as they areTeams that want to stay open source with community governance
BridgeLinkOpen source (MPL 2.0), paid services availableDesigned to run them as they areTeams that want an open engine with one vendor behind it
Another engine (Rhapsody, Corepoint, Cloverleaf, Qvera, InterSystems)CommercialRebuilt from scratchLarger organizations replacing their integration platform anyway

Eclipse Open Integration Engine

Open Integration Engine is a community fork of the last open-source Mirth Connect release, started in March 2025 under the Mozilla Public License 2.0. On September 7, 2026 it became an Eclipse Foundation project, now in incubation as Eclipse Open Integration Engine.

That matters for a reason beyond the license. A fork run by one company can disappear with that company. A project at a foundation, with contributors from several vendors, is harder to abandon. The project is shipping, too: version 4.6.0 was released in July 2026.

BridgeLink

BridgeLink is another open-source engine in the Mirth family, stewarded by Innovar Healthcare. It is released under the same Mozilla license and ships updates regularly. The difference from Open Integration Engine is governance: one company leads it, which some teams prefer because one company is accountable.

Commercial engines

Rhapsody, Corepoint, Cloverleaf, Qvera and InterSystems HealthShare Health Connect are mature integration platforms with strong support. None of them can import a Mirth channel. Every interface has to be rebuilt, mapped and tested again, which turns a licensing question into a full integration project.

How to choose

Start from what you have, not from feature lists.

  • A handful of stable interfaces, no budget for licensing: move to Open Integration Engine. You keep your channels and get a maintained engine.
  • Interfaces your business cannot run without, and a team that wants a support contract: price commercial Mirth against an open engine plus a paid support vendor. Both exist.
  • A planned overhaul of your whole integration layer: evaluate the commercial engines, because you are rebuilding anyway.
  • No one in-house to run an engine: consider a managed service, where a support vendor hosts and patches the engine for you, on-premises or in the cloud.
  • A vendor runs it for you: ask which path they chose and get it in writing.

Whichever engine you land on, the interfaces themselves still have to be right. Our guide to FHIR vs HL7 covers why most organizations will run both standards for years, and where FHIR integration fits next to an engine. The healthcare API integration guide covers where modern APIs fit alongside an engine.

What a migration involves

Moving from Mirth 4.5.2 to Open Integration Engine is the smallest migration on the list, but it is not a file copy. Plan to migrate the way you would plan any deployment that carries live clinical workflow.

  1. Inventory every existing Mirth channel. List each interface, its source, its destination and who owns the system on the other end.
  2. Back up the configuration and database. Export channels and code templates before anything changes.
  3. Stand up the new engine in parallel. Point a test instance at the same configuration and replay real message traffic through it.
  4. Compare outputs message by message. Custom JavaScript transformers and third-party plugins are where differences hide.
  5. Cut over one interface at a time, with the old engine kept ready until each feed has run cleanly for a full business cycle.

A move to a different commercial engine follows the same steps, plus a rebuild of every channel. Budget it like new interface work; our breakdown of what EHR integration costs gives the ranges.

The bottom line

Mirth Connect still works, and nobody is switching it off. But an engine with no patch path that carries your patient data is a risk that grows quietly. The free route forward exists and is getting stronger, now that Open Integration Engine sits at the Eclipse Foundation.

If you would rather not run the migration yourself, our HL7 integration team moves Mirth installs to Open Integration Engine or a licensed engine. Your interfaces run in parallel and are tested message by message before anything is switched over.

Ready to take the next step? Explore our healthcare IT services, book a free consultation, or compare our plans.

HIPAACybersecurityManaged ITRansomwareComplianceEHRData BreachAI AutomationBackup & DR
4MEDNET
Contact Us
Ready to secure your practice?
Schedule a free IT assessment today
Book Your Free IT Assessment