Cybersecurity: 24/7/365

Somewhere in your organization, lab results arrive in the electronic health record (EHR) without anyone retyping them. Admissions reach the billing system on their own. Something is moving those HL7 messages, and there is a fair chance it is Mirth Connect.
In March 2025 that something stopped being free to upgrade. If you run Mirth Connect yourself, or a vendor runs it for you, you now have a decision to make. This guide covers what changed, how to tell whether it affects you, and how each alternative to Mirth Connect compares.
Mirth Connect is a healthcare integration engine owned by NextGen Healthcare. For years it was the default open-source interface engine, and plenty of healthcare organizations built their healthcare interoperability on it.
On March 19, 2025, NextGen announced that Mirth Connect 4.6 and every later release would be commercial only. The open-source license ended with Mirth Connect 4.5.2, released in September 2024 as the last open-source release. The source code for new versions is no longer public.
NextGen gave open-source users three paths: stay on their current version, move to 4.5.2, or buy a license and upgrade to 4.6. Its announcement does not say that 4.5.2 will keep receiving security fixes.
Mostly organizations with more integration than staff. Mid-size hospitals and health systems run it to connect the EHR to labs, radiology and billing. Reference labs use it to send results back to the ordering practice, and imaging centers use it for both HL7 and DICOM traffic.
Health-tech vendors are the group most often missed. Many products that exchange data with an EHR carry Mirth inside them, so a practice can depend on it without ever having installed it. Health information exchanges and public health reporting feeds use it too.
Small practices rarely run their own copy. Their exposure comes through those vendors, which is why the checks further down start with a phone call rather than a server.
Version 4.5.2 and earlier remain free to run under their original open-source license. Nothing forces you off them, and they keep working.
What you do not get is a future. Every fix and feature after 4.5.2 requires commercial licensing. NextGen does not publish its prices; licenses are quoted directly or through resellers. One integration consultancy, Saga IT, estimates commercial Mirth at "low-to-mid five figures" a year for a single production instance. Treat that as a vendor's estimate, and get a real quote before you budget.
An integration engine is not a background utility. It holds credentials and encryption keys for your EHR, your lab and your billing system, and it handles protected health information all day.
Mirth Connect has already been a target. CVE-2023-43208, an unauthenticated remote code execution flaw in versions before 4.4.1, was added to the CISA Known Exploited Vulnerabilities catalog on May 20, 2024. Attackers were using it in the wild against healthcare systems.
So check your version first. Anything older than 4.4.1 is exposed to a flaw that is being exploited today. And 4.5.2 is a version with no committed patch path, which is the same problem as any end-of-life software in your practice. It is fine today and a liability the first time a new flaw is found.
Many organizations run Mirth without knowing it, because a vendor installed it inside an interface. Three checks find most of it.
If a vendor runs Mirth for you, the licensing change is their problem to solve, but the risk is still yours. Their engine touches your patient data, which puts this squarely inside vendor risk management.
There are four realistic paths. The first two keep your existing channels; the last two mean rebuilding them.
| Option | License | Your existing channels | Best fit |
|---|---|---|---|
| Commercial Mirth Connect 4.6+ | Paid, from NextGen | Upgrade in place | Teams that want vendor support and accept the cost |
| Eclipse Open Integration Engine | Open source (MPL 2.0) | Designed to run them as they are | Teams that want to stay open source with community governance |
| BridgeLink | Open source (MPL 2.0), paid services available | Designed to run them as they are | Teams that want an open engine with one vendor behind it |
| Another engine (Rhapsody, Corepoint, Cloverleaf, Qvera, InterSystems) | Commercial | Rebuilt from scratch | Larger organizations replacing their integration platform anyway |
Open Integration Engine is a community fork of the last open-source Mirth Connect release, started in March 2025 under the Mozilla Public License 2.0. On September 7, 2026 it became an Eclipse Foundation project, now in incubation as Eclipse Open Integration Engine.
That matters for a reason beyond the license. A fork run by one company can disappear with that company. A project at a foundation, with contributors from several vendors, is harder to abandon. The project is shipping, too: version 4.6.0 was released in July 2026.
BridgeLink is another open-source engine in the Mirth family, stewarded by Innovar Healthcare. It is released under the same Mozilla license and ships updates regularly. The difference from Open Integration Engine is governance: one company leads it, which some teams prefer because one company is accountable.
Rhapsody, Corepoint, Cloverleaf, Qvera and InterSystems HealthShare Health Connect are mature integration platforms with strong support. None of them can import a Mirth channel. Every interface has to be rebuilt, mapped and tested again, which turns a licensing question into a full integration project.
Start from what you have, not from feature lists.
Whichever engine you land on, the interfaces themselves still have to be right. Our guide to FHIR vs HL7 covers why most organizations will run both standards for years, and where FHIR integration fits next to an engine. The healthcare API integration guide covers where modern APIs fit alongside an engine.
Moving from Mirth 4.5.2 to Open Integration Engine is the smallest migration on the list, but it is not a file copy. Plan to migrate the way you would plan any deployment that carries live clinical workflow.
A move to a different commercial engine follows the same steps, plus a rebuild of every channel. Budget it like new interface work; our breakdown of what EHR integration costs gives the ranges.
Mirth Connect still works, and nobody is switching it off. But an engine with no patch path that carries your patient data is a risk that grows quietly. The free route forward exists and is getting stronger, now that Open Integration Engine sits at the Eclipse Foundation.
If you would rather not run the migration yourself, our HL7 integration team moves Mirth installs to Open Integration Engine or a licensed engine. Your interfaces run in parallel and are tested message by message before anything is switched over.
Ready to take the next step? Explore our healthcare IT services, book a free consultation, or compare our plans.