Skip to main content

New in InterSystems Health Connect 2025.3

This page describes the new features, enhancements, and other significant updates in the 2025.3 release of InterSystems Health Connect™, which is a continuous delivery (CD) release.

For other information you may wish to consider related to changes included in this release, see Known Issues and NotesOpens in a new tab. For a more exhaustive list of the changes included in this release, refer to the Upgrade Impact ChecklistOpens in a new tab.

Release Information for 2025.3

The current release is 2025.3. The posting for 2025.3 is build 2025.3.0.226.0.

Enhancing Analytics and AI

Improved performance for vector search

The internal layout of the Approximate Nearest Neighbour (ANN) index used by vector search has been modified to improve duplicate entry management and reduce query-time overhead. Benchmarks show throughput and latency improvements of up to 10% depending on workload characteristics.

The updated format is applied automatically when the index is rebuilt. Rebuilding is not required for continued operation: the runtime is fully backwards compatible and can read and write indices in both the legacy and updated formats.

New version of Adaptive Analytics

Adaptive Analytics has published AtScale 2025.4.1. This release contains bug fixes and performance enhancements, and introduces support for inbound query CROSSJOIN operations that return inbound cells.

Improvements to the Cube Manager

The Cube Manager was designed to assist customers with managing cube updates, synchronization, and build. In this release, InterSystems has made several improvements in functionality and in the user interface to more easily manage cube updates. The improvements include:

  • Reworking the cube build/sync functions so that they perform dependency analysis and automatically rebuild dependent cubes when called, providing guardrails and preventing situations where dependent cubes are not built.

  • Updating the Cube Manager user interface to focus on a schedule group. The user identifies the frequency with which the cube is to be updated and the schedule is kicked off to sync (if possible) or build (is sync is not possible). Power users can continue to manage builds and syncs from the APIs, command line, or the Architect user interface.

  • Logging cube update events in %DeepSee_CubeManager.CubeEvent.

  • Including additional information to help customers identify what is happening with the cube updates in this user interface, such as previous update time, status, and next schedule time as shown below.

Healthcare Interoperability

Bulk FHIR Coordinator

InterSystems Bulk FHIR Coordinator now produces Patient, Group, and System exports conformant to the FHIR Bulk Data Access v2.0.0Opens in a new tab Implementation Guide when exporting from InterSystems FHIR Servers. In addition, ingestion performance for the Bulk FHIR Coordinator storage adapters has been significantly improved with support for configurable thread counts.

FHIR Search and management

InterSystems FHIR Server now supports the $expand operation for ValueSet resources, enabling instance-level expansions as well as expansion of ValueSets within the repository using imported CodeSystems and packages. Query chaining has also been enhanced to allow mixing forward and reverse chain syntax within a single parameter: For example, to search for Encounter of patients who are members of Group 102, use the following query:

GET [base]/Encounter?patient._has:Group:member:_id=102

Chaining is also supported through canonical references. For example, to search for all ActivityDefinitions and include any Tasks absed on them via canonical identifiers, use the following query:

GET [base]/ActivityDefinition?_revinclude=Task:instantiatesCanonical

In addition, the Capability Statement now populates the supportedProfile element on each resource type. Configuration options for unauthenticated access have also been removed.

FHIR as a Service

There is now a new InterSystems FHIR Server offer available on AWS with fully enabled FHIR repositories, search strategies, FHIR SQL Builder, Bulk FHIR Coordinator, package management, and OAuth configuration tools.

Enhancing Developer Experience

Scale interoperability production hosts while maintaining FIFO

In past releases, it was necessary to configure pool sizes of one in order to force sequential message processing in order to maintain first-in-first-out (FIFO) queuing behavior for messages in a message feed. This release introduces customer-calculated message group identifiers, which allows for pool sizes of greater than one while maintaining FIFO. These identifiers also enable parallel processing of messages that had no direct dependency, increasing throughput of a production.

There are two settings provided for Business Processes and Business Operations under the header “FIFO Message Grouping” - Group Calculation (FMGCalculation) and Group Completion Hosts (FMGCompletionHosts) - that allow developers to configure the group identifier and the host that releases the group handle for a given group identifier, respectively. Group identifiers are configured by a Data Transformation (DTL) and is typically set to a value that identifies a FIFO dependency, such as a patient or device id.

Enhancing Database Operations

Journal archiving support for Azure Blob Storage

Journal Archiving allows Health Connect to push closed journal files—after compression—directly to a cloud-based archive location, reducing the use of high-IOPS local storage. In addition to Amazon S3, Azure Blob Storage is now supported as an archive target.

Additional metrics for process information, ECP status, and the Write Daemon

The 2025.3 release includes substantial metrics additions to the metrics available through OpenTelemetry and the metrics API. These additions include:

  • An entry for each iris_process, listing its pid, state, internal wait state, job type, and client name.

  • Counters by process for global references, ObjectScript commands, block allocations, physical reads, blocks queued for writing, and journal entries.

  • A gauge for PPG block usage in megabytes by process.

  • The iris_ecp_servers metric, which reports a series for each ECP connection, listing the server it is connected to and the connection state.

  • The iris_ecp_clients metric, which is similar to iris_ecp_servers, but lists the information for clients.

  • iris_wd_* metrics, which provide insights into the state of the Write Daemon.

Daily System Performance collection service

When enabled, your instance will collect daily system performance reports. This feature is configured through the SystemPerformanceDailyReportsOn CPF parameter.

Add metrics to %SYS.ProcessQuery

This release now exposes the parent process ID and start time in %SYS.ProcessQuery. Both metrics are exposed in the Management Portal (on the Processes and Process Details pages) and in ^JOBEXAM (under Examine details).

Full support for truncations across database volumes

When using multivolume databases, you can now truncate up to any size small enough to hold the remaining data. Previously, you could only truncate the last volume for a database, but now truncation will delete empty volumes as needed.

Integrity check CHUI

This release introduces a new CHUI (character user interface) for the integrity check utility (^Integrity), significantly enhancing the usability of this important maintenance task. The new interface uses multiple background processes and offers better progress information, including tallies of globals checked and errors found while the process is running, and a number of minor quality-of-life enhancements.

With this release, InterSystems also deprecates a number of legacy subroutines in favor of this new entry point.

Enhancing Speed, Scale, and Security

Security Wallet

The new security wallet lets you securely store and access “secrets” in Health Connect without exposing those secrets to application code. In this context, a “secret” refers to any piece of sensitive information required by an application at runtime, including API keys, encryption keys, usernames, and passwords. Secrets are grouped together in collections for convenient access management and access to these secrets is audited.

Secrets are stored in the IRISSECURITY database, which must be encrypted to protect sensitive data.

New security database

Upgrading to InterSystems Health Connect 2025.2 will move security data from the IRISSYS database into the IRISSECURITY database. New installations also store their security data in IRISSECURITY.

Among other things, this change removes direct access to security globals, updates privileges for security APIs (these now require %DB_IRISSYS:R and %Admin_Secure:U), and restricts SQL queries on security data. Customers should thoroughly test their applications prior to upgrade.

You can use the new %SecurityAdministrator role for general security administration tasks.

InterSystems recommends encrypting IRISSECURITY.

For a detailed overview of these changes, see https://community.intersystems.com/post/advisory-irissecurity-intersystems-iris-20252Opens in a new tab or IRISSECURITY Upgrade ImpactOpens in a new tab.

Important:

This is a major incompatible change to a core component of InterSystems Health Connect. If you are upgrading to version 2025.2, it is imperative that you thoroughly test your software after upgrading. If you encounter any problems, please contact InterSystems SupportOpens in a new tab.

OAuth2 Authentication

This release introduces several features to improve the user experience of configuring OAuth2.

  • OAuth2 is now a native authentication type that can easily be enabled for web applications.

  • You can now create resource servers with the new OAuth2.ResourceServer class, which simplifies resource server configuration significantly. Previously, resource servers were configured as an instance of OAuth2.Client.

  • The OAuth2.ResourceServer class provides a sample authenticator for determining user permissions which, for simple configurations, requires no custom code (this previously required a custom ZAUTHENTICATE implementation). This simple authenticator can be extended and customized to suit your environment.

  • You can now use JDBC and ODBC to authenticate to InterSystems IRIS with access tokens.

Support for ECC

InterSystems IRIS now supports ECC (ECDSA) certificates for TLS configurations. ECC certificates are smaller and more computationally efficient than RSA and DSA certificates.

Modernizing Interoperability User Interface

The following enhancements are included in interoperability-enabled products in the new user interface (which remains an opt-in experience).

New Production Configuration user experience enhancements
  • When editing host categories, viewing connections are permissible.

  • A view icon on all rule sets open the specific rule set in the Rule Editor split panel.

  • Updated icons to open and close a panel.

  • When selecting the test button, the button is highlighted to indicate that the test panel is open.

  • Added a legend for Host Statuses in the information icon on a host.

  • Added drop down icons for all drop-down enabled settings fields.

  • Host Properties are now searchable, with added “expand all” sections.

  • IP Address and Port Number are now searchable in the Production Configuration Filter Bar.

  • Host Connections appear as they are registered by the front end, rather than appearing all at once when connections are fetched.

  • Pool size quantities are now displayed on each production configuration host.

  • You can now create a new category by directly entering the naming convention in the category field of the host.

  • There is now support for browser-level control find in Production Configuration.

  • Production Host items now feature the Test Host function.

  • In the new Settings Panel the X cancel icon also appears on panels to cancel an action.

  • Longer class tooltip descriptions are formatted per the class documentation.

  • Display of configuration item descriptions is enhanced to honor markup for longer, structured descriptions.

  • Action Items are grayed out when not in the context of a host item or production.

  • Creating a host enabled the automatic creation of a router and role.

  • You now have the option to Update and Recover a production, where supported.

  • Productions may not be created through the UI.

New DTL Editor user experience enhancements
  • DTL Segment Path copies with both field text and ordinal numbers.

  • The “hover over” segment icons for copying or adding a mapping are more accessible.

  • When adding a mapping, hovering over the particular segment now only shows the copy icon.

  • The DTL Editor split screen header and toolbar both remain in place when scrolling.

  • The Data Transformation Function drop-down menu is now searchable and limited to functions defined in the subclass.

  • The DTL Graphical Editor now includes a button to copy an HL7 field path when hovering over a segment.

  • Setting the Ordinal Number or Path Expressions or both will input the same expression setting when setting the DTL statement target and source fields.

New Rule Editor User Experience Enhancements
  • It is no longer possible to rename rules. Previously, that behavior cause confusion about changes to active rules. To create a new rule, use Save As instead.

  • There is now support for browser-level control find in Rule Editor.

Platform Updates

Remove Support for Red Hat 8

This release discontinues support for running InterSystems IRIS for Health on Red Hat Enterprise Linux 8 for x86–64 or ARM64.

Minimum Supported CPU Models

InterSystems Health Connect 2025.3 sets a new minimum CPU instruction set policy for Intel and AMD (amd64/x86_64) processors. CPUs are now required to have the AVX, BMI, AVX2, BMI2, MOVBE, and RDRAND instructions, which are generally available on the following CPU architectures:

  • For Intel processors: Skylake and up

  • For AMD processors: Excavator and up

FeedbackOpens in a new tab