shouldiuse.io

Categories

VERDICT

Should I use Mirth (Mirth Connect)?

Taction Software — FHIR Integration with Mirth Connect - mirth.support

Depends. Buy only if you run healthcare interfaces — HL7/FHIR pipelines between EHRs, labs, and hospital systems — and can staff integration engineering. Small teams or non-healthcare data plumbing should pick a lighter integration tool.

Confidence

Medium. Based on ~20 public sources. Note: mirth.support is Taction Software's third-party support site for Mirth Connect; several 'Mirth' search results (a novel, a cocktail bar) were excluded as unrelated.

Ratings

  • Value for money
  • Ease of useNo usable evidence in sources
  • Feature depth
  • Support qualityNo usable evidence in sources
  • Security posture

Pricing

Mirth Connect (licensed)

Flat-fee; amounts public on vendor site but not in reviewed sources

ModelShifting to paid
Monthly feesNot disclosed
HardwareNot disclosed

Best for

  • Hospital IT departments
  • EHR-to-lab HL7 pipelines
  • FHIR integration projects
  • Teams with integration engineers

Not for

  • Small teams syncing simple app data — massive overkill
  • Non-healthcare integration work
  • Buyers without dedicated engineering staff
  • Anyone counting on the old free open-source edition

Gotchas - check before you buy

high

License change effective 2025 — existing open-source users face migration or paid upgrade decisions

high

CVE-2023-43208 RCE was under active exploitation; unpatched deployments are a real liability

medium

NextGen training is a separate paid purchase; Reddit users question its cost

medium

is a third-party vendor (Taction Software), not NextGen's official product site

Pros and cons

Pros

  • Proven across hospital Epic/lab integration case studies
  • Handles both HL7 and FHIR healthcare standards
  • Flat-fee licensing option from NextGen
  • Deployable via AWS Marketplace images

Cons

  • Going proprietary; open-source era ending
  • Critical RCE vulnerabilities actively exploited
  • Licensing change created cost uncertainty for existing users
  • Requires specialized integration engineering to run well

Sources & method

Analyzed 10/01/2026 - 10 sources - History of critical RCE vulnerabilities, including one actively exploited — CISA-advised; strict patching required.

official x2review x4security x2news x2
  • CVE-2023-43208 — RCE, actively exploited, NextGen Healthcare Mirth Connect remote code execution; CISA medical advisory and HIPAA Journal reported active exploitation.
  • CVE-2023-37679 — RCE, Separate remote code execution vulnerability in NextGen Mirth Connect, tracked in SentinelOne's database.
  • XXE, weak crypto, weak password policy, Reported in the official NextGen healthcare GitHub repo as an open product security issue.

Key stats

  • Value for money: 3/5

    Rating

  • Flat-fee; amounts public on vendor site but not in reviewed sources

    Starting price

  • 10

    Sources

  • Analyzed

  • Value for money: 3/5. Flat-fee exists, but 2025 license shift unsettled costs
  • Ease of use. No usable evidence in sources
  • Feature depth: 4/5. Proven HL7/FHIR engine in hospital case studies
  • Support quality. No usable evidence in sources
  • Security posture: 2/5. Critical RCEs actively exploited in 2023–24
  • HL7/FHIR interface engine Category Healthcare data integration
  • 2 (2023) Known RCE CVEs CVE-2023-43208, CVE-2023-37679
  • Shifting to paid License model Closed-source move announced 2025
  • 14+ Tracked alternatives Open-source and paid, per 2026 roundup

Pricing

Mirth Connect (licensed)

Flat-fee; amounts public on vendor site but not in reviewed sources

  • NextGen offers simple flat-fee licensing
  • Vendor site lists two product lines with public prices

Security

History of critical RCE vulnerabilities, including one actively exploited — CISA-advised; strict patching required.

  • CVE-2023-43208 — RCE, actively exploitedNextGen Healthcare Mirth Connect remote code execution; CISA medical advisory and HIPAA Journal reported active exploitation.⁴
  • CVE-2023-37679 — RCESeparate remote code execution vulnerability in NextGen Mirth Connect, tracked in SentinelOne's database.
  • XXE, weak crypto, weak password policyReported in the official NextGen healthcare GitHub repo as an open product security issue.

What users say

Healthcare IT practitioners treat Mirth Connect as a capable interface engine, but the licensing shift and security patch burden drive visible complaints.

“Mirth Connect is going proprietary”
LinkedIn post by Sidharth Ramesh
“NextGen Mirth Connect Moving to a Licensed Model”
Reddit, r/healthIT
“What's next for us?”
Reddit, r/mirth

Companies that use it

  • LUXITH G.I.E. (Luxembourg)
  • Leica Biosystems
  • Medtronic
Full analysis

Based on ~20 public sources. Note: mirth.support is Taction Software's third-party support site for Mirth Connect; several 'Mirth' search results (a novel, a cocktail bar) were excluded as unrelated.

Proven HL7/FHIR engine for hospital integration — but now paid licensing, real RCE history, overkill outside healthcare IT.

Methodology

Based on ~20 public sources. Note: mirth.support is Taction Software's third-party support site for Mirth Connect; several 'Mirth' search results (a novel, a cocktail bar) were excluded as unrelated.

Sources

  1. review
  2. review
  3. official
  4. security
  5. security
  6. news
  7. review
  8. official
  9. review
  10. news

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.