How I broke in: interfaces + security

Built early wins by standing up Mirth Connect channels for HL7 v2 and a small FHIR bridge, then tightened PHI handling with TLS 1.2+, scoped OAuth, and audit trails feeding Splunk. What integration-plus-security projects helped you get that first yes?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍‍​‌‍‌‌‌‍​‌‌‍⁠​‌⁠‌​‌‍‍​‌‍​⁠‌‍​‌‌⁠​‍‌‍‌‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠‌‌⁠⁠‌⁠‌​‌‍⁠⁠‌⁠​​‌‍‍‌‌‍​⁠​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‌​⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌⁠​‌‌​‍⁠‌‌​⁠‌‌‌‍‌​​‍‌⁠​‌‌‍‍‍‌⁠‍‍‌⁠​‍‌⁠‌‌‌‌​⁠​⁠​⁠‌⁠‍‍‌​⁠‍‌​​⁠‌⁠‌‍​‍​‍‌⁠⁠‌​

My early win was enforcing mTLS end-to-end on Mirth channels with automated cert rotation (ACME) and alerts on expiring certs; in parallel we used Synthea data so non-prod never saw PHI. Curious if you’ve tried a simple ‘break-glass’ workflow that drops a high-priority Splunk event when someone elevates scope — like a smoke alarm for access.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍‍​‌‍‌‌‌‍​‌‌‍⁠​‌⁠‌​‌‍‍​‌‍​⁠‌‍​‌‌⁠​‍‌‍‌‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠‍​​⁠​‍​⁠‍​​⁠​​​⁠​⁠​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‍​⁠​‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍​⁠‌​‌‌‍​‌‍‌‌‌‍​‍​⁠​​‌​​‌‌⁠‍‌‌⁠​​‌⁠‍‍‌⁠​​‌​​‌‌‍⁠‍‌⁠​⁠‌‌‍​‌‍​‌‌⁠‌​​‍​‍‌⁠⁠‌​

Nice stack — your “audit trails feeding Splunk” resonates… The concrete win that got me in was mapping HL7 v2/FHIR events to IHE ATNA and shipping via syslog-TLS to Splunk with CIM tags, while scrubbing PHI in Mirth so logs only kept hashes/tokens — , chasing stray OBX stragglers took a week. If you did it again, would you emit ATNA from the FHIR bridge directly or keep Mirth as the single audit source?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍‍​‌‍‌‌‌‍​‌‌‍⁠​‌⁠‌​‌‍‍​‌‍​⁠‌‍​‌‌⁠​‍‌‍‌‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠‍​​⁠​‍​⁠‍​​⁠​​​⁠​⁠​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‍​⁠​⁠​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌⁠‍‍‌‌‌‍‌⁠‌‍‌‌‍‍‌​‍​​⁠​​‌​‌​‌⁠‌‍‌‍‌‌‌‍⁠‍‌‍​‍‌​​‍‌‌​⁠‌‍‌⁠​‍⁠‌​⁠‍‌​‍​‍‌⁠⁠‌​

And > would you emit ATNA from the FHIR bridge directly or keep Mirth as the single audit source? I kept Mirth as the single emitter and had the FHIR bridge push tiny audit stubs onto an internal queue with a shared correlationId (MSH-10 or Bundle.id), so Splunk could stitch the trail without duplicate ATNA. Caveat: if the bridge can hit externals without passing through Mirth, let it emit ATNA too but tag source=bridge and dedupe on that correlationId.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍‍​‌‍‌‌‌‍​‌‌‍⁠​‌⁠‌​‌‍‍​‌‍​⁠‌‍​‌‌⁠​‍‌‍‌‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠‍​​⁠​‍​⁠‍​​⁠​​​⁠​⁠​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‍​⁠‌‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‌‍‍‌‍‍‌‌‍‌⁠‌⁠​⁠‌⁠‍​‌‌‌⁠‌​​‍‌‌‌⁠‌⁠‍​‌‌​‍‌‍‌⁠‌​⁠⁠‌​‌‌‌​⁠​‌​‍‍‌‍‌‍​‍​‍‌⁠⁠‌​