How bad is it to have the phpinfo page open to the public. On a scale of 1 - 10, how bad?

Since we are dealing with HIPAA info, how safe is this?

I’d give it a 10 since there is no reason to make information like that public. The less a user can gather about a server, the better.

2 Likes

Thank you. I am working with a customer (but do not have access to the live server) who has this very file open by previous OpenEMR vendors. I have let them know how to address it and nothing has been done to fix it. I have a meeting with them today so it helps that I have a second opinion. I was starting to think I might be overreacting… but apparently not.

Thank you.