Ideagen Healthcare Guardian v25.4.0 release notes
Who is this article for?
Users and admins who want to learn more about the changes introduced in the latest release.
No special access or permissions are required.
This article contains a summary of the changes and improvements available with this release, scheduled for 18 August 2026.
Breaking changes (on-premise customers only)
External data connection security hardening
As part of our ongoing security hardening programme, connection strings for external data sources (SQL Server, Oracle, ODBC) are now validated against a network-level deny-list before use. This reduces the risk of server-side request forgery (SSRF) attacks. Model registration is also affected by this change.
On-premise customers should check how Ideagen Healthcare Guardian connects to their database. If the application connects over a private network, on the same host, or via a local IP address, a small configuration change will be needed before upgrading. The steps involved are straightforward and can be completed at any time in advance, without any impact on your current system. See the related article for full instructions.
Once any necessary changes have been made, you may request the release upgrader through your account manager as normal. Please contact your Customer Success Manager or our support team if you are unsure whether this affects you, or you need assistance.
What's new
Hub cascade logout
Ideagen Healthcare Guardian now supports cascade logout with Ideagen Mazlan Home. When a user logs out of any Hub-integrated product, the logout is automatically propagated across all Hub-integrated products, ending all active sessions. This can be initiated by the user or by an administrator. All logout events are recorded in Ideagen Healthcare Guardian for audit purposes.
Generic external look-up data source
This release introduces a generic external look-up data source framework, allowing administrators to connect Ideagen Healthcare Guardian to external data systems via Live Connect. Once configured, a new External ID question type can be added to questionnaires, enabling users to look up and auto-populate data from the external source when filling in a form, improving data quality and reducing errors and re-keying.
Patient Demographics: multi-trust support
Organisations operating across multiple trusts can now configure Ideagen Healthcare Guardian to route patient lookups to the correct demographic system automatically. When a user triggers a patient lookup, the answer to a designated question determines which system data is retrieved from — reducing manual effort and the risk of cross-trust data errors.
Question Manager navigation
Lists and Transform to Group have moved from the Question Manager top tabs to the side navigation - reflecting that management of these features is independent of specific questionnaires. No functionality has changed, just a small UI shift.
Security improvements
As part of our ongoing vulnerability scanning and continuous improvement programme, this release includes a number of proactive security enhancements. These changes reflect our commitment to maintaining the highest security standards and have no impact on how you use the product.
Fixes
LFPSE medication questions not showing — Fixed an issue where medication questions were not appearing on the LFPSE form despite conditions being met.
LFPSE medication payload error — Fixed an intermittent issue where medicine code fields could be submitted to NHSE as empty values rather than being omitted, causing LFPSE submission errors for medication incident types.
Questionnaire locks releasing too early — Fixed an issue where editable locks on a questionnaire could release after around 20–25 minutes, allowing two users to edit the same record. This has been released with a heartbeat to ensure the system knows a user is still in the record
Audit dashboard: planning pattern period handling — Resolved an issue where an audit could produce an error on the dashboard if its planning pattern did not extend beyond the current date.
Live Connect: period end date slicer — Resolved an issue where filtering a Live Connect table by period end date returned no results when using certain date formats.
Permission triggers not applying for repeatable sections — Fixed an issue where a permission trigger did not grant record access to the intended user group when the record was in specific statuses within a second or later repeatable section.
Level of Harm triggers not firing after LFPSE V6 update — Resolved an issue where Level of Harm notification and permission triggers stopped firing on first save following the LFPSE V6 update.
Transform column values: missing question aliases — Fixed an issue where calculated fields configured in a scheduled import connection did not appear in the Transform Column Values dialog.
Further reading:
Preparing for upgrade: external data source connectivity changes in 25.4