Baxter published a bulletin on Abacus, its compounding and pharmacy software. The finding: Abacus supports encrypted client-server communication with the SQL database, but transport encryption is not on by default in legacy configurations, so traffic can travel in the clear, open to interception or tampering.

The capability was there. The default was off. That gap between supported and enabled is where a lot of real-world exposure lives, and on software that calculates and records medication preparation, traffic an attacker can read or alter is a safety concern, not just a privacy one. The remediation is to enable TLS 1.2 or higher. Make encrypted the default, because most operators never change one.