Announcing the OpenMRS Secure Coding Course

berylkanali Avatar

OpenMRS systems support patient care and manage sensitive health information across diverse healthcare settings. Security is therefore not a separate task reserved for security experts, it is an essential part of how we design, develop, deploy, and maintain OpenMRS.

We are pleased to introduce the OpenMRS Secure Coding Course, a free, self-paced course developed to strengthen developers’ understanding of security and support the application of secure coding practices throughout the software development lifecycle.

Intended Audience

The course is designed primarily for OpenMRS core developers. It is also recommended for developers working on:

  • OpenMRS country instances
  • National and regional distributions
  • Facility-level implementations
  • Modules and other solutions built on the OpenMRS platform

Whether contributing directly to OpenMRS core or adapting the platform for a specific implementation, developers make decisions that can affect the confidentiality, integrity, and availability of sensitive health information.

Course Content and Learning Outcomes

The course introduces key security concepts within the context of OpenMRS development. It combines foundational knowledge with practical guidance that developers can apply when designing, implementing, testing, and reviewing security-sensitive code.

The course covers:

  • The OWASP Top 10 and its relevance to OpenMRS development
  • Authentication and authorization in OpenMRS
  • Roles, privileges, and the principle of least privilege
  • The safe use of proxy privileges
  • Protection of authenticated sessions
  • Cross-Site Request Forgery (CSRF) and the risks it presents to active user sessions
  • Secure REST API design
  • Secure file handling and the prevention of path-traversal vulnerabilities
  • Writing and implementing OpenMRS vulnerability tests
  • Running security tests and generating the OpenMRS Security Dashboard
  • A practical security checklist for use before submitting a pull request

The course takes approximately three hours to complete and includes short lessons and quizzes. Participants who successfully complete the course will receive a certificate of completion.

Contribution to the SAFE-OSE Project

The course was developed as part of SAFE-OSE—Secure Applications For Open-source Ecosystems—a two-year project funded through a grant from the U.S. National Science Foundation and implemented through a collaboration between Indiana University and OpenMRS.

SAFE-OSE brings together OpenMRS contributors, health informatics researchers, and computer security experts to strengthen security across the OpenMRS ecosystem through practical, sustainable, and community-driven approaches.

The project includes work to:

  • Improve secure coding guidance and training
  • Strengthen how vulnerabilities are identified, assessed, and prioritized
  • Introduce automated security checks into development and build workflows
  • Improve security governance and vulnerability-reporting processes
  • Strengthen software supply-chain security
  • Make security work more visible and accessible across the community

The OpenMRS Secure Coding Course represents an important step towards making security knowledge more accessible and applicable to developers throughout the OpenMRS community.

Strengthening Security Across the OpenMRS Ecosystem

Every developer working on OpenMRS has a role in protecting the patients, healthcare workers, and health systems that depend on the platform.

Secure development begins long before a system is deployed. It requires developers to understand potential risks, make deliberate design decisions, review code carefully, and test for vulnerabilities throughout the development lifecycle.

By completing this course, developers will be better prepared to identify common security risks and integrate secure practices into their everyday development work.

Course Access and Enrolment

The OpenMRS Secure Coding Course is available free of charge through the OpenMRS Academy.

Enrol in the OpenMRS Secure Coding Course

We encourage OpenMRS core developers, country implementation teams, and developers supporting OpenMRS distributions to complete the course and share it with their technical teams.

Additional information about the broader initiative is available in the SAFE-OSE project announcement.

Together, we can strengthen the security, resilience, and trustworthiness of the OpenMRS ecosystem.

Leave a Reply

Discover more from OpenMRS

Subscribe now to keep reading and get access to the full archive.

Continue reading