What's probably WAY worse than this is that most healthcare providers running OpenEMR are likely on older versions of OpenEMR where CVEs are already detected.
Well, it's not popular maybe on bigger hospitals, but back in the day I think it was relatively popular on smaller practices even on the US. I don't know if it has lost traction (or not) with the popularization of cloud services, I'm not super up to date...