Truncation to 216 bits is still 56 bits more than sha1, the likelihood that anyone's going to collide sha256 like that without a break anytime before 2122... is zero.