Dormant contractor account exposed 4,000 dental patient records for years

← Back to the feed

Dormant contractor account exposed 4,000 dental patient records for years

The Register · 1 hour ago

A digital marketing consultant carrying out a routine security audit for a dental practice discovered a hidden admin account, set up years earlier by a former contractor, that had silent access to around 4,000 patient records. The account belonged to a scheduling company the practice had stopped using back in 2021, yet it remained active and undetected for at least three years, exposing protected health information and creating a potential HIPAA compliance risk. The case highlights how forgotten "zombie" accounts, rather than obvious lapses like written-down passwords, often pose the more serious long-term security threat.

Chris Kirksey, founder of healthcare marketing firm Direction, found three admin-level accounts with database access during the audit, none of which the practice's office manager knew existed. He removed all three and introduced a new policy requiring automatic access revocation whenever a vendor relationship ends, alongside twice-yearly reviews of all account access. Kirksey said he has since uncovered similar hidden accounts at six other healthcare practices, underlining the need for regular audits of who — and what — can access sensitive systems.

  • Forgotten contractor account had hidden access to 4,000 dental patient records
  • Account was active three years after its associated vendor was dropped
  • Auditor found similar issues at six other healthcare practices since

Business Celebrity Companies Entertainment

Read the full article at the source →

Originally published by The Register as “Dental contractor set up secret account with access to 4,000 patient records then left the company”.