Dormant contractor account exposed 4,000 dental patient records for years
A digital marketing consultant carrying out a routine security audit for a dental practice discovered a hidden admin account, set up years earlier by a former contractor, that had silent access to around 4,000 patient records. The account belonged to a scheduling company the practice had stopped using back in 2021, yet it remained active and undetected for at least three years, exposing protected health information and creating a potential HIPAA compliance risk. The case highlights how forgotten "zombie" accounts, rather than obvious lapses like written-down passwords, often pose the more serious long-term security threat.
Chris Kirksey, founder of healthcare marketing firm Direction, found three admin-level accounts with database access during the audit, none of which the practice's office manager knew existed. He removed all three and introduced a new policy requiring automatic access revocation whenever a vendor relationship ends, alongside twice-yearly reviews of all account access. Kirksey said he has since uncovered similar hidden accounts at six other healthcare practices, underlining the need for regular audits of who — and what — can access sensitive systems.
- Forgotten contractor account had hidden access to 4,000 dental patient records
- Account was active three years after its associated vendor was dropped
- Auditor found similar issues at six other healthcare practices since
Business Celebrity Companies Entertainment
Read the full article at the source →
Originally published by The Register as “Dental contractor set up secret account with access to 4,000 patient records then left the company”.