Urgent.News

What's breaking now, across thousands of outlets.

Health & Medicine

Dental contractor set up secret account with access to 4,000 patient records then left the company

Toothless security

Dental contractor set up secret account with access to 4,000 patient records then left the company

A dental contractor inadvertently created a security risk by setting up a secret account with access to 4,000 patient records for a practice they had stopped using in 2021. The account, which had been active for at least three years, showed no signs of being noticed by the office manager who was responsible for using the system.

The contractor, who later left the company, failed to inform anyone about the account, leaving it dormant and potentially vulnerable. Chris Kirksey, the founder and CEO of Direction, a digital marketing and SEO company, discovered the account during a security audit of the dental practice's systems. He immediately took steps to remove the unnecessary accounts, including the one with administrative access to patient data.

To prevent similar security breaches in the future, Kirksey implemented new policies that automatically shut down vendor accounts upon termination and scheduled reviews of access rights twice a year. Kirksey noted that many organizations overlook the risk posed by forgotten or unused accounts, which can lead to long-term security vulnerabilities.

He emphasized the importance of conducting regular audits and ensuring all accounts have a valid reason for existence. By proactively addressing such issues, organizations can mitigate the risk of potential HIPAA compliance violations and protect sensitive patient information.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Health & Medicine

More from Thursday 10 September →