Urgent.News

What's breaking now, across thousands of outlets.

Health & Medicine

Dental contractor set up secret account with access to 4,000 patient records then left the company

Toothless security

Dental contractor set up secret account with access to 4,000 patient records then left the company

An unnamed dental contractor inadvertently created a secret account with access to 4,000 patient records for a dental practice he had recently worked with. The account, which belonged to the contractor, had been active for at least three years and posed a significant potential HIPAA compliance risk. The office manager, unaware of the existence of this account, did not take any action to shut it down.

The contractor, Chris Kirksey, discovered the account while conducting a security audit of the dental practice's systems last year. He promptly removed all three admin accounts he found, including the problematic one, and implemented new policies to prevent the creation of similar accounts in the future. Kirksey has since identified similar security vulnerabilities at six other healthcare practices he has worked with, emphasizing the importance of regularly auditing all accounts with access to sensitive data.

He stresses that the most dangerous security risks often come from forgotten or abandoned accounts that remain active for years, potentially causing unseen damage.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Health & Medicine

More from Thursday 10 September →