Dental contractor set up secret account with access to 4,000 patient records then left the company
Toothless security
An unnamed dental contractor inadvertently created a secret account with access to 4,000 patient records for a dental practice he had recently worked with. The account, which belonged to the contractor, had been active for at least three years and posed a significant potential HIPAA compliance risk. The office manager, unaware of the existence of this account, did not take any action to shut it down.
The contractor, Chris Kirksey, discovered the account while conducting a security audit of the dental practice's systems last year. He promptly removed all three admin accounts he found, including the problematic one, and implemented new policies to prevent the creation of similar accounts in the future. Kirksey has since identified similar security vulnerabilities at six other healthcare practices he has worked with, emphasizing the importance of regularly auditing all accounts with access to sensitive data.
He stresses that the most dangerous security risks often come from forgotten or abandoned accounts that remain active for years, potentially causing unseen damage.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.