Dental contractor set up secret account with access to 4,000 patient records then left the company

Sep 10, 2026 - 12:30
0 0
Dental contractor set up secret account with access to 4,000 patient records then left the company

SECURITY

Toothless security

PWNED Welcome back to PWNED, the weekly column where we highlight examples of how not to handle your security. This week’s tale of woe comes from a very unhealthy part of the healthcare sector.

Have a story about someone leaving a gaping hole in their network? Share it with us at [email protected]. Anonymity is available upon request.

Our story comes courtesy of Chris Kirksey, founder and CEO of Direction, a digital marketing and SEO company that works in the healthcare industry. He also does security audits of his clients’ systems.

Last year, Kirksey was checking out a dental practice’s systems and noticed something strange. There were three accounts that had admin access to the patient database, including one that belonged to a scheduling company the dentists had stopped using all the way back in 2021. 

The account had been active for at least three years and could access 4,000 patient records. Leaving an unnecessary account with access to protected health information created a potential HIPAA compliance risk, particularly if someone no longer authorized to view the data could still get to it.

The office manager responsible for using the system didn’t even know that this dangerous login existed. Apparently, a contractor who set up the account never told anybody, then left the company. Because no one knew that the account existed, no one knew to kill it.

Kirksey immediately set about getting rid of all three admin accounts he found on the dental practice’s system. He then set up new policies for his client.

“I built a permanent rule after that,” he said. “Every vendor relationship that ends now triggers an automatic access shutdown and the full list gets reviewed twice a year no matter what.”

Since the incident, Kirksey has found similar security holes at six other healthcare practices he has worked with. Yikes!

“Everyone worries about the sticky note with a password on it or the file just called passwords.xls, because those get caught fast and make a good story,” he told us. “Nobody worries about the login they forgot even exists, and that is usually the one still wide open years later, causing real, unseen damage.”

The lesson here is pretty straightforward. You need to see all of the accounts that have access to your data and make sure that they all have a reason to exist. Conduct regular audits, even if nothing seems wrong.

And, as we’ve seen before, zombie accounts can kill. When an employee or contractor leaves, check not only which accounts they used, but also which accounts they created while doing the job. ®

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0

Comments (0)

User