{"id":890428,"date":"2026-09-10T11:32:09","date_gmt":"2026-09-10T11:32:09","guid":{"rendered":"https:\/\/www.newsbeep.com\/ca\/890428\/"},"modified":"2026-09-10T11:32:09","modified_gmt":"2026-09-10T11:32:09","slug":"dental-contractor-set-up-secret-account-with-access-to-4000-patient-records-then-left-the-company","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ca\/890428\/","title":{"rendered":"Dental contractor set up secret account with access to 4,000 patient records then left the company"},"content":{"rendered":"<p class=\"kicker above\" style=\"\">\n        SECURITY\n    <\/p>\n<p class=\"subtitle below\" style=\"\">\n        Toothless security\n    <\/p>\n<p>PWNED Welcome back to PWNED, the weekly column where we highlight examples of how not to handle your security. This week\u2019s tale of woe comes from a very unhealthy part of the healthcare sector.<\/p>\n<p>Have a story about someone leaving a gaping hole in their network? Share it with us at\u00a0<a href=\"https:\/\/www.theregister.com\/security\/2026\/09\/10\/dental-contractor-set-up-secret-account-with-access-to-4000-patient-records-then-left-the-company\/mailto:pwned@sitpub.com\" rel=\"nofollow noopener\" target=\"_blank\">pwned@sitpub.com<\/a>. Anonymity is available upon request.<\/p>\n<p>Our story comes courtesy of Chris Kirksey, founder and CEO of <a href=\"https:\/\/direction.com\/company\/\" rel=\"nofollow noopener\" target=\"_blank\">Direction<\/a>, a digital marketing and SEO company that works in the healthcare industry. He also does security audits of his clients\u2019 systems.<\/p>\n<p>Last year, Kirksey was checking out a dental practice\u2019s systems and noticed something strange. There were three accounts that had admin access to the patient database, including one that belonged to a scheduling company the dentists had stopped using all the way back in 2021.\u00a0<\/p>\n<p>The account had been active for at least three years and could access 4,000 patient records. Leaving an unnecessary account with access to protected health information created a potential HIPAA compliance risk, particularly if someone no longer authorized to view the data could still get to it.<\/p>\n<p>The office manager responsible for using the system didn\u2019t even know that this dangerous login existed. Apparently, a contractor who set up the account never told anybody, then left the company. Because no one knew that the account existed, no one knew to kill it.<\/p>\n<p>Kirksey immediately set about getting rid of all three admin accounts he found on the dental practice\u2019s system. He then set up new policies for his client.<\/p>\n<p>\u201cI built a permanent rule after that,\u201d he said. \u201cEvery vendor relationship that ends now triggers an automatic access shutdown and the full list gets reviewed twice a year no matter what.\u201d<\/p>\n<p>Since the incident, Kirksey has found similar security holes at six other healthcare practices he has worked with. Yikes!<\/p>\n<p>\u201cEveryone worries about the sticky note with a password on it or the file just called passwords.xls, because those get caught fast and make a good story,\u201d he told us. \u201cNobody worries about the login they forgot even exists, and that is usually the one still wide open years later, causing real, unseen damage.\u201d<\/p>\n<p>The lesson here is pretty straightforward. You need to see all of the accounts that have access to your data and make sure that they all have a reason to exist. Conduct regular audits, even if nothing seems wrong.<\/p>\n<p>And, as we\u2019ve seen before, zombie accounts can kill. When an employee or contractor leaves, check not only which accounts they used, but also which accounts they created while doing the job.\u00a0\u00ae<\/p>\n","protected":false},"excerpt":{"rendered":"SECURITY Toothless security PWNED Welcome back to PWNED, the weekly column where we highlight examples of how not&hellip;\n","protected":false},"author":2,"featured_media":890429,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34],"tags":[49,48,84,392],"class_list":["post-890428","post","type-post","status-publish","format-standard","has-post-thumbnail","category-healthcare","tag-ca","tag-canada","tag-health","tag-healthcare"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/890428","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/comments?post=890428"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/890428\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media\/890429"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media?parent=890428"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/categories?post=890428"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/tags?post=890428"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}