CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Dental contractor set up secret account with access to 4,000 patient records then left the company

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6943

As cited

Copy frozen at (site build).

regulatory

Dental contractor set up secret account with access to 4,000 patient records then left the company

A dental practice failed to deactivate an admin account created by a contractor who left the company in 2021, leaving access to 4,000 patient records active for at least three years. A security auditor discovered the dormant account during a system review and found similar orphaned accounts at six other healthcare practices. The incident highlights the risk of forgotten vendor and contractor accounts that remain accessible to sensitive data long after their business purpose ends.

Why it matters: Dental practices and healthcare providers using patient management systems face HIPAA violations and data breach exposure when contractor-created accounts are not tracked and removed upon contract termination. Practitioners must inventory all accounts with database access and establish automated offboarding processes to prevent unauthorized access to protected health information.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary