As cited
Copy frozen at (site build).
regulatory
Dental contractor set up secret account with access to 4,000 patient records then left the company
A dental practice failed to deactivate an admin account created by a contractor who left the company in 2021, leaving access to 4,000 patient records active for at least three years. A security auditor discovered the dormant account during a system review and found similar orphaned accounts at six other healthcare practices. The incident highlights the risk of forgotten vendor and contractor accounts that remain accessible to sensitive data long after their business purpose ends.
Why it matters: Dental practices and healthcare providers using patient management systems face HIPAA violations and data breach exposure when contractor-created accounts are not tracked and removed upon contract termination. Practitioners must inventory all accounts with database access and establish automated offboarding processes to prevent unauthorized access to protected health information.
- Source published
- First seen by Cybersecurity Tracker