Dental contractor set up secret account with access to 4,000 patient records then left the company
PWNED Welcome back to PWNED, the weekly column where we highlight examples of how not to handle your security.
This week’s tale of woe comes from a very unhealthy part of the healthcare sector.
Have a story about someone leaving a gaping hole in their network? Share it with us at [email protected].
Anonymity is available upon request.
Our story comes courtesy of Chris Kirksey, founder and CEO of Direction, a digital marketing and SEO company that works in the healthcare industry.
He also does security audits of his clients’ systems.
Last year, Kirksey was checking out a dental practice’s systems and noticed something strange.
There were three accounts that had admin access to the patient database, including one that belonged to a scheduling company the dentists had stopped using all the way back in 2021.
The account had been active for at least three years and could access 4,000 patient records.
Leaving an unnecessary account with access to protected health information created a potential HIPAA compliance risk, particularly if someone no longer authorized to view the data could still get to it.
The office manager responsible for using the system didn’t even know that this dangerous login existed.
Apparently, a contractor who set up the account never told anybody, then left the company.
Because no one knew that the account existed, no one knew to kill it.
Kirksey immediately set about getting rid of all three admin accounts he found on the dental practice’s system.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.