Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Health

Dental contractor created hidden admin account accessing 4,000 patient files before quitting

A contractor who set up a secret admin login for a dental practice could view 4,000 patient records and left the firm without the account being discovered.

While reviewing the IT systems of a dental practice, security consultant Chris Kirksey discovered three administrative accounts on the patient database, including one tied to a scheduling contractor that had stopped working with the practice in 2021. The concealed account remained active for a minimum of three years, exposing the personal health information of roughly 4,000 patients. The contractor who established the login never informed the practice and left the organization, so the office manager never knew the account existed.

Recognizing the HIPAA compliance danger, Kirksey promptly disabled all three admin accounts and introduced a rule that any terminated vendor relationship triggers immediate access termination, with a full access list audited twice yearly. Since that incident, he has identified comparable security gaps at six additional healthcare providers, underscoring how forgotten "zombie" accounts can persist unnoticed for years.

Why it matters

Undisclosed admin accounts can expose thousands of health records, risking privacy breaches and regulatory violations.

In this story

admin accountpatient recordsHIPAA risksecurity auditzombie accountvendor accesshealthcare data breach
Get the beta ↗