Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Dental Contractor's Secret Account Exposes Patient Records, Highlighting the Need for Vigilant Access Management




A dental contractor's secret account exposed 4,000 patient records, highlighting the need for vigilant access management. The incident, which occurred after a contractor left the company without informing anyone about the account's existence, serves as a stark reminder of the importance of regular audits and promptly revoking access to accounts once an employee or contractor leaves the company.

  • Dental contractor set up secret account with access to 4,000 patient records.
  • Audit revealed three accounts with admin access to patient database, including an inactive account from 2021.
  • Contractor failed to inform anyone about the account's existence, causing a potential HIPAA compliance risk.
  • Office manager was unaware of the account's existence and did not know to shut it down.
  • Incident highlights the need for regular audits and prompt revocation of access to accounts once an employee or contractor leaves.



  • The dental healthcare industry, like many others, has faced a significant challenge in recent years. The recent case of a dental contractor setting up a secret account with access to 4,000 patient records, which remained active for at least three years and was never revoked, serves as a stark reminder of the importance of vigilant access management.

    The incident came to light after a digital marketing and SEO company, Direction, conducted a security audit of a dental practice's systems. The audit revealed three accounts that had admin access to the patient database, including one that belonged to a scheduling company that had been stopped using all the way back in 2021. The account in question had been active for at least three years and could access sensitive patient information, including protected health information.

    The contractor who set up the account, who had left the company, had failed to inform anyone about its existence, resulting in a potential HIPAA compliance risk. The office manager responsible for using the system was unaware of the account's existence, and therefore, did not know to shut it down.

    The incident highlights the need for companies to conduct regular audits to ensure that all accounts with access to sensitive data have a legitimate reason to exist. It also emphasizes the importance of promptly revoking access to accounts once an employee or contractor leaves the company.

    The incident has been described by Chris Kirksey, the founder and CEO of Direction, as "a lesson in how not to handle your security." Kirksey stated, "Nobody worries about the login they forgot even exists, and that is usually the one still wide open years later, causing real, unseen damage." He went on to say that conducting regular audits, even if nothing seems wrong, is essential to preventing such incidents.

    The incident has also led to changes in the way that companies approach vendor relationships. Kirksey stated that every vendor relationship that ends now triggers an automatic access shutdown and the full list gets reviewed twice a year, regardless of what. This change is designed to prevent similar incidents from occurring in the future.

    The incident serves as a wake-up call for companies in the healthcare industry, emphasizing the need for vigilance and attention to detail when it comes to access management. It highlights the importance of regular audits and the need to promptly revoke access to accounts once an employee or contractor leaves the company.

    In conclusion, the recent incident involving the dental contractor's secret account exposes patient records is a stark reminder of the importance of vigilant access management. It highlights the need for companies to conduct regular audits and to promptly revoke access to accounts once an employee or contractor leaves the company.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Dental-Contractors-Secret-Account-Exposes-Patient-Records-Highlighting-the-Need-for-Vigilant-Access-Management-ehn.shtml

  • https://www.theregister.com/security/2026/09/10/dental-contractor-set-up-secret-account-with-access-to-4000-patient-records-then-left-the-company/5295361


  • Published: Thu Sep 10 02:24:04 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us