Dental contractor set up secret account with access to 4,000 patient records then left the company
- ID
- 23088
- Status
- summarized
- Published
- 10 Sep 2026, 3:00 PM
- Fetched
- 10 Sep 2026, 3:54 PM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/security/2026/09/10/dental-contractor-set-up-secret-account-with-access-to-4000-patient-records-then-left-the-company/5295361
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 5.5
- Created
- 10 Sep 2026, 3:55 PM
- Tags
- Audience
- developerssaas_foundersdatabase_learners
What happened
A dental practice's contractor secretly created an admin account with access to 4,000 patient records, then left the company without telling anyone. The account stayed active for at least three years after the scheduling vendor relationship ended in 2021, creating a HIPAA compliance risk. The auditor, Chris Kirksey, has since found similar orphaned admin accounts at six other healthcare practices.
Why it matters
If you build or maintain systems where vendors or contractors get admin access, implement an automatic access shutdown triggered by contract termination and review the full account list at least twice a year. The failure mode here isn't weak passwords—it's accounts nobody remembers exist. For Malaysian SaaS founders handling customer data under PDPA, orphaned vendor accounts are the same blind spot.
Discussion angle
What's your vendor offboarding checklist—do you have an automated trigger that revokes access when a contract ends, or is it still a manual step someone has to remember?