AI Weekly Malaysia

Back to items Summaries

Dental contractor set up secret account with access to 4,000 patient records then left the company

ID
23088
Status
summarized
Published
10 Sep 2026, 3:00 PM
Fetched
10 Sep 2026, 3:54 PM
Provider
The Register
Category
technology
Original URL
https://www.theregister.com/security/2026/09/10/dental-contractor-set-up-secret-account-with-access-to-4000-patient-records-then-left-the-company/5295361
Source URL
https://www.theregister.com/headlines.atom

Summary

Score
5.5
Created
10 Sep 2026, 3:55 PM
Tags
Audience
developerssaas_foundersdatabase_learners

What happened

A dental practice's contractor secretly created an admin account with access to 4,000 patient records, then left the company without telling anyone. The account stayed active for at least three years after the scheduling vendor relationship ended in 2021, creating a HIPAA compliance risk. The auditor, Chris Kirksey, has since found similar orphaned admin accounts at six other healthcare practices.

Why it matters

If you build or maintain systems where vendors or contractors get admin access, implement an automatic access shutdown triggered by contract termination and review the full account list at least twice a year. The failure mode here isn't weak passwords—it's accounts nobody remembers exist. For Malaysian SaaS founders handling customer data under PDPA, orphaned vendor accounts are the same blind spot.

Discussion angle

What's your vendor offboarding checklist—do you have an automated trigger that revokes access when a contract ends, or is it still a manual step someone has to remember?

Top