TECH Signal 42
Dental contractor's secret admin account exposed 4,000 patient records for three years after departure
A dental contractor created a secret admin account with access to 4,000 patient records, then left the company without disclosing it, leaving the account active and unknown to the practice for at least three years.
Zombie accounts created by departing contractors are a persistent access risk that standard offboarding processes miss because they only revoke known accounts. This incident shows that auditing must cover not just who has access, but what accounts were created during a vendor or employee's tenure.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
A contractor's secret admin account with access to 4,000 patient records remained active for at least three years after the contractor left the dental practice.
The office manager responsible for the system did not know the account existed, so no one thought to revoke it during offboarding.
The security auditor who discovered the issue found similar zombie accounts at six other healthcare practices.
THE CLUSTER