Dental contractor set up secret account with access to 4,000 patient records then left the company
A dental practice left an unknown vendor admin account with access to 4,000 patient records active for over three years, creating HIPAA risk.
Chris Kirksey, CEO of Direction, found three admin accounts on a dental practice's patient database, including one belonging to a scheduling company dropped in 2021 that retained access to 4,000 patient records for at least three years. A contractor had created the account without telling anyone and then left, so nobody knew to remove it, creating HIPAA compliance risk. Kirksey removed the accounts, adopted mandatory vendor access shutdown and twice-yearly reviews, and later found similar orphaned-account issues at six other healthcare practices.