Thursday, September 10, 2026

SECURITY

A Critical Oversight

Chris Kirksey, founder and CEO of Direction, a digital marketing and SEO firm specializing in the healthcare industry, conducts security audits for his clients.

During a recent assessment of a dental practice, Kirksey discovered a significant anomaly. Three accounts possessed administrative access to the patient database, one of which belonged to a scheduling service the practice had discontinued in 2021.

This forgotten account had remained active for over three years, exposing 4,000 patient records to potential compromise. Retaining unnecessary access to protected health information poses a severe HIPAA compliance risk, particularly if unauthorized individuals can still reach the data.

The office manager who relied on the system was entirely unaware of the dangerous login’s existence. A contractor had established the account without informing anyone and subsequently departed the company. Because the account was unknown, no one took action to deactivate it.

Kirksey immediately removed all three administrative accounts from the practice’s system and implemented new security protocols for his client.

“I established a permanent rule following this incident,” he stated. “Now, the conclusion of any vendor relationship triggers an automatic access shutdown, and the complete access list undergoes a bi-annual review regardless.”

“People often worry about physical sticky notes containing passwords or an easily discovered spreadsheet, as those are quickly identified,” he explained. “However, they fail to consider logins they have entirely forgotten, which are often the ones left wide open for years, causing substantial and unseen damage.”

The key takeaway is clear: organizations must maintain complete visibility over all accounts with data access and verify that each one serves a legitimate purpose. Regular audits are essential, even when no immediate issues appear.

Source link

Exit mobile version