Trending
NWU professor helps shape Africa’s first hypertension guidelines is trending now Smoking reduces chances of successful fertility treatment, says WHO is trending now Congo-Kinshasa: Ebola Fatigue? the Anglican Church in DR Congo Launches New Phase of Resp… is trending now Strange 'fast radio bursts' across the universe could help solve major cosmic mysteries: … is trending now Blue Origin to become first telco on Mars with $700m NASA contract is trending now New MRI agent to earlier detect lung cancer, hidden metastases is trending now Chalmers Researchers Make Bosonic Quantum Operations More Than 1,000 Times Faster is trending now PSG dent Yaya Toure’s historic UCL night as Liverpool defeat Atletico is trending now Xabi Alonso blames himself! Chelsea boss admits he made it 'too difficult' for Blues star… is trending now US Open quarterfinal scores, highlights: Zverev, Khachanov advance, Gauff rallies is trending now Tottenham should be awarded 2016-17 Premier League title after Chelsea breaches, says Mau… is trending now Davido’s ‘Oriadé’ Surpasses 100 Million Streams On Spotify is trending now NWU professor helps shape Africa’s first hypertension guidelines is trending now Smoking reduces chances of successful fertility treatment, says WHO is trending now Congo-Kinshasa: Ebola Fatigue? the Anglican Church in DR Congo Launches New Phase of Resp… is trending now Strange 'fast radio bursts' across the universe could help solve major cosmic mysteries: … is trending now Blue Origin to become first telco on Mars with $700m NASA contract is trending now New MRI agent to earlier detect lung cancer, hidden metastases is trending now Chalmers Researchers Make Bosonic Quantum Operations More Than 1,000 Times Faster is trending now PSG dent Yaya Toure’s historic UCL night as Liverpool defeat Atletico is trending now Xabi Alonso blames himself! Chelsea boss admits he made it 'too difficult' for Blues star… is trending now US Open quarterfinal scores, highlights: Zverev, Khachanov advance, Gauff rallies is trending now Tottenham should be awarded 2016-17 Premier League title after Chelsea breaches, says Mau… is trending now Davido’s ‘Oriadé’ Surpasses 100 Million Streams On Spotify is trending now
Technology

Dental contractor set up secret account with access to 4,000 patient records then left the company

Toothless security

PWNED Welcome back to PWNED, the weekly column where we highlight examples of how not to handle your security. This week’s tale of woe comes from a very unhealthy part of the healthcare sector. Have a story about someone leaving a gaping hole in their network? Share it with us at [email protected]. Anonymity is available upon request. Our story comes courtesy of Chris Kirksey, founder and CEO of Direction, a digital marketing and SEO company that works in the healthcare industry. He also does security audits of his clients’ systems. Last year, Kirksey was checking out a dental practice’s systems and noticed something strange. There were three accounts that had admin access to the patient database, including one that belonged to a scheduling company the dentists had stopped using all the way back in 2021. The account had been active for at least three years and could access 4,000 patient records. Leaving an unnecessary account with access to protected health information created a potential HIPAA compliance risk, particularly if someone no longer authorized to view the data could still get to it. The office manager responsible for using the system didn’t even know that this dangerous login existed. Apparently, a contractor who set up the account never told anybody, then left the company. Because no one knew that the account existed, no one knew to kill it. Kirksey immediately set about getting rid of all three admin accounts he found on the dental practice’s system. He then set up new policies for his client. “I built a permanent rule after that,” he said. “Every vendor relationship that ends now triggers an automatic access shutdown and the full list gets reviewed twice a year no matter what.” Since the incident, Kirksey has found similar security holes at six other healthcare practices he has worked with. Yikes! “Everyone worries about the sticky note with a password on it or the file just called passwords.xls, because those get caught fast and make a good story,” he told us. “Nobody worries about the login they forgot even exists, and that is usually the one still wide open years later, causing real, unseen damage.” The lesson here is pretty straightforward. You need to see all of the accounts that have access to your data and make sure that they all have a reason to exist. Conduct regular audits, even if nothing seems wrong. And, as we’ve seen before, zombie accounts can kill. When an employee or contractor leaves, check not only which accounts they used, but also which accounts they created while doing the job. ®
View original source →

Related

More from The Register