A dental practice spent years with three administrator accounts quietly sitting on its patient database, including one tied to a scheduling vendor it had stopped using in 2021.
Security auditor Chris Kirksey found the accounts while reviewing the practice’s systems. The dormant login had been active for at least three years and could reach roughly 4,000 patient records. The office manager who ran the system did not know the account existed. A contractor had created it, never documented it, and then left the company. Because nobody knew it was there, nobody shut it down.
Kirksey removed all three admin accounts and rewrote the practice’s policies. Vendor relationships that end now trigger an automatic access shutdown, and the full account list is reviewed twice a year. He has since found similar orphaned logins at six other healthcare practices.
Zombie accounts are an easy blind spot for small clinics and dental offices, where IT is thin and systems are often set up by outside contractors. They also carry real regulatory weight: the HHS Office for Civil Rights has repeatedly cited missing or unmanaged access controls when settling HIPAA cases.
The fix is procedural, not technical. When a vendor or contractor leaves, check not only the accounts they used, but the accounts they created. Inventory access regularly, even when nothing appears wrong, and treat every orphaned login as a potential exposure of patient data.