“Nobody worries about the login they forgot even exists, and that is usually the one still wide open years later, causing real, unseen damage,” said Chris Kirksey after a routine review turned up a hidden administrative account with access to health records.
The discovery: three admin accounts and an unused vendor login
Last year Chris Kirksey, founder and CEO of Direction, a digital marketing and SEO firm that also performs security audits for healthcare clients, was examining systems at a dental practice when he found three accounts with administrative access to the practice’s patient database. One of those accounts belonged to a scheduling company the dentists had stopped using all the way back in 2021. The account had remained active for at least three years.
Scope of exposure: access to 4,000 patient records and a potential HIPAA risk
That dormant vendor account could access roughly 4,000 patient records. As Kirksey noted, leaving an unnecessary account with access to protected health information creates a potential HIPAA compliance risk if an individual who is no longer authorized to view the data still retains access. The office manager responsible for the system did not know the account existed; a contractor who had set it up apparently never told anyone and later left the company.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleKirksey’s remediation: deleting admin accounts and a permanent offboarding rule
On finding the accounts, Kirksey immediately removed all three administrative logins from the dental practice’s system. He then implemented a firm policy change for the client: every vendor relationship that ends now triggers an automatic access shutdown, and the full list of accounts gets reviewed twice a year no matter what. “I built a permanent rule after that,” he said.
Patterns beyond one practice: six more similar holes
Since that incident, Kirksey has encountered similar security gaps at six other healthcare practices he has worked with. He contrasted this kind of hidden access with more visible hygiene failures: “Everyone worries about the sticky note with a password on it or the file just called passwords.xls, because those get caught fast and make a good story,” he said. The recurring problem, he added, is the forgotten login — the account that remains active and unnoticed for years.
What this means for technologists and security teams, practice managers and procurement leaders, and patients
- Technologists and security teams: Verify the complete inventory of accounts that have administrative or data access rights and bake vendor offboarding into identity and access management workflows. In this case, the immediate technical fix was removal of three admin accounts; the policy fix was an automated shutdown tied to vendor termination and biannual reviews.
- Practice managers and procurement leaders: Track which vendors were engaged, who created accounts on their behalf, and which of those accounts still exist after relationships end. The office manager in this incident was unaware of the dormant scheduling-company account; a procurement or contract-close checklist that includes access revocation might have prevented that oversight.
- Patients and the public: Records tied to roughly 4,000 patients were accessible through a forgotten administrative login. Even if no misuse is reported, retained access by an external vendor represents an exposure and a compliance concern that patients and advocates will want clarified when incidents are detected.
The immediate harm in this episode was mitigated by a prompt audit and the deletion of unnecessary accounts, but the broader lesson is clear from Kirksey’s experience: sometimes the weakest link is not an obvious credential on a sticky note but a forgotten account that quietly persists. His response — automate shutdowns when vendor relationships end and review the access list at least twice a year — is a concrete step that turned discovery into durable change.
Read the original report on The Register: Dental contractor set up secret account with access to 4,000 patient records then left the company




