HIGHRegulatoryTier 1
Zombie Accounts May Be Putting Your Practice at Risk
SourceDecisions in DentistryTier 1Clinical & Visual
By Kristen Pratt Machado
Originally at decisionsindentistry.com
Summary & scoring by The Bell Brief (Dr. Jennifer Bell) using the Drill-Down Protocol (Drill-Down Score) — not the original publisher.
Why it matters for dental
Dental practices that fail to audit user accounts on practice-management and imaging systems risk HIPAA breaches, fines, and loss of patient trust—especially solo owners and DSOs whose staff turnover creates dormant “zombie” logins.
Key points
- Zombie accounts are logins left active after staff depart, giving former employees, contractors, or hackers continued access to full patient charts, radiographs, and billing records.
- Decisions in Dentistry warns that these accounts are a top vector for ransomware and identity-theft attacks that can halt a practice for days or weeks.
- Owners and DSO compliance officers should run quarterly access audits and immediately deactivate accounts upon termination to reduce breach surface area.
- Under the HIPAA Security Rule, covered dental entities must implement “access controls” and maintain an audit trail; failure to do so can result in civil monetary penalties up to $1.5 million per year per violation category.
Who should care
OwnerDSOStaff
Read the original on Decisions in Dentistry
Full reporting and any paywall content live on decisionsindentistry.com. We summarize and score; we do not republish.