Dental practice software maker fixes bug that exposed patients’ medical records

A dental practice management software serving over 5,000 practices contained a critical vulnerability allowing unauthorized access to patient medical records through sequential URL manipulation—a flaw that went unpatched for an unknown duration due to the vendor's lack of security reporting mechanisms. This incident underscores a growing risk in healthcare IT ecosystems where third-party SaaS vendors managing sensitive PHI may lack basic security controls, pre-launch security audits, and responsible disclosure programs. IT leaders must reassess vendor security postures and implement stricter oversight of patient data access controls, particularly for mission-critical healthcare applications.

Zack WhittakerTechCrunch2 min read
Read full article
Dental practice software maker fixes bug that exposed patients’ medical records
The security bug is now fixed, but the patient who found it said it was challenging to alert the software company about the issue.