A patient portal bug exposed records across dental practices

Practice by Numbers, a developer of dental office management software used in more than 5,000 practices in the United States, has fixed a security flaw that exposed patient records through its portal, according to TechCrunch. The issue was identified by a patient using the portal to review his own dental files.

According to the report, the bug allowed a logged-in patient to access documents belonging to other patients. The exposed files reportedly included personal information, medical histories, photo identification, and other documents. Because the flaw affected how documents were retrieved, the patient who found it said his own files were likely exposed to others as well.

An easy-to-exploit issue with sensitive consequences

The reported weakness was notable not only because it involved health information, but because it was simple to exploit. TechCrunch said the patient discovered that changing a document number in the web address could reveal other files. Those document numbers also appeared to be sequential, which raised the possibility that other records could be guessed without much difficulty.

That combination matters. A flaw that requires deep technical skill is dangerous enough, but one that can be reproduced by an ordinary portal user creates a much broader exposure surface. In this case, access to the system did not appear to require specialized tools or insider privileges beyond a valid patient login.