Orphaned Accounts and Former Vendors as Breach Pathways

Every organization accumulates accounts. A temporary nurse who left two years ago, a consultant who finished a project, a vendor technician who installed equipment and never needed to return, a test account someone created and forgot. Each one is a door that nobody is watching. Attackers love doors like these, because no one notices when they are used.

Dormant accounts are attractive for a simple reason: they work, they have real permissions, and nobody is responsible for them. Finding and removing them is among the most cost-effective security tasks an organization can do. This post describes where orphaned access hides and how to clean it up.

Why Dormant Access Is Dangerous

No one notices activity. A former employee's account signing in at 3 a.m. does not trigger the same concern as a current staff member's.

Passwords go stale. Old passwords may have been reused, exposed in unrelated breaches or never changed from defaults.

Multi-factor protection may be missing. Older accounts often predate your authentication requirements.

Permissions linger. Access granted for a project often outlives the project.

Vendors are a bridge. A vendor account into your network can be compromised through the vendor's own weaknesses.

Where Orphaned Access Hides

User Accounts

Former employees, seasonal and agency staff, interns and volunteers. Check your directory, email system and every application with its own login, including the record system.

Vendor and Contractor Accounts

Remote support logins, vendor portals, VPN accounts and remote access tools installed by past service providers. Equipment suppliers and software vendors sometimes keep standing access for support.

Service and Shared Accounts

Accounts used by applications, scheduled tasks, copiers and scanners, or generic logins shared by a department. These rarely have an owner, and their passwords often never change.

Cloud and Application Access

Third-party apps connected to your email or file storage, unused administrator roles, forgotten test environments and old guest accounts invited to shared sites.

Remote Access Paths

Old VPN profiles, remote desktop configurations, forwarded ports on a firewall and remote management software that no one remembers installing.

How to Find Dormant Access

Pull a list of all accounts from your directory and major applications.

Compare it with current HR records for employees, and with contracts for vendors. Anyone who does not appear needs an explanation.

Check last sign-in dates. Accounts unused for 60 to 90 days deserve review. Many platforms can report this.

Identify accounts with administrative privileges and confirm each is necessary and tied to a named person.

Review vendor access. For each vendor, ask what access they have, why, who approved it and whether it is still needed.

Look at firewall rules and remote access settings for services reachable from the internet.

Review third-party app connections in your email and file platforms.

Clean Up Safely

Deleting immediately can break something unexpected, especially service accounts. A cautious approach:

Disable the account first rather than deleting it.

Wait a defined period, perhaps 30 days, to see if anything fails.

Then delete, or archive according to your retention policy.

Document what was removed, when and why.

For service accounts, identify the system that uses them before changes, and rotate their passwords.

Prevent Accumulation

Cleanup without prevention means doing it again next year.

Build Offboarding Into HR

Make account removal part of every termination and contract completion, with a checklist shared between HR, IT and department managers.

Give Vendors Time-Limited Access

Where possible, enable vendor access only during scheduled work, require multi-factor authentication, and use named accounts. Include access terms in contracts, including notification when vendor staff leave.

Run Regular Access Reviews

Quarterly, have managers confirm that each person on their list still needs access. Automated reports on inactive accounts make this practical.

Use Automatic Expiration

Set expiration dates for temporary accounts and guest access, so that access ends without anyone remembering to remove it.

Monitor for Unusual Use

Alert on sign-ins to long-dormant accounts, logins from unusual locations and administrative changes. Dormant accounts that suddenly wake up deserve attention.

If You Find Evidence of Misuse

Treat it as an incident. Disable the account, preserve logs, determine what was accessed, and assess whether protected health information may have been exposed under HIPAA's breach notification requirements. Reset related credentials and look for other accounts that may be affected.

How UnityCare IT Helps

UnityCare IT helps healthcare organizations inventory accounts and vendor access, retire what is no longer needed and set up the reviews and alerts that keep orphaned access from returning.

Related service

Security monitoring, HIPAA safeguards, backups and staff training for healthcare and small businesses.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172