Apps & Consumer
Practice by Numbers fixes bug exposing patient health records
Practice by Numbers has fixed a security flaw in its dental software that exposed private patient records, affecting fewer than 10 patients in the United States.
Practice by Numbers, a developer of dental office management software, has resolved a security vulnerability that exposed the private health records of patients. The security flaw was located on a patient portal bundled with the company’s software, which is used in over 5,000 dental practices across the United States.
The security bug was discovered by Joseph R. Cox, a patient who encountered the issue while viewing his own dental records on the portal. According to Cox, the bug allowed any user of the portal to access documents belonging to other patients. The vulnerability was easy to exploit: changing the document number in the web address while loading a file allowed users to access other patients’ files, including medical histories, photo identification, and personal information. Because the document numbers in the web address appeared to be sequentially incremental, guessing the identifiers of other people’s medical files was straightforward. Cox reported experiencing significant difficulty in alerting the company to the issue, as there was no clear channel for reporting security problems. The email address listed on the company’s website was broken, and messages sent to a founder on LinkedIn went unanswered.
Because the security flaw was actively putting patients’ data at risk, TechCrunch alerted Practice by Numbers to the issue on April 13. The company subsequently took its patient portal offline to address the bug, bringing it back online on April 17. According to Chris Lau, the co-founder and chief technology officer of Practice by Numbers, “The company had fixed the vulnerability, and it was notifying fewer than 10 patients that their information was exposed due to the bug, citing its server logs.” Lau added that the company is working with the affected dental practice to notify those patients. Additionally, co-founder and president Rohit Garg stated that the company plans to update its website to let people report security issues, though the company did not provide a timeline for this update. Such an update would function similarly to a vulnerability disclosure program, which is a formal channel allowing security researchers to report flaws to a company.
The incident highlights a broader challenge where consumers identify security flaws in commercial products but find no established mechanism to report them to developers. Similar reporting difficulties occurred recently with other major retailers. In December, a security researcher tried to privately alert Home Depot about a security lapse that exposed access to its internal systems, but the reports were ignored until TechCrunch contacted the company. Similarly, in April, fashion retailer Express fixed a website bug that allowed access to customer order details and personal information only after a user identified the flaw but struggled to find a way to alert the company.
Why it matters
The incident underscores a growing trend where consumers discover critical security flaws in commercial products but lack clear, accessible channels to report them to developers. Without formal reporting mechanisms, companies risk leaving sensitive user data exposed to exploitation for extended periods.