A cyber insurance broker referred a multi-location dental practice to LeakTrace during the applicant's renewal cycle. The underwriter requested independent verification of the practice's external cyber posture before binding the coverage. The forensic engagement completed in seventy-two hours, and the findings changed the outcome of the renewal.

Engagement origin

The broker had known the practice principal for over a decade. When the underwriter flagged the applicant's answers on the ransomware and multi-factor authentication questions as insufficient for the requested limit, the broker introduced LeakTrace as an independent verification path. The practice operates four clinical locations across Southern Ontario, employs approximately forty-seven clinical and administrative staff, and maintains active patient files in the range typical of a mid-size group practice governed by the Personal Health Information Protection Act.

Discovery scope

External attack surface only. LeakTrace did not request system access, did not conduct penetration testing, and did not touch the practice's internal network. The audit relied on public and monitored sources: breach database indexes, DNS and certificate transparency records, corporate registry filings, paste-site monitoring, and public-record aggregation on the practice's registered domains, principal dentist email patterns, and Business Number filings.

Findings summary

The engagement produced findings across four categories. The most material are summarized below.

  • Credential exposure. Eleven clinical and administrative email addresses were identified across breach databases actively monitored by threat actors. Six had passwords recovered in cleartext or crackable hash form. Three of those six matched the practice's Microsoft 365 login pattern, meaning an attacker with the breach index could have attempted authenticated access to the practice's primary business platform.
  • Practice management portal exposure. The practice management platform's login portal was publicly reachable without geographic access controls. Login rate limiting was not configured. Password complexity policy was below current industry baseline.
  • Vendor mapping via DNS. DNS records disclosed the practice's mail server hostname and its outsourced information-technology provider. A targeting attacker would have had a complete picture of the vendor relationships available to impersonate in a business email compromise campaign.
  • Principal cross-contamination. The principal dentist's personal email address appeared in a large 2023 consumer breach that continues to be indexed by criminal-marketplace platforms. The same address had been reused across the practice's payment processor, banking, and Google Workspace login patterns, extending the blast radius of any credential reuse.
  • Terminated access retained. Two former staff members retained access to the patient scheduling system at least eight months after termination, based on timestamps observable in the vendor's public system logs.

Client actions

The practice acted on every material finding within the seventy-two-hour window after report delivery. Passwords were rotated for all clinical staff identified in the breach index. Multi-factor authentication was enforced across Microsoft 365, the practice management system, and payroll. Geographic access controls were configured on the practice management admin portal, restricting login attempts to Canadian address ranges. The principal dentist's personal email address was rotated off all business-critical accounts and replaced with a dedicated business address. Access for the former staff members was terminated and the vendor's provisioning process was audited. The practice filed a proactive notification with the Information and Privacy Commissioner of Ontario documenting the audit and the remediation.

Outcome

The underwriter bound the policy at the pre-audit premium. The fifteen percent premium loading initially proposed on the ransomware and business email compromise sub-limits was withdrawn. The audit itself was accepted as evidence of due diligence. The practice management group later engaged LeakTrace for continuous monitoring across all four locations.

Methodology transparency

All source databases and enumeration techniques used in this engagement are documented in the LeakTrace methodology briefing available on request. No source used in this audit required access to non-public systems, purchased breach data, or coordination with any threat actor. Personal Health Information Protection Act obligations were reviewed with the practice's counsel prior to finalizing remediation.