How Complaining About a Doctor Got a Red Teamer Into a Restricted Hospital Records Room
Healthcare security is a mess. Not just the software kind, either. This week's instalment of PWNED looks at the very human failure mode that keeps red teamers employed: gatekeepers who can be charmed, guilted, or simply chatted into handing over access they absolutely should not.
Red teamer Dahvid Schloss has built a career finding these gaps, and he's shared enough war stories with us that we've featured him before. His speciality isn't just poking at firewalls. He tests physical security too, and he's very good at it.
One assignment took him to a hospital where the objective was simple on paper: get into the records room and walk out with a specific physical file the client had planted there. Simple, except the room had an electronic lock and a nurse stationed outside it.
Schloss considered the technical options. Pick the lock. Clone an access badge. Lift someone's badge outright. He went with none of them. Instead, he put on scrubs, printed a fake security badge that wasn't actually wired to open anything, and went in with a cover story.
The cover story was complaining about a doctor.
"Nurses talk a lot of shit. It's the law of the land when it comes to the hospital," Schloss explained.
He walked up to the records room, swiped his useless badge, performed visible frustration when nothing happened, then leaned into the window where the duty nurse was standing. He'd done his homework and picked a real consultant on staff by name. What he couldn't have scripted was that the doctor in question was, apparently, genuinely difficult.
"I'm gonna save you the details. But Dr Johnson's being an absolute asshole right now," he told her. "He didn't pull out his patient records that he was supposed to pull out for trauma. They sent me down here. I'm brand new, just started yesterday."
The nurse didn't hesitate. She sympathised, told him she knew exactly what he was going through, and opened the door.
After grabbing the file, Schloss didn't bolt. He stayed for another ten minutes, swapping grievances with the nurse about incompetent IT departments and difficult consultants. She invited him for lunch before he left. With the folder.
Network security at other hospitals he's tested wasn't much better, just less entertaining. At one facility, he sat in the waiting room, connected to the guest Wi-Fi, and ran a scan. Everything important in the building, MRI machines, patient record systems, clinical devices, sat on VLAN 1. The same network as the public Wi-Fi. Unencrypted.
Patient names, dates of birth, Social Security numbers, the full package of data any organisation would panic about losing was just flowing across the network in plaintext. Schloss said this wasn't unusual. Most medical devices at most hospitals he's tested don't encrypt traffic at all.
His theory for why is grimly pragmatic. Hospitals prioritise uptime. If a nurse can't access a patient record because of a security friction point and has to call IT, that delay could, in the worst case, cost someone their life. So security gets quietly deprioritised in favour of speed.
That logic has some merit, but it doesn't justify waving strangers into restricted areas because they look annoyed and know the right name to drop. The lesson here isn't complicated: looking the part is not the same as being the part, and a sympathetic ear is one of the oldest attack vectors going.