Authorized security assessments at hospitals uncovered serious weaknesses that allowed a red teamer to access restricted patient information through both physical and network paths. By posing as a new staff member, wearing scrubs, using a fake badge, and building rapport with a nurse by complaining about a real doctor, the tester was allowed past an electronic lock and a human gatekeeper into a medical records room, where he retrieved a target patient file and demonstrated how easily trust could override access controls.
A separate assessment found guest Wi-Fi effectively shared exposure with critical medical systems on VLAN 1, leaving devices including MRI machines visible from less trusted networks and transmitting sensitive patient data without encryption. The findings indicate that some healthcare environments continue to prioritize operational speed, uptime, and data flow over stronger security hygiene, increasing the risk of unauthorized access to restricted areas and private medical records.

See the actors and campaigns active against you right now.
2 events from the most recent confirmed update back to the earliest known activity.
In another hospital assessment, Schloss found that guest Wi-Fi and critical medical systems were effectively exposed together on VLAN 1. This allowed visibility into unencrypted sensitive data from devices including MRI machines, highlighting poor network segmentation.
During an authorized hospital security assessment, red teamer Dahvid Schloss bypassed an electronic lock and a human gatekeeper by posing as a new staff member, using a fake badge, wearing scrubs, and building rapport with a nurse. He was then allowed into the medical records room and retrieved a target physical patient file, demonstrating exposure of private records through social engineering.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.