Talking smack about a doctor got him access to private medical files

← Back to the feed

Talking smack about a doctor got him access to private medical files

The Register · 3 hours ago

A security researcher named Dahvid Schloss, hired to test a hospital's defences, gained access to a locked medical records room using nothing more than a fake badge and a bit of social engineering, rather than any technical exploit. The case, reported in The Register's weekly PWNED column, illustrates how human trust and workplace gossip can undermine even electronically secured facilities, and highlights broader weaknesses in healthcare security.

Schloss researched the hospital in advance, dressed in scrubs, made a non-functioning fake badge, and identified a real but unpopular doctor on staff. When his badge failed to swipe in, he complained to the on-duty nurse that "Dr Johnson" had failed to pull patient files needed for a trauma case, and she sympathised and let him straight into the records room, allowing him to retrieve the target file. He lingered afterwards to chat and reinforce his cover story before leaving. Schloss also found separate network security failures at hospitals, including one where guest Wi-Fi shared the same VLAN as critical medical devices such as MRI machines, exposing unencrypted patient data to anyone on the network.

  • Red teamer used a fake badge and fake gripe to enter a hospital records room
  • Nurse let him in after he badmouthed an actual unpopular doctor
  • Separate hospitals found sharing guest Wi-Fi with unencrypted medical device data

Software

Read the full article at the source →