Red teamer says hospital records room fell to social engineering
Dahvid Schloss said an authorized hospital security test exposed weak physical controls and poorly segmented medical networks.
By Renata Fuchs · Policy Reporter
· 3 min read
Red teamer Dahvid Schloss said he gained entry to a hospital records room during an authorized security test by wearing scrubs, carrying a fake badge and persuading a nurse that he needed a file for an irritated doctor. The hospital was not named, and Schloss did not disclose when the test occurred, but the account points to a familiar healthcare security problem: access controls often fail at the human layer.
Schloss said he had been hired to test whether he could reach a protected records room and remove a particular physical file that the client had placed there for the exercise. The target area had two barriers: an electronic lock and a nurse stationed as a gatekeeper.
Rather than pick the lock, clone an access card or steal a badge, Schloss said he prepared a social-engineering approach. He researched the hospital, dressed in scrubs and made a badge that looked plausible but had no ability to open the door. He also selected the name of a real doctor on staff to make the story more credible.
According to Schloss, he deliberately failed to swipe the badge, then told the nurse he was new, had been sent to retrieve records and was dealing with a difficult doctor. He said the doctor he named happened to have a reputation that made the story believable, a detail he did not know beforehand. The nurse opened the door and allowed him into the room, he said.
Schloss said he retrieved the file, then stayed in the area for about 10 minutes while continuing the conversation. He said he complained about the badge issue and hospital security, while the nurse discussed frustrations with doctors. He left with the folder after the interaction. No patient harm was alleged, and the file had been placed for the test, according to Schloss.
The episode is a useful reminder for operators because the technical control, the electronic lock, existed but was bypassed through workflow pressure and assumed identity. Hospitals are especially exposed to this failure mode because urgent requests, rotating staff and deference to clinical needs can make verification feel like friction.
Schloss also described network weaknesses he said he found in other hospital tests. In one case, he said he joined a guest Wi-Fi network from a waiting room and found critical hospital devices on VLAN 1, the same network segment as guests. He said data from medical devices, including an MRI machine, was visible and unencrypted.
Schloss further claimed that many medical devices in hospitals he has tested send data across networks without encryption. He said that data can include Social Security numbers, dates of birth and other personally identifiable information. He attributed the pattern to hospitals prioritizing availability and speed for clinical systems over tighter security controls.
The account does not identify the hospitals, device makers, remediation steps or whether the findings were independently verified. Even so, the details fit two persistent security gaps in healthcare: physical access policies that depend on trust, and flat or poorly segmented networks where guest access and clinical equipment are not adequately separated.
This story draws on original reporting from The Register.