A fake security badge and “dissing” a doctor got a red teamer inside hospital records
One unlocked door plus sloppy internal controls show how healthcare access can fail fast, even with “security” in place.

Red teamer Dahvid Schloss used social engineering, including a fake badge and targeted talk, to access a hospital records room and steal a specific physical file. The incident is a reminder that healthcare security often collapses at the human gatekeeper, not the locks.
Welcome back to PWNED, the weekly column where we spotlight security own-goals so you can dodge them. This story is less “dramatic hacker movie” and more “how did this get through?” Red teamer Dahvid Schloss says he gained access to a hospital records room by walking in dressed for the part, generating a specific conversation with the on-duty nurse, and then getting the door opened for him.
The key move: Schloss didn’t pick a lock or clone a badge. He reportedly used social engineering by “dissing” an actual doctor. He showed up in appropriate scrubs, carried a fake security badge that he made himself, and tried to swipe it. When it failed, he complained that Dr Johnson was being “an absolute asshole” and that the doctor had not pulled the patient records that were needed. Schloss had done research to pick the name of a real doctor on staff. Then the nurse, described as sympathetic to his “pain,” let him in. Schloss said the nurse told him, essentially, that she knew what he was going through, “I got you,” and opened the door.
This is exactly the failure mode healthcare organizations do not want to bet on. The records room had both an electronic lock and a nurse gatekeeper. In theory, that should be a layered defense: technology restricts entry, then personnel control the exceptions. In practice, social engineering attacks the layer that is easiest to manipulate quickly under normal operations. The nurse on duty is not a firewall. She is a person working a shift with time pressure, emotional labor, and institutional context. If the attacker can convincingly frame the request and establish that they belong to the workflow, the “gate” becomes a conversation, not a control.
Schloss also described what happened after he got inside. He retrieved the specific physical file his client had left for him to pilfer. Then he stayed and talked to the nurse for another 10 minutes, complaining about security incompetence and, again, how some doctors were “jerks.” The nurse, according to Schloss, invited him to hang out and go for lunch before he left with the folder. That detail matters because it exposes the second-order risk: once someone has been validated socially, the same relationships can smooth the next access attempt. Even a short window of trust can turn a one-time breach into repeated exposure.
If you are an executive, this is where it gets uncomfortable. Healthcare security often gets treated as an IT problem with a checklist solution. But the story shows that the real control may be a human who believes a plausible narrative. And narratives work best when they are anchored in real internal facts. Schloss claimed he researched the hospital and selected the name of an actual doctor. That kind of precision suggests attackers can spend time learning the context of operations, not just the mechanics of locks.
And that is only the physical side. In other tests, Schloss said he found network security practices that were “bad” and dangerously permissive. One hospital, he said, exposed important devices to the guest Wi-Fi network. Specifically, he reported that the hospital had critical devices on VLAN 1, the same network used by guest Wi-Fi. He also said medical device data was accessible and unencrypted, and that many medical devices at most hospitals he tested do not encrypt data they send over the network. The consequence is not abstract. Schloss said that, via network traffic from devices like an MRI machine, you could see Social Security numbers, patient data, date of birth, and other PII.
Put those two findings together and you get a grim but useful picture: access can fail at multiple layers, and each layer can be exploited quickly enough to create real harm. Schloss argued that hospitals often prioritize keeping machines running and distributing data quickly over strong security hygiene. He also said delays caused by security or IT troubleshooting could “cost a life.” That sounds like a trade-off argument, but the conclusion in the piece is blunt: regardless of life-and-death pressure, do not let someone into a restricted area just because they look and act the part.
For decision-makers, the stakes extend beyond one records room. Healthcare data and patient safety are intertwined with operational urgency. If you ignore social engineering, you risk physical document exposure, credential-less entry, and trust-based bypasses. If you ignore network segmentation and encryption, you risk making sensitive device traffic readable to anyone who can gain a foothold in the wrong network segment. The board-level question becomes straightforward: are you measuring security outcomes in terms of “what can happen” rather than “what tools we bought,” and are you stress-testing the human gates and the network boundaries the same way you test patches and perimeter defenses?
In other words, the story is not about a clever trick. It is about a system that assumes the attacker will fail because a badge or a lock exists. Schloss’s account suggests the attacker only needed the smallest advantage: credibility, timing, and a nurse willing to help a “brand new” worker who just started yesterday and knows which doctor to blame.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Science
Study: Europe drought is more severe due to human-caused extreme heat, not rainfall
A new international analysis says heat, not low precipitation, is driving Europe's exceptionally dry conditions and tightening risk for water, energy, and insurers.
Phantom Twist drone vanishes into a haze by spinning 25 times per second
A Northwestern-led prototype uses motion blur and counter-rotation to make drones harder to see, not just harder to spot.

Orcas on video smashing fish: researchers see feeding strategy or possible play
New footage shows orcas “smashing fish to smithereens,” raising a rare question: toollike hunting, or pure play behavior?

