Red Teamer Exploits Nurse's Gossip to Access Hospital Records
A red teamer successfully gained physical access to a hospital's medical records room by impersonating a new employee and leveraging a nurse's willingness to gossip about a doctor.

In a striking demonstration of social engineering's enduring power, a red teamer known as Dahvid Schloss successfully infiltrated a hospital's secure medical records room by exploiting human trust and a bit of office gossip. The objective was to retrieve a specific physical file, a task complicated by both an electronic lock and a vigilant nurse guarding the entrance.
Schloss, a seasoned security tester with a history of testing both digital and physical security, opted for a social engineering approach over more conventional methods like lock picking or badge cloning. After researching the hospital and donning appropriate scrubs, he created a non-functional security badge. His strategy hinged on appearing as a legitimate, albeit new, employee facing a minor technical hurdle.
Approaching the nurse on duty, Schloss feigned frustration with his badge and then launched into a fabricated story. He claimed to be a new hire, sent to retrieve critical patient records for a "trauma" case, and complained about a specific doctor, Dr. Johnson, whom he described as an "asshole" for not having the records ready. This tactic played directly into the common workplace dynamic where colleagues might bond over shared frustrations with management or difficult personalities.
The nurse, receptive to Schloss's fabricated woes and perhaps eager to commiserate, readily agreed with his assessment of the doctor. She expressed empathy, stating, "honey, I know exactly the pain that you're going through," and promptly opened the door, granting him access to the records room.
Inside, Schloss retrieved the target file and spent an additional ten minutes with the nurse, further solidifying his cover story by complaining about the "incompetent" security and sharing fabricated past work experiences. The nurse, fully convinced, even invited him to hang out and go for lunch sometime before he departed with the file, highlighting the depth of the deception.
This incident underscores a broader issue within the healthcare sector, where physical security can be undermined by social dynamics. Schloss also noted a separate, alarming finding at another hospital: critical patient data, including Social Security numbers, was accessible on the same network as the guest Wi-Fi. This indicates a severe lack of network segmentation and data encryption, leaving sensitive information vulnerable to interception.
Schloss theorizes that healthcare institutions often prioritize operational continuity and rapid data flow over stringent security practices. The potential for even minor delays in accessing patient data, he suggests, could have life-or-death consequences. However, he maintains that this prioritization should not come at the expense of basic security hygiene, especially concerning physical access to sensitive records.
The story serves as a potent reminder that even the most sophisticated technological defenses can be bypassed by exploiting human psychology. It highlights the critical need for comprehensive security training that addresses social engineering tactics and reinforces strict access control protocols, particularly in sensitive environments like hospitals.