XOOMAR
Red teamer social-engineers hospital staff near a secure medical records room with digital lock overlays.
CybersecurityJuly 23, 2026· 9 min read· By XOOMAR Insights Team

Gossip Cracked Healthcare Social Engineering at a Hospital

Share
Updated on July 23, 2026

A fake badge failed, but a complaint about “Dr Johnson” opened a hospital records room.

XOOMAR Intelligence

Analyst Take

72/ 100
High
3 sources analyzedMedium confidenceTrend10Freshness100Source Trust85Factual Grounding92Signal Cluster20

That’s the uncomfortable lesson from a healthcare social engineering test described by red teamer Dahvid Schloss in The Register Security. The people most exposed are not only patients. It’s also nurses, clerks, compliance teams, and hospital security staff who are expected to defend sensitive spaces while keeping care moving.

The source headline frames the incident as access to private medical files. The body gives a more precise detail: Schloss was hired to enter a hospital records room and retrieve a specific physical file that his client had placed there for the test. That distinction matters. The test still exposed a serious control failure, but the available source does not establish that he removed real patient records.

Gossip Became the Badge: Healthcare Social Engineering Hit the Records Room

Schloss had options. He could try to pick the lock. He could clone a badge. He could steal a badge from someone with access. Instead, he chose the cheaper path: pretexting.

The records room had two controls: an electronic lock and a nurse acting as a human gatekeeper. Schloss researched the hospital, wore appropriate scrubs, and made a fake security badge that could not swipe him in. Then he performed frustration.

“Nurses talk a lot of shit. It's the law of the land when it comes to the hospital,” Schloss told The Register.

His pitch was built around workplace intimacy. Not politeness. Not a sterile request. He sounded annoyed in the way insiders sound annoyed.

“I'm doing fine, hon. How you doing,” he told the nurse. “Look, I'm gonna save you the details. But Dr Johnson's being an absolute asshole right now; he didn't pull out his patient records that he was supposed to pull out for trauma. We need these records, and they sent me down here. I'm brand new. I just started yesterday.”

He had picked the name of an actual doctor on staff. What he did not know, according to the source, was that the doctor was difficult to work with. The nurse recognized the pain point and opened the door.

If a fake badge fails and the person still gets in, what exactly did the badge protect?


Frontline Staff: Doctor Gossip Worked Because It Sounded Like Internal Life

The mechanics were simple, which is the problem.

Schloss used four signals that often pass as legitimacy in a busy facility:

  • Name-dropping: He referenced an actual doctor.
  • Shared frustration: He criticized a staff member in a way that sounded familiar.
  • Fake urgency: He tied the request to trauma records.
  • New-person cover: He explained away his broken badge by saying he had just started.

The nurse’s response shows why this kind of healthcare social engineering can beat technical controls.

“The nurse goes ‘honey, I know exactly the pain that you're going through,’” Schloss continued. “She goes ‘I got you’ and she opens the door, lets me in.”

After retrieving the file, Schloss did not rush out. He stayed for another 10 minutes, complained about security not activating his badge, and let the nurse complain about difficult doctors. He also had a backstory about where he had worked before. Before he left with the folder, she invited him to hang out and go to lunch sometime.

That extra time matters. It turned a bypass into a relationship. The longer he stayed without being challenged, the more normal he became.

Could a nurse under pressure realistically stop every confident person in scrubs without clear backing from management?

Security Teams: The Small Data Points Are More Useful Than Big Breach Statistics

The supplied source does not provide industry-wide breach counts, average breach costs, or HIPAA penalty figures. So this analysis won’t pretend it does.

The useful numbers here are operational:

Control or condition Source-supported detail Security meaning
Physical access control Records room had an electronic lock Technical control existed
Human gatekeeper Nurse guarded the records room Manual override became the attack path
Badge status Fake badge could not swipe in Failed authentication did not stop access
Post-entry dwell time Schloss stayed around for 10 minutes The pretext survived beyond the door
Network exposure elsewhere Important devices were on VLAN 1 with guest Wi-Fi Segmentation failed in another hospital test

That last point came from a separate hospital engagement Schloss described. He sat in a waiting room, joined the guest Wi-Fi, scanned the network, and found important devices on VLAN 1, the same network as guest Wi-Fi. Data from medical devices including an MRI machine was accessible and unencrypted, according to his account.

“So you're getting Social Security numbers just being populated over the network via the MRI machine and you're getting the patient data, the date of birth, all the PII that any organization would lose their shit about,” he said.

The physical and network stories rhyme. In both, the control existed in form but failed in practice. The badge did not stop the human bypass. The guest network did not isolate clinical devices.

How many security programs audit the moment after a control fails, not just whether the control exists?

Patients: Medical Privacy Depends on Gatekeepers They Never See

Patients rarely see the systems that protect their records. They see the front desk, the nurse station, the printer, the door, the badge reader. Trust sits behind all of that.

The source does not say what was inside the test file. It does say Schloss was asked to retrieve a specific physical file from a records room. That is enough to show why paper still matters in a world of electronic records. A locked room can become a soft target if access depends on whether an impostor sounds plausible.

The second hospital example raises a different patient risk. Schloss said Social Security numbers, dates of birth, patient data, and other PII were visible in traffic from medical devices. He also said most medical devices at most hospitals he has tested do not encrypt data they send over the network.

That claim is based on his testing experience, not a public census. Still, it points to a pattern security teams should test directly: can someone on guest access see clinical data traffic?

Patients can’t personally inspect VLANs or badge logs. They can ask narrower questions:

  • Records access: Who can enter physical records areas?
  • Auditability: Are access attempts and manual overrides logged?
  • Breach response: How are patients notified if unauthorized access is suspected?
  • Insurance review: Are unfamiliar claims or statements investigated quickly?

If privacy depends on invisible controls, what signal tells a patient those controls are actually working?


Compliance Teams: Policies Fail When No One Can Challenge the Pretext

A policy saying “don’t admit unauthorized people” is weak if staff feel punished for slowing work down.

Schloss said hospitals he has tested appear to prioritize keeping machines running and moving data quickly over security hygiene. He offered the reason plainly: if someone tries to get data, fails, and needs IT help, those minutes could matter in care delivery.

That tension is real. The mistake is treating it as permission to skip verification.

A better control culture gives staff a script and authority. Not a vague reminder. A script.

  • Challenge: “I need to verify your access before I open this door.”
  • Escalate: “Let me call the charge nurse or supervisor.”
  • Contain: “Please wait here while I check.”
  • Log: Record failed badge attempts followed by manual entry.
  • Review: Match physical access events with visitor records and staffing schedules.

This is where physical security begins to look like endpoint security. Controls need telemetry, review, and behavior-based detection, not just hardware. That same principle underpins why investors are paying attention to security tools that track modern risk signals, as covered in XOOMAR’s $1.2B AI Risk Bet Hurls Glow Endpoint Security Into View.

Would the nurse have acted differently if failed badge plus manual override triggered a review?

Operators: Medical Privacy Needs a Lock, a Log, and a Challenge

Hospitals and clinics should treat the Schloss story as a drill script.

The practical fixes are not exotic:

  • Badge checks: Don’t open restricted doors for failed badges without independent verification.
  • Escorted access: New staff, vendors, students, and contractors should not self-navigate sensitive spaces.
  • Locked storage: Physical files should not be reachable just because someone enters the room.
  • Printer control: Sensitive printouts should not sit unattended.
  • Visitor verification: Scrubs, confidence, and local gossip are not credentials.
  • Network segmentation: Guest Wi-Fi should not share exposure with clinical devices.
  • Encryption in transit: Medical-device traffic should not reveal PII in cleartext.

The deeper fix is management backing. Staff need to know that challenging someone is not rudeness. It’s the job.

Security teams also need to test these controls the way Schloss did. Not with a policy review. With live exercises that measure whether people challenge failed badges, whether manual entries are logged, and whether guest networks can see sensitive device traffic. The endpoint lesson is similar to the one in $1.2B AI Risk Bet Hurls Glow Endpoint Security Into View: visibility matters most when routine behavior starts to look risky.

Can a hospital prove its records room is secure without sending someone to try to talk their way in?

Attackers Will Keep Starting in Hallways, Desks, and Shared Printers

The forward-looking signal is blunt: healthcare social engineering does not need Hollywood hacking. It needs local names, workplace language, fake urgency, and a staff member who has not been given permission to say no.

The evidence that would confirm this thesis is specific. More red-team reports showing failed badges followed by manual entry. More audits finding guest networks adjacent to clinical devices. More incidents where physical access leads to exposure of files, screens, printers, or device traffic.

The evidence that would weaken it would be just as concrete: routine challenge drills, clean logs around manual overrides, segmented guest networks, encrypted device traffic, and frontline staff who can delay access without fear of blame.

The future of medical privacy won’t be decided only by firewalls. It will also be decided at the records room window, when one employee says: “I need to verify who you are.”

Impact Analysis

  • The test shows that hospital security can fail even when electronic access controls are in place.
  • Staff under pressure may be manipulated by social cues that sound familiar and urgent.
  • The incident highlights the need to train healthcare workers to verify requests without slowing care.

Hospital Records Room Access Controls vs. Social Engineering

Barrier or TacticWhat Happened
Electronic lockThe fake badge could not swipe Schloss into the records room.
Human gatekeeperA nurse was persuaded by an insider-style complaint about “Dr Johnson.”
PretextingWorkplace frustration became the successful route into the records room.
XOOMAR

Written by

XOOMAR Insights Team

Research and Editorial Desk

The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.

Related Articles

Fake Wi-Fi technician stealing a trophy from a corporate office amid digital security visualsCybersecurity

Fake Wi-Fi Fixer Snatches $250,000 Trophy in Security Test

A fake Wi-Fi fixer walked a $250,000 trophy out of a Fortune 500 office, proving habit can beat security policy.

Jul 9, 20268 min
Silhouetted cybersecurity leader analyzing risk signals with shields, locks, and code in a dark command room.Cybersecurity

Judgment Beats Tools in Tarah Wheeler CISO Playbook

Tarah Wheeler’s CISO playbook reframes security as behavior, evidence and risk judgment, not just technical control.

Jul 12, 20268 min
AI assistant compromised through poisoned inbox attacking a developer workstationCybersecurity

Claude Desktop Betrays Developers in Code Execution Attack

Pentera showed a breached inbox could poison Claude Desktop and escalate into remote code execution on a developer workstation.

Jul 1, 20267 min
Glowing master key over user profiles in a dark law office, symbolizing exposed sensitive dataCybersecurity

Shared Admin Password Exposes Law Firm Client Data

A law firm used one admin password to impersonate staff and clients, exposing PII, health records, and audit trails.

Jul 16, 20267 min
US Capitol with global defense imagery and connected world map, symbolizing a contentious defense bill vote.Global Trends

Trump’s $1.15tn NDAA Squeaks Through Bitter House Revolt

A $1.15tn NDAA barely cleared the House as Democrats turned Trump’s Iran war and voting agenda into a Senate showdown.

Jul 23, 20266 min
English high street with pub and vape shop under a global map, symbolizing shifting local tax policy.Global Trends

Andy Burnham Makes Vape Shops Pay for Business Rates Cut

Burnham’s 20% pub rates cut turns vape shops into the billpayer and signals a tougher tax fight on England’s high streets.

Jul 23, 20269 min
Silver bars on a trading floor with market charts suggesting stalled momentum and rising yield pressure.Trading

Treasury Yields Pin Silver Price Forecast Under $60

Silver's 7.5% rally is stuck below $60 as Treasury yields climb, turning the next XAG/USD move into a credibility test for bulls.

Jul 23, 20267 min
Crude oil trading screens show WTI price action near resistance with oil barrels and market visuals.Trading

WTI Price Forecast Pins $90 Hopes on One Clean Breakout

WTI is pressing $87.50, but bulls need a clean break above the 100-day SMA near $88.15 to put $90 in play.

Jul 23, 202611 min
Trading floor visualizes yen rising amid intervention risk and volatile dollar-yen market pressure.Trading

Intervention Fear Knocks USD/JPY Back From 40-Year High

USD/JPY eased near 163 as Japan's intervention warnings made traders think twice about a crowded dollar-yen carry trade.

Jul 23, 20268 min
FX trading desk visualizing AUD/USD breakout after strong Aussie jobs data amid dollar and oil risks.Trading

Jobs Beat Sends AUD/USD Price Forecast Above 0.7000

AUD/USD cleared 0.7000 as strong Aussie jobs data lifted RBA hike bets, but Dollar and oil risks still threaten the breakout.

Jul 23, 20265 min

Don't miss the signal

Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.

Free forever. No spam. Unsubscribe anytime.