"Nurses talk a lot of shit. It's the law of the land when it comes to the hospital," Dahvid Schloss told us.
Dahvid Schloss's social-engineering ploy
Red teamer Dahvid Schloss was hired to test a hospital's physical security by retrieving a specific physical file left for him to pilfer. He considered technical options — picking the electronic lock, cloning or stealing a badge — but instead chose a people-first approach. Schloss put on hospital-appropriate scrubs, created a fake security badge that could not swipe in, and leaned on a scripted complaint about a named clinician.
When his badge failed, he approached the nurse at the records-room window with a rehearsed story: "I'm doing fine, hon. How you doing," followed by, "Look, I'm gonna save you the details. But Dr Johnson's being an absolute asshole right now; he didn't pull out his patient records that he was supposed to pull out for trauma. We need these records, and they sent me down here. I'm brand new. I just started yesterday." Schloss had researched the hospital and picked an actual on‑staff doctor's name; he later learned the doctor was in fact difficult to work with.
The records room: electronic lock and a nurse gatekeeper
The records room Schloss targeted had two layers of control: an electronic lock and a nurse stationed as a gatekeeper. Schloss's social approach worked. As he told the story, the on‑duty nurse responded, "honey, I know exactly the pain that you're going through," and "I got you" — then opened the door and let him in. Schloss retrieved the file, lingered for roughly 10 minutes trading complaints with the nurse and delivering a backstory about previous work, and was even invited to lunch before he left with the folder.
Hospital networks, MRI machines, and unencrypted PII
Schloss described a separate, technical failing he has observed at other hospitals. In one case, after connecting to guest Wi‑Fi from a waiting room, he found that "all the important devices in the hospital were on VLAN 1, the same network as guest Wi‑Fi." He said data leaving medical devices — specifically calling out the MRI machine — was "readily accessible and unencrypted." According to Schloss, this exposed Social Security numbers and other patient data: "So you're getting Social Security numbers just being populated over the network via the MRI machine and you're getting the patient data, the date of birth, all the PII that any organization would lose their shit about."
Schloss summarized his broader observation bluntly: "most medical devices at most hospitals he’s tested do not encrypt data that they send over the network." He framed the choice hospitals face as a tradeoff: many prioritize keeping machines running and distributing data quickly over following "good security hygiene," because any delay that forces clinicians to call IT could, in their view, "cost a life."
What this means for technologists, procurement leaders, and patients
- Technologists and security teams: Schloss's findings highlight two concrete weaknesses to watch for — weak physical authentication processes and network segmentation failures that leave critical devices on the same VLAN as guest Wi‑Fi, with unencrypted traffic from devices like MRI machines.
- Procurement leaders and device vendors: The account underscores that many deployed medical devices may not encrypt data in transit; procurement decisions that tolerate unencrypted devices create opportunities for exposure of personally identifiable information such as Social Security numbers and dates of birth.
- Patients and clinical staff: The story illustrates how simple social engineering and routine operational choices can expose private medical files and PII — even when a facility has an electronic lock in front of a records room, a human gatekeeper remains a critical control point.
Schloss's episode is plain and proportional: a fake badge, a rehearsed gripe about a real doctor, and a willing nurse opened a door and handed over private records. His network findings are equally stark — medical devices on default or flat networks, and data leaving equipment like MRI machines in the clear. If the hospital's priority is minimizing delay for patient care, the human and technical gaps he describes are where attackers will probe first.
The blunt takeaway Schloss leaves is also the clearest prescription in the piece: "But even if it's a matter of life and death, do not let someone into a restricted area just because they look and act the part." That leaves hospital leaders with a practical tension to resolve — how to preserve uninterrupted care without turning basic access-controls and network hygiene into optional extras.




