Skip to main content

When Gossip Becomes a Privacy Risk in Healthcare

Rare Ivy
Rare IvyMarketing Manager
11 min read
When Gossip Becomes a Privacy Risk in Healthcare

How everyday chatter turns into a privacy threat

In hospitals, privacy failures don’t always begin with a clever piece of malware or a polished hacking toolkit. Sometimes they start with a shrug, a half-finished conversation, or a staff member deciding that the person at the door probably belongs there. That’s the awkward part of a healthcare privacy risk: the weak spot can be ordinary workplace trust, the kind people use all day without thinking twice.

Dahvid Schloss, a red teamer who has tested both digital and physical security at hospitals and other sites, has spent time looking for exactly those seams. His work isn’t limited to software screens and network ports. He also pays attention to doors, desks, badges, plus the split-second decisions people make when something feels familiar enough. In a hospital, that can matter just as much as a password prompt.

One of his tests centered on a records-room access attempt, where a locked door was only half the problem. The other half was the human gatekeeper standing beside it. That setup’s easy to underestimate if you’re thinking like a technician. A lock is a lock. But a person can be persuaded, distracted, or simply tired of being the bad guy at the end of a long shift.

A restricted room is often protected by hardware, but the real barrier is whether staff question the story they’re hearing.

That’s where hospital social engineering gets unpleasantly effective. Healthcare workers are used to urgency. They’re also used to colleagues asking for help, asking for access and asking for things to move faster because a patient, a doctor, or a chart’s waiting somewhere down the hall. If someone shows up sounding frustrated, busy, and vaguely offended by a delay, that can sound less like a threat and more like another rough day at work.

There’s also a social layer to it. Staff members talk. They complain about delays, missed handoffs and the eternal mystery of why a record wasn’t ready when it should’ve been. So when someone drops into that same conversational groove, the request can feel oddly safe. Not because it’s safe, but because it sounds like the sort of thing everyone has already heard before.

That’s the real lesson running through this story. A person who acts like they belong may not need to force anything. They may only need to fit the rhythm of the place, say the right annoyed thing and let assumptions do the rest. In the next section, the access test gets more specific, and the details show how little it took to turn casual chatter into entry.

The records-room test: a fake badge, scrubs, and a complaint

The records-room test: a fake badge, scrubs, and a complaint

The records room had the sort of setup that looks reassuring on paper and slightly less reassuring once a human being gets involved. There was an electronic lock on the door, then a nurse stationed nearby to decide who actually got through it. Two layers. One keypad, one person. That sounds decent until someone shows up looking like they belong.

Dahvid Schloss didn’t start with the social trick. He looked at the room and considered the blunt options first: lock-picking, badge cloning, or lifting a legitimate badge from someone who already had access. Those paths were there, and in a less patient mood, one of them might’ve worked. He chose the quieter route instead.

He researched the hospital, put on scrubs and clipped on a fake badge that looked official enough from a few feet away. It couldn’t open the door. That was the point. The badge was a prop, not a credential. He then walked up to the reader and acted like the problem was technical, not personal.

In medical records security, the door is rarely the hardest part. The harder part is getting someone to assume you’ve already cleared it.

When the badge reader refused to cooperate, he played the part of the annoyed staffer who had already had a long shift. The complaint came next. He blamed the delay on a doctor who had supposedly failed to prepare trauma records ahead of time. Not a vague doctor, either. He used the name of a real doctor on staff, which gave the story a little weight and kept it from sounding like a random excuse cooked up in the hallway.

That detail mattered. A made-up name can sound fake in a hurry. And a real one sounds like inside baseball. And hospital gossip has a habit of making those names feel familiar fast.

The nurse heard a complaint that fit the daily rhythm of the place. Doctor didn’t send the records. Badge is acting up. Patient care is waiting. That mix is hard to ignore, especially in a setting where people are used to solving problems quickly and moving on. Schloss had dressed for the job, spoken like he belonged there and picked a grievance that sounded routine rather than suspicious.

He didn’t walk in waving his arms or acting like a movie villain. And he waited. He let the frustration sit in the air for a moment. Then the nurse sided with him, opened the door, and let him into the records room.

That part’s almost annoyingly simple. No lock got dramatically defeated. And the badge reader did its job, no alarm screamed. The nurse did hers, too, at least as far as she could tell from the information in front of her. The weak spot was the story that wrapped around the access request. Once the complaint sounded plausible, the rest followed.

This is where hospital gossip gets dangerous. A passing remark about a doctor, a casual assumption about who’s behind schedule, a bit of shared irritation about paperwork or trauma prep and suddenly a stranger has a path into a restricted space. The badge was fake, but the social context was real enough to carry it across the threshold.

For anyone thinking for medical records security, that’s the uncomfortable lesson. Doors and readers matter. So do the people standing beside them. If the person asking for access sounds overworked, annoyed and vaguely connected to the right names, the security check can shrink to a quick nod and a hand on the handle. That’s not a computer problem, and it’s a habit problem.

The same pattern shows up elsewhere, too. A workplace that gets casual about access can hand the wrong person the keys without much resistance. A law office, for instance, can make itself just as vulnerable when everyone wants one shared password, as in How I Would Handle a Law Firm Asking for One Password Everyone Can Use. Different setting, same bad reflex: trusting convenience a little too much.

Why the lie worked: trust, status, and shared frustration

Once Schloss got past the door, the easier question was how. The better one was why anyone inside the room felt comfortable enough to help. And the answer sits in a very ordinary part of hospital life: people complain together. They complain about delayed orders, confusing schedules, and, yes, doctors who seem to treat everyone else’s time like a suggestion. That kind of gripe can sound trivial from the outside. Inside a ward, though, it acts like a password of sorts. They start to feel familiar fast, if someone mutters about a difficult doctor and sounds annoyed in exactly the same way you’re annoyed.

That’s where the con gained traction. Schloss didn’t walk in sounding polished or theatrical. He acted like a nurse, tech, or support worker who had already had a long shift and was now being slowed down by a malfunctioning badge reader. That detail matters more than it might seem. A fake badge can be spotted. Scrubs can be borrowed. A calm, annoyed tone is harder to challenge because it matches the mood of the place. The complaint made him seem unremarkable, and in a busy hospital, unremarkable often passes for legitimate.

People trust the person who sounds tired in the same language they use to complain.

He also used frustration as cover for status. Rather than act mysterious, he behaved like someone dealing with routine friction. That puts the listener in a familiar frame of mind. The nurse at the door wasn’t being asked to evaluate a bizarre intruder with a movie-villain plan. She was dealing with another staffer who had an irritating problem and wanted to get on with the workday. In healthcare cybersecurity, that’s the awkward part. A malicious person doesn’t always look malicious. Sometimes they look like someone who needs a hand and has the right vocabulary to ask for it.

Why the lie worked: trust, status, and shared frustration

The invented backstory helped, too. Schloss didn’t speak as a blank slate. He reportedly gave himself prior work experience that made him sound like he had already spent time around hospitals. That kind of claim does a lot of quiet work. It explains why he knows the rhythm of the place. And it explains why he sounds impatient instead of lost. It even gives his story a bit of worn-in credibility, as if he’d already learned the rules and was now stuck dealing with them. A front-line gatekeeper hearing that from a person in scrubs may not have enough reason, or enough time, to stop and untangle it.

What followed was almost more persuasive than the entry itself. After the file was handed over, Schloss didn’t rush off in a way that would’ve felt scripted. He stayed. Simple as that. He chatted for several more minutes. That extra time matters because belonging’s often measured in tiny social cues, not in credentials. People who don’t belong usually leave quickly, keep their answers short, and act as if every second’s borrowed. Someone who belongs lingers, complains a little and fills the silence with the kind of talk that no one remembers later. The conversation itself becomes proof of harmlessness.

This is one of those situations where gatekeepers can be more exposed to someone who speaks their language than to someone who looks suspicious on paper. A strange badge can be waved off if the story sounds right. A tired-sounding complaint about a doctor can do more to lower the guard than a perfectly printed credential can raise it. The mind seems to ask, “Would a real employee be this irritated?” and, unhelpfully, the answer is often yes.

That doesn’t mean every complaint is a security risk. Hospitals would grind to a halt if staff treated every gripe like a breach attempt. Still, the episode shows how much everyday interaction shapes access. People do Verify faces and badges. They also verify tone, posture and whether someone sounds like they belong to the same overworked tribe. Schloss understood that. He made himself sound like one more person trying to get through the shift, not like a stranger trying to defeat a lock.

And that’s the uncomfortable lesson for healthcare cybersecurity and even medical device network security planning more broadly. The weakest point isn’t always a system or a cable. Sometimes it’s a moment of recognition that happens too quickly, before anyone asks the extra question.

The bigger problem: hospital networks built for speed, not separation

the mess didn’t stop at a single door, once the records-room trick worked. Schloss also looked at the technical side of hospital security, and that’s where things got uncomfortable in a less theatrical, more ordinary way. No fake badge required, and no nurse to persuade. What was deserved by just a guest connection in a waiting room and a network that seemed to assume everyone inside the building is a seat at the same table.

In one test, he connected to the guest Wi-Fi from a hospital waiting area and found major medical devices sitting on the same network segment as visitors. That meant the public side of the hospital and equipment used for patient care were sharing the same digital space. In practice, that sort of setup often means a shared VLAN, where traffic from outsiders, internal staff, and sensitive systems all pass through the same general lane instead of being split off cleanly.

A guest network should be for guests, not a front-row view into medical equipment.

That’s the part that makes people blink. Guest Wi-Fi is supposed to be boring. Maybe someone checks email. Maybe a child watches a video while a parent waits for test results. It shouldn’t, even accidentally, give a curious visitor a view of devices tied to patient care. Yet that was the shape of the problem here. The hospital had built a network that moved data fast, but it had not separated that data nearly well enough.

He also found traffic from medical equipment, including an MRI machine, visible on the network and sent without encryption. That’s the kind of detail that sounds technical until you spell out what can ride along in those packets. Social Security numbers. Dates of birth. Names. Internal identifiers. Other personal details that can point directly back to a patient. If that traffic isn’t encrypted, anyone with access to the right part of the network may be able to read it as it moves. That’s patient data exposure in plain sight, not in a Hollywood sense, but in the dull, real-world way that actually causes damage.

Hospitals can end up here for reasons that make some sense on paper. Their systems have to stay online. Images need to move quickly. Nurses and doctors can’t wait around while a network admin decides whether a segment should be split, re-routed, or tested after midnight. If a delay slows a scan, a chart lookup, or a machine used at the bedside, the whole place feels it. So security hygiene can get treated like the thing that will wait until after the next shift change, after the next upgrade, after the next time somebody has a free afternoon, which in a hospital may be a fantasy category.

That tradeoff is understandable. It’s also where trouble gets invited in wearing a lanyard and a helpful smile. Isolation starts to look optional, when uptime becomes the main goal. Encryption can get skipped on systems that were never meant to be visible to a guest on public Wi-Fi, when fast data flow is the priority. And once a network’s built that way, a privacy problem can spread far beyond one prankish conversation at a door.

Schloss’s point was not that hospitals don’t care. They clearly do. The problem’s that caring about care can push teams toward speed, convenience and fewer interruptions, even when those choices leave patient records and device traffic easier to expose than anyone would like to admit. A hospital can be fully staffed, well meaning and still have a network that assumes too much trust.

That’s the broader lesson here. Gossip may have opened one file room, but the network design showed a much wider gap. One was social. The other was structural. Together, they make a pretty poor argument for letting familiarity do the work of verification. The next question is what hospitals, and the people guarding their doors and systems, can do when the request sounds routine but the risk isn’t.

Practical safeguards for hospitals and the people guarding them

A scrub top can buy a lot of goodwill. It shouldn’t buy a door. If a person says they’re new, delayed, sent by another department, or stuck because a doctor “forgot” something, that story needs a little friction before anyone hands over access. Hospitals run on trust, but trust without a check is just guesswork with a badge clip.

Friendly isn’t the same as verified. In a hospital, the fastest way to prevent a bad day is often to pause long enough to confirm the basics.

For front-line staff, the habit can be simple: ask for the person’s full name, department, and supervisor, then confirm it through an internal directory or a known callback number. Don’t use the number they offer. Don’t accept “I’m covering for someone” as proof. If someone claims they were sent by radiology, records, IT, or a physician’s office, the next step is a call to that department, not a shrug and an unlocked door. A temporary badge, a visitor log, and an escort rule can help too, but the real win is consistency. The same script should apply whether the person looks nervous, polished, sleep-deprived, or annoyingly confident.

The network side needs the same sort of discipline. Guest Wi-Fi should live on its own island, not on the same internal lane as imaging systems, charting tools, or medical equipment. If a visitor can reach the same segment as an MRI machine, a nurse station terminal, or a file share full of patient data, the network design has already done half the attacker’s work. Separate VLANs or subnets are the starting point, not the finish line. Firewalls, access control rules, and tight routing restrictions should keep public traffic from wandering into systems that store or move sensitive records.

Encryption matters just as much. Patient details can be read while they travel across the network, when device traffic moves in plain text. That can include names, dates of birth, account details and other information nobody should be able to skim with the right tool and five quiet minutes. Secure protocols and encrypted sessions should be standard wherever the equipment supports them. It needs compensating controls and a limited network path, not a polite exemption because replacing it’s inconvenient, if older hardware can’t do that cleanly.

Healthcare will always involve urgency. Alarms ring, people rush and nobody’s time for theater. Still, urgency can’t be the excuse for skipping identity checks or leaving systems wide open. A hospital can move quickly and still ask one more question before the door opens.

Newsletter

Stay in the loop

Join our newsletter and get resources, curated content, and inspiration delivered straight to your inbox.