SECURITY

Talking smack about a doctor got him access to private medical files

Who needs a working security badge when you know how to talk your way into the records room?

PWNED Welcome back to PWNED, the weekly column where we focus on security own-goals so you can avoid them. This week’s topic involves serious problems in the healthcare sector, specifically the very human problem of compromised gatekeepers.

Have a story about someone leaving a gaping hole in their network? Share it with us at pwned@sitpub.com. Anonymity is available upon request.

Our legend of lameness comes courtesy of red teamer Dahvid Schloss, who shared so many great stories with us that we’ve featured his tales a couple of times before. Schloss has made a career out of testing not only network security but also physical security at a wide variety of places. He has learned that if you act as you belong, people will usually treat you like you belong.

At one hospital, Schloss was hired to test security by getting access to the records room and trying to steal a specific physical file that his client left there for him to pilfer. The challenge was that the records room had both an electronic lock and a nurse gatekeeper guarding it.

Schloss told us that he considered several approaches to get into the records room. He could try picking the lock, cloning a badge, or even stealing the badge of someone who had access. Instead, he decided to try social engineering.

Schloss did research on the hospital and he put on a pair of appropriate scrubs and made himself a fake security badge that could not possibly swipe in. Then he knew it was time to turn on the charm with the nurse who was on duty at the records room. And by “turn on the charm,” we mean “diss the doctor.”

“Nurses talk a lot of shit. It's the law of the land when it comes to the hospital,” Schloss told us.

So he tried to swipe his non-working badge and showed frustration when it didn’t work. Then he walked up to the window where the on-duty nurse was standing and won her over.

“I'm doing fine, hon. How you doing,” he told the nurse. “Look, I'm gonna save you the details. But Dr Johnson's being an absolute asshole right now; he didn't pull out his patient records that he was supposed to pull out for trauma. We need these records, and they sent me down here. I'm brand new. I just started yesterday.”

Schloss had done his research and picked out the name of an actual doctor on staff. What he couldn’t have known is that the doctor was actually a difficult person to work with. And the duty nurse let him know she was on his side before letting him in.

“The nurse goes ‘honey, I know exactly the pain that you're going through,’” Schloss continued. “She goes ‘I got you’ and she opens the door, lets me in.”

After Schloss went into the records room and retrieved the file, he hung around and talked to the nurse for another 10 minutes, complaining about how security was incompetent for not activating his badge and letting her complain about what jerks some of the doctors were. He even had a backstory about where he had worked before. She invited him to hang out and go for lunch sometime before he left with the folder.

Other hospitals he tested had bad network security practices. He told us about one hospital where he sat down in the waiting room and logged into the guest Wi-Fi network and did a scan.

What he found was that all the important devices in the hospital were on VLAN 1, the same network as guest Wi-Fi. All of the data coming out of medical devices like the MRI machine was readily accessible and unencrypted. He said that most medical devices at most hospitals he’s tested do not encrypt data that they send over the network.

“So you're getting Social Security numbers just being populated over the network via the MRI machine and you're getting the patient data, the date of birth, all the PII that any organization would lose their shit about,” he said.

Schloss said that he thinks hospitals he’s tested prioritize the ability to keep machines running and distributing data quickly over good security hygiene. If someone tried to get data, failed, and had to call IT for help, those precious minutes of delay could cost a life.

But even if it's a matter of life and death, do not let someone into a restricted area just because they look and act the part. ®