Network Security

Hospital security compromised by social engineering and poor network practices

The image shows an illuminated "EMERGENCY" sign on a hospital door

As outlined in The Register, a recent security assessment highlighted significant vulnerabilities within the healthcare sector, particularly concerning compromised gatekeepers and inadequate network security. These issues, often stemming from human factors and a prioritization of operational speed over security, create substantial risks for sensitive patient data.

Red teamer Dahvid Schloss demonstrated how social engineering can bypass physical security at a hospital. By impersonating a new employee and leveraging common workplace frustrations, he successfully gained access to a restricted records room guarded by a nurse. This highlights how easily gatekeepers can be manipulated. Furthermore, Schloss discovered that critical hospital devices, including MRI machines, were often on the same network as guest Wi-Fi. This lack of network segmentation allowed sensitive patient data, including Social Security numbers and personal information, to be transmitted unencrypted and readily accessible. The underlying issue appears to be a prioritization of machine uptime and data flow speed over robust security measures, a trade-off that leaves patient data highly vulnerable to breaches.

Source: The Register

An In-Depth Guide to Network Security

Get essential knowledge and practical strategies to fortify your network security.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds