BPL Logo Banner
CareersContact

In Part 1, we showed how a single text file could compromise an entire healthcare network. But not every breach starts with a forgotten password file. 

Sometimes, the threat is physical. It’s an unlocked workstation in a patient room, an open network jack in a hallway, or a forgotten web portal that everyone—including the IT team—forgot was facing the internet.

The Patient Room Hack

Hospitals are unique environments. They host a constant stream of visitors who are granted a level of privacy not found in a typical corporate office. Unfortunately, this physical access can quickly become a digital nightmare.

The Flaw: For a busy hospital IT team, securing every connected workstation is a monumental challenge, yet these workstations remain a frequent entry point for attackers.

The Attack: An attacker can plug a device into a physical port on an unsecured workstation. Even if the organization has disabled USB drives, many common prevention methods are ineffective against Human Interface Device (HID) attacks.

In this scenario, a malicious device masquerades as a keyboard. This allows it to bypass standard USB storage restrictions and rapidly type commands to download and execute malware.

The Result: In just a few minutes, an attacker can turn an unsecured workstation in a patient room into a persistent foothold deep inside the network. The attacker achieves this without needing to defeat a single security appliance.

Mitigation Strategies: Physical and digital security are deeply intertwined.

The Forgotten Front Door

Sometimes, the greatest risks are the systems you don’t even know are exposed. Poor asset management, a human process, can leave a critical internal system open to the entire internet.

The Flaw: During a pentest for a healthcare customer, our team identified a pager application web portal for medical personnel that was accessible from the internet. The organization didn’t realize this system was publicly exposed. This kind of oversight in asset management is a common challenge we see when conducting security penetration testing for our clients.

The Attack: We discovered we could send a pager message to our Point of Contact without being authenticated to the system. An attacker could exploit this vulnerability to cause significant disruption to staff communications. 

In addition, the application publicly listed personnel names and phone numbers, providing a perfect resource for a future phishing or social engineering campaign.

The Result: A critical communication line was left open to potential disruption, and a sensitive employee directory was exposed to the public, all from a system they didn’t know was exposed.

Mitigation Strategies: You can’t protect what you don’t know you have.

Securing Your Full Attack Surface

Your true attack surface is always larger than the systems you have on paper. A single workstation or forgotten web portal can open doors that attackers are eager to exploit.

Key Takeaways:

Our hospital cybersecurity assessments go beyond basic scans. We evaluate everything from workstations to waiting room jacks to exposed web portals, helping organizations secure both the physical and digital sides of their attack surface.


Once we’re in, we look for the “keys to the kingdom” — and too often, they’re left lying around. In Part 3, we reveal how default credentials, old accounts, and mismanaged data expose entire networks. If you think your old password doesn’t matter, think again.

chevron-down