Earlier quoted context omitted.
A relative of mine works in IT for a non-US hospital. (Avoiding naming it because of backlash potential, both for him and myself.) When he started there, as bottom level IT support, he had access to everything. Admin passwords, doctor's passwords, he could write prescriptions and put a doctor's name on it. He could order anything and everything, and send it anywhere. He could read your medical files, if you were a pa…
For the first 100 years, we just arrested folks who actually faked records or stole things. Now we do it if they don't make it impossible? I know, networks change everything. But inside a secure facility its often (always) the case that personal integrity (and maybe some audits) is used to ensure correctness most of the time. Somebody working in a hospital could steal prescriptions off of patient's tables, could lift…
First, "impossible" is taking the argument to the extreme. Second, the insecure network OP described is negligence. Perhaps they were even reckless. That's not a new concept.