In 2016, I was brought in to assist on a colleague’s massive “Reveal, Repair, and Reprogram” project for one of New Mexico’s two specialized cancer research and treatment centers.
New Mexico’s IT industry is a fascinating ecosystem made up of dozens of “fully staffed firms,” each consisting of one person, a logo, and a dangerously optimistic business card and website. When one of these operations lands a contract larger than their Adderall intake can support, they subcontract other firms with the necessary skills.
This was one of those moments. It was a digital barn-raising, except the barn was on fire, wired incorrectly, and storing nuclear materials in a horse stall.
Author’s Note-
I will not name the center, though this is a small state and the process of elimination is a powerful thing. Please note that everything described here was provided to regulatory agencies and law enforcement shortly after the events occurred. To the best of my knowledge, nothing was ever done with the information, which is fully par for the course in the Land of Entrapment. (At this time, our award winning1 local police openly2 and admittedly3 manufactured crack4, accepted worn items of clothing in exchange for it, and then arrested their homeless victims for felony possession to “Help them out!”, for Christ’s sake!)
Also, while the contracted firm signed NDAs, I did not. This appears to have been a catastrophic oversight. I am unbothered by that unforced error.
Back to the story-
After repeated violations of HITECH (The Health Information Technology for Economic and Clinical Health Act5) the digital side of HIPAA (the Health Insurance Portability and Accountability Act6), designed to prevent hospitals from doing exactly what these guys were doing, the Center had recently been fined $1.5 million by the HHS Office for Civil Rights7.
We were brought in to assess and fix cybersecurity, business processes, compliance, policy adherence, and operational behaviors such as device management, disposal, and secured communication practices, with the goal of stitching up an open data wound oozing patient PI (Personal Information) like it was starring in a Hellraiser flick and forcing the Center into the kind of compliance remission necessary to be worthy of being called a medical institution.
This was ambitious, to say the least.
The Soon to be Former IT Department
What we discovered was an awe inspiring commitment to professional negligence.
Their in house IT team spent most days playing catch with a baseball and engaging in lively discussions on every subject except information technology, cybersecurity, patient privacy, or federal law. They were basically running a tech themed daycare center, minus the supervision and moral responsibility.
When I say what we discovered was unbelievable, I am not being hyperbolic. It was genuinely baffling that the department had not already been shut down by federal agents storming the building while shouting acronyms.
We uncovered evidence of wire fraud, unauthorized database access, malicious code injection into medical records, installation of EMR backdoors, identity theft, and credit card fraud. In short, they had assembled what can only be described as a Greatest Hits compilation of federal crimes.
The Point of IT All?
What I was able to put together from what we found in the on-site PCs, pre-un-non-shredded paperwork and, of course, what arrived in the mail, they were actively mining patient data to apply for credit cards in the names of terminal patients. Apparently, someone saw end-of-life care and thought,
“You know what this really needs? Identity theft.”
Needless to say, our first recommendation was to fire the entire IT team, immediately. Instead, they fired most of the IT staff. The head of IT security was placed on four weeks paid leave, while her security credentials remained active and she retained full remote access to all systems. During this time, her keys were used to download gigabytes of patient data.
In most organizations, suspicion of these kinds of activities results in immediate credential revocation and a brisk escorted walk to the parking lot. Here, it earned a paid vacation and unlimited data access. Management clearly believed in something. What? I have no idea.
Testing Location Security
The building had no fit-for-purpose camera or security system. It did have exactly one security camera, pointed at the IT Department door, wired to a Raspberry Pi with a wireless network connection. We never found a client app for it anywhere.
The following is just one example of how badly they failed all of our tests.
During one routine test, I obtained a vendor key card from the front desk without signing for it or even so much as telling the receptionist who I was. The following Saturday, I returned when the building was closed and used that card to access every secured area in the facility, including the side entrance and the room containing the nuclear medicine storage lockers, which were unlocked and unguarded, but not empty.
This is a Department of Homeland Security violation8 so severe it should reasonably be expected to result in permanent closure and the arrest of responsible staff members and managers. This resulted in zero actions by DHS after they were informed. I guess they were busy elsewhere.
To bring this point home- Their system treated every key card as a permanent, unrestricted, all-access pass. No logs. No tracking. No accountability. The security model appeared to be: I really can’t be bothered with this right now.
Although I was assigned my own staff card with photo ID, I continued to use the vendor card, exclusively, until we finally corrected that issue.
Device Security
Retired Devices and Equipment-
Several rooms were filled with dismantled laptops, desktops, and servers, harvested for parts so IT staff could build personal machines for themselves, their friends, and assorted staff members. We know this because we found several unfinished gaming builds, a couple fully built machines, and thank you notes.
A hard drive shredder existed on site, presumably as a decorative sculpture. It had never been used. Policy and law mandate that health care drives be destroyed before disposal. Instead, they were casually recycled into offsite personal systems, allowing patient records to roam freely across Albuquerque like lost pets.
Active Devices and Equipment-
The $1.5 million HITECH fine stemmed from a stolen laptop left logged in at the front registration desk. The doctor who absentmindedly left the MacBook there, disliked logging in repeatedly, so IT kindly configured the machine to bypass security* altogether. After an initial sign in, he would remain signed in to the machine, the network, and the EMR archives until the machine was turned off, because convenience is the cornerstone of cybersecurity. The only surprise here was that the police were notified of both the theft and the potential unauthorized access specifics.
*This wasn’t a one off. We found many systems set up this way.
Secure Communications
Now we arrive at the truly horrifying part.
The most worldview shattering part of our deliverables turned out to be this, “ascertain compliance with secure communications protocols”. This involved the read through of hundreds of email threads between doctors, staff, and administrators. I wish I’d passed on this part of the project.
Reviewing internal email communications revealed exactly zero discussions about improving patient outcomes. Instead, conversations focused on strategies for-
Upselling patients into more expensive treatments
Pressuring consent for experimental procedures
Justifying additional unnecessary testing and treatments
Entirely exhausting insurance benefits
Encouraging debt acquisition to pay for more treatment
Extending treatment plans until financial resources were fully depleted
There were frequent discussions of life expectancy, emotional resilience, physical decline, and optimal revenue extraction timelines, but no mention of their promises of reduced spread or remission ever coming to fruition. They congratulated one another on billing achievements, never on patient recovery.
This was not healthcare. This was hospice flavored vulture capitalism.
Connecting Crimes
These conversations theoretically aligned with the IT department’s identity theft operations. The timing of fraudulent credit card applications would need to match patients’ desperate attempts to finance continued treatment, ensuring that when patients died, families inherited a mountain of debt alongside their grief, with no way of knowing that a few of those expended credit card limits went to buying jewelry, home electronics, and gift cards they would never see.
I did not find direct written orders from administrators instructing IT to commit crimes. I did, however, find multiple random emails from Center administrators to IT staff containing Amazon wish lists, filled with expensive personal items, with no discernible professional justification.
Coincidences, of course, happen all the time.
The Results
After roughly 120 days, we brought the Center back into regulatory compliance and successfully appealed the $1.5 million fine. Within minutes of the appeal being granted, our contract was terminated, our access revoked, and since that day, our outstanding invoices ignored. Totaling over $80,000.
They also promptly rehired key members of the former IT team, despite being shown overwhelming evidence of their criminal activity. This last act, frankly, brought everything full circle. Like a very expensive, deeply unethical, morally unhinged, federally regulated, but not visited carousel of grief and misery.
You may wonder how they sleep at night, but I know that’s what the Ambien and Trazadone are for.



Holy Shit!!