You obviously don't understand how utterly appalling the security of a lot of software is. My job title is "security consultant" and the last test I did was on a medical related application that tracks medication administered to patients in care facilities. All the sensitive patient data can be read and updated completely unauthenticated. They implemented ALL of their permission checks in the thick client which simply talked to a webservice - anyone with a decompiler and half a brain could alter patients drug doses with no record. This is a large application used in a large number of places.
Maybe we need more security consultants in the medical industry.