A health company where they have that poor of security practices? Get the hell out ASAP! When they get ransomware, (and they will,) you do NOT want to be on the hook for trying to recover their systems.
Trust me, I had to help recover from a ransomware attack at a small company a while back, it hit early in the morning, I got there a little before 8am once I got the call.
22 hours later, we had only just finished wiping and re-imaging every computer, let alone getting all the software reinstalled, configured, tested, backups re-synced, etc. It took weeks to get everything fully recovered, and that was with a team of half a dozen people.
In the meantime, CYA hardcore. Document all security issues you can find in email and make sure whoever is in charge is aware and is on the email chain. There literally could be legal charges brought up if it’s involving private health information.
At a place I worked at previously, there was a guy who got fired because the company found out that he had been hiding cans of beer in the water tank part of the toilet.
Yes…you read that right, he would “take a bathroom break” so he could pound a beer a few times throughout the day lol.
I wouldn’t critique it that much honestly, except for the fact that he operated heavy equipment for his job, so yeah, not safe at all.