Company Logo

The Breach that Reimagined Recruiting:
What a Hack Taught Us About Building the Most Secure Healthcare Recruiting Platform in America

About Intro

By the time we learned what happened, it was too late.

It wasn’t a ransomware attack. No files were encrypted. No demands made. Instead, it was the silent kind of theft — a digital break-in through overlooked logins, orphaned spreadsheets, and outdated processes trusted far too long. The kind that thrives in the shadows of an industry that hasn’t kept up with the digital age. The kind that leaves no fingerprints, but a trail of stolen resumes, pilfered data, and candidate information now in the hands of competitors who shouldn’t have had access in the first place.

For nearly two decades, we operated as Mlee Healthcare, placing thousands of clinicians, therapists, and healthcare executives across the country. We built relationships, earned trust, and made a name for ourselves.

But behind the scenes, we were relying on the same tools, the same workflows, and the same loosely secured systems as every other staffing and recruiting firm.

And that’s what made us vulnerable.

So, when our internal data was siphoned and shared and sold, we didn’t just tighten a few bolts and patch things up.

We started over. We rebranded. We rebuilt. We reimagined the entire business as Stelmo — a name that reflects not just a new platform, but a new promise:

That trust and transparency must be engineered into every part of healthcare recruiting.

Healthcare Recruiting Is Under Siege

Healthcare is now the most targeted industry for cybercrime.

According to IBM’s 2023 Cost of a Data Breach report, the average healthcare data breach now costs over $10.93 million — more than any other sector for the 13th year in a row. Yet most headlines focus on hospitals and insurance providers.

What rarely makes the news are the vendors and staffing firms holding just as much sensitive data.

Outdated ATS tools. Recruiters with desktop folders of resumes. Siloed spreadsheets. Agencies passing around candidate data like trading cards. It’s not just inefficient, it’s dangerous.

It’s a goldmine for bad actors. And it’s being left unguarded.

We Thought We Were Safe, Until We Weren’t

The breach started small, siphoning candidate resumes and contact details into a personal database. At first, it looked like standard IP theft, but the deeper we dug, the more we uncovered: external logins used from unfamiliar devices, batch exports of data from third-party job boards, and most disturbingly, entire lead lists being duplicated and resold.

The worst part? These weren't faceless bots. This was corporate espionage by people in our industry, people who knew exactly what to steal and how to cover their tracks.

We Did Something Most Firms Wouldn’t — We Started Over

Instead of patching a broken system, we built a new one.

We built an end-to-end platform designed to not only streamline recruitment but also protect the people it serves.

And we took no shortcuts:

  • Zero Trust Architecture: Every user, internal or external, is authenticated and verified continuously. No blanket access. No universal passwords.
  • End-to-End Audit Trails: Every action — from a resume view to a job submission — is logged and reviewed for unusual patterns.
  • Role-Based Permissions: Recruiters can’t see what they don’t need. Clients control their data. Candidates decide how their info is shared.
  • Secure Candidate Vaults: Proprietary information is tokenized and encrypted. Even our engineers can’t access personal data without multi-party approval.
  • Auto-Escalation Protocols: Suspicious activity triggers alerts, flags the user, and notifies leadership across departments with no manual intervention required.

And perhaps most importantly, we no longer use third-party software to manage client and candidate relationships. Every data flow — from the job board to the applicant database to communications — is routed and managed through our platform.

We Didn’t Just Fix a Security Issue, We Solved a Trust Problem

In our industry, data is the business. The names of the best NICU nurses, the personal contact info of traveling speech therapists, the licensing history of an executive CMO — it’s all leverage. Which is why too many firms treat it like currency, not responsibility.

We believe trust is the future currency of recruiting. And it’s earned, not assumed.

When candidates join our network, they can be assured their data isn’t being scraped, sold, or shared behind closed doors. When clients and vendors work with us, they can be assured our recruiters aren’t stockpiling candidates in spreadsheets that walk out the door with the next departure.

In fact, we’ve made it our mission to help other healthcare organizations secure their data too — through our Community First initiative, we offer our platform free of charge to select clinics, nonprofits, and underserved facilities who need help managing candidate data safely and transparently.

Don’t Wait to Get Burned

If this sounds dramatic, good. It should.

Because what happened to us isn’t rare, it’s just rarely talked about.

The truth is most firms won’t even know they've been breached. Data exfiltration doesn’t set off alarms unless you know where to look. And in staffing, where turnover is high and systems are fragmented, breaches can be hiding in plain sight.

So, here’s our challenge to the industry:

  • Audit your platforms.
  • Ask your vendors how they store their data.
  • Look at your logs.
  • Talk to your engineers.
  • Don’t assume you’re secure — prove it. Or work with a firm like Stelmo that already has.

We're Not Just Filling Jobs, We're Building a Safer Industry

Stelmo is proud to lead the charge toward a more secure, ethical, and transparent future for healthcare staffing. Not just because it’s good for business, but because it’s what people deserve.

We believe that:

  • Resumes are not a commodity.
  • Trust is more valuable than speed.
  • Platforms should protect, not just perform.

If you’d like to learn more or partner with us, connect here.