It is physically possible for a consultant to write bad code. But you'd hope that a consultant could understand that medical data is extremely important to keep secure, and actually write it to have some level of security

Sure, but you'd hope that the LLM could understand that too.

And yet it seems it didn't