A health company where they have that poor of security practices? Get the hell out ASAP! When they get ransomware, (and they will,) you do NOT want to be on the hook for trying to recover their systems.
Trust me, I had to help recover from a ransomware attack at a small company a while back, it hit early in the morning, I got there a little before 8am once I got the call.
22 hours later, we had only just finished wiping and re-imaging every computer, let alone getting all the software reinstalled, configured, tested, backups re-synced, etc. It took weeks to get everything fully recovered, and that was with a team of half a dozen people.
In the meantime, CYA hardcore. Document all security issues you can find in email and make sure whoever is in charge is aware and is on the email chain. There literally could be legal charges brought up if it’s involving private health information.
Get ready for corpos to have power and influence like you wouldn’t believe.