In many care facilities, the network grew one piece at a time. A printer here, a camera system there, a nurse call upgrade, a guest Wi-Fi network added after residents asked. Often all of it sits on one flat network where every device can talk to every other device. That convenience carries a serious cost: if one device is compromised, an attacker can often move to systems that hold resident data.
Network segmentation fixes this by dividing the network into zones with controlled paths between them. It is one of the most effective structural protections available, and it is achievable for small and mid-size organizations.
Think of a building with locked doors between departments. A visitor in the lobby cannot walk into the medication room. Segmentation does the same for data. Devices in one zone can reach only the specific services they need in another zone, and everything else is blocked by default.
Older devices cannot be patched. Some medical equipment, building systems and specialty devices run outdated software that cannot be updated without vendor involvement. Segmentation limits what an attacker can do through them.
Residents and guests bring unmanaged devices. Personal phones and tablets are outside your control and should never share a network with clinical systems.
Ransomware spreads sideways. A flat network lets malware travel from one workstation to servers and backups quickly. Segments slow or stop that movement.
Compliance expectations. HIPAA requires safeguards that limit access to electronic protected health information, and segmentation is a recognized way to support that.
Every facility is different, but most benefit from some version of the following.
Managed computers used by administration, nursing and business office, with access to the EMR, file shares and email.
Medical devices, monitors and similar equipment that connect to the network. Restrict them to the specific servers or services they need, and block internet access unless the vendor requires it.
Thermostats, door controllers, cameras, fire panels and nurse call systems. These are often managed by outside vendors and should be isolated from staff computers.
Systems that store data, with tight rules about who and what can connect.
Internet access only, with no path to internal networks. Consider client isolation, so one guest device cannot reach another.
IP phones are usually placed on their own segment so call quality can be prioritized and traffic separated.
Network equipment management interfaces should be reachable only from a few trusted administrator workstations.
The most common approach uses virtual LANs, or VLANs, which separate traffic on the same physical switches. A firewall or a layer 3 switch then controls what can pass between VLANs. On wireless, each zone typically maps to its own network name tied to the right VLAN.
The important part is not the technology term but the rules. The default should be deny, with explicit allowances documented for each need. For example, a nurse call controller may be allowed to reach one vendor server on one port, and nothing else.
Inventory devices. You cannot segment what you have not found. Use a network scan and walk-through to list everything connected.
Classify by risk and need. Group devices by function, sensitivity and who manages them.
Map the traffic. Work out which devices must talk to which services. Vendors can help with specifics.
Design zones and rules on paper before changing equipment.
Implement in stages, starting with the easiest wins such as separating guest Wi-Fi, then moving to cameras, then clinical devices.
Test and monitor. Keep a rollback plan, and ask for a staff member on each shift to report oddities during the transition.
Document. Maintain a current diagram and rule list.
Moving too fast and breaking a critical device on a Friday afternoon
Leaving permissive any-to-any rules between zones, which defeats the purpose
Forgetting vendor remote access paths
Allowing exceptions to accumulate without review
Overlooking wired ports in common areas that connect to the staff network
New devices appear constantly. Review firewall rules and device lists at least yearly, and require a request process for any new system that connects to the network.
UnityCare IT designs and implements segmented networks for healthcare and senior living facilities in Oklahoma, Texas and Arkansas. If you suspect your network is flat, we can map it, propose zones that fit your building and phase the work to limit disruption.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172