Network Segmentation Explained for Care Facility Administrators

Picture a nursing home where every door is unlocked and every hallway leads everywhere. A visitor who wanders in can reach the medication room, the business office and the resident wings. That is how many computer networks are built: one flat network where every device, from the director's laptop to the resident entertainment tablet, can talk to every other device.

Network segmentation is the process of dividing that single network into separate zones, with controlled doors between them. It is one of the most useful things a facility can do to contain a problem before it becomes a crisis.

Why segmentation matters

Most serious cyber incidents spread. An attacker gets into one computer through a phishing email, then moves sideways to find servers, backups and clinical systems. On a flat network, nothing stops them. On a segmented network, the infected computer can only reach what it needs, and the rest of the building keeps running.

Segmentation also helps with problems that are not malicious. A misbehaving device flooding the network can be limited to its own zone.

Typical zones in a care facility

Staff and administrative computers

Office workstations, business office, HR and email. These handle sensitive data and are heavily targeted by phishing.

Clinical systems

EHR or EMR access, medication carts, point-of-care devices and clinical servers. These need reliable access to applications and strict control over who else can reach them.

Medical and monitoring devices

Devices such as infusion pumps, vitals monitors or oxygen systems often run older software that cannot be patched easily. Place them in their own zone with limited connections.

Building systems and IoT

Security cameras, door access controls, HVAC, thermostats, elevator controllers and nurse call systems. These are often managed by outside vendors and are common entry points for attackers.

Resident and guest Wi-Fi

This should have internet access only and no path to anything internal. It is also the area where devices are least controlled.

Servers and backups

Your most valuable assets should have the strictest rules, with backups reachable by as few systems as possible.

Phones and voice

VoIP phones typically sit on their own segment so call quality is protected and phones cannot be used as a stepping stone.

How segmentation is done

The common building blocks are:

VLANs: logical networks that share the same physical switches but cannot talk to each other directly.

Firewall rules: a firewall or router controls which zones can talk to which, and on which ports. The default should be to block, with specific exceptions.

Wireless network separation: separate SSIDs mapped to separate VLANs, rather than one network for everyone.

Access control: more advanced systems assign devices to the right zone automatically based on who or what they are.

Questions to ask about your network

Can a guest or resident device reach any internal computer or printer?

Can a staff computer reach the backup system directly?

Are building systems and cameras on the same network as the EHR?

Do vendors have remote access to devices, and can they reach more than the one device they support?

Can an old medical device connect to the internet, and does it need to?

If the answer to any of these is yes or I do not know, a conversation with your IT provider is worthwhile.

Practical tips

Start by drawing a simple map of what is on your network. You cannot separate what you have not identified.

Begin with the highest-value moves: guest Wi-Fi separated from everything, then servers and backups, then medical and IoT devices.

Test after each change. Segmentation can break something that depended on open access, such as a printer or a monitoring dashboard.

Document the rules. Each exception should have a reason and an owner.

Review quarterly, since devices and vendors change.

Compliance angle

The HIPAA Security Rule asks for technical safeguards that limit access to ePHI and protect against unauthorized access, and the HHS 405(d) practices recommend network management and segmentation. Segmentation is a reasonable and appropriate safeguard for most facilities and belongs in your risk analysis.

Getting started

UnityCare IT designs and implements segmented networks for healthcare facilities, working around clinical schedules so care is not disrupted. If you have never mapped what is on your network, we can start there.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172