Network Segmentation for Care Facilities: A Starter Guide

Many small and mid-sized care facilities run what network engineers call a flat network: everything sits on one big network where any device can talk to any other. Computers, printers, cameras, residents' tablets, the nurse call system and the server holding clinical data all share the same space. It is simple to set up, and it is exactly what ransomware operators hope to find. One infected computer can then probe everything else.

Network segmentation divides the network into smaller zones, with controls on what can pass between them. This guide explains the concept in plain terms and offers a phased approach.

What segmentation does

Think of a building with locked doors between wings, rather than one open floor. If a fire starts in one wing, it does not automatically reach the others. Segmentation:

Limits how far malware or an intruder can move

Reduces exposure of sensitive systems to less trusted devices

Makes it easier to monitor traffic, because each zone has expected behavior

Supports HIPAA's requirement to implement technical safeguards and limit access to ePHI

Common zones in a care facility

A starting design might include:

Clinical and administrative workstations: staff computers that use the EMR and business applications

Servers and critical systems: hosted or on-site servers, with strict rules about who can reach them

Medical and clinical devices: connected equipment that often cannot be updated easily

Building systems: door access, cameras, HVAC, nurse call, fire panels

Printers and copiers: frequently overlooked and often poorly secured

Resident Wi-Fi: completely separate from internal systems, with internet access only

Guest Wi-Fi: also internet only, and isolated from residents

Vendor access: a controlled zone for third-party remote connections

Management: a restricted zone for network equipment administration

How it is done: VLANs and firewalls

A VLAN, or virtual local area network, is a way to create separate logical networks on shared switches and cabling. Each VLAN is a zone. Traffic between VLANs must pass through a router or firewall, where you set rules about what is allowed. A rule might say, for example, that staff workstations can reach the EMR server on specific ports, while resident Wi-Fi cannot reach it at all.

The principle is default deny: block traffic between zones unless a business need is documented, then allow only that.

Why it matters for real threats

Consider a hypothetical: a visitor's infected phone joins guest Wi-Fi. On a flat network, that device might find file shares and printers throughout the building. With segmentation, the guest zone only reaches the internet. Or a camera with a known vulnerability is compromised. In a segmented network, the camera zone cannot reach the server holding resident records.

Plan the project in phases

You do not need to do everything at once, and trying to can disrupt care. A reasonable sequence:

Document the current state. Map devices, switches, cabling and traffic flows. Identify which devices talk to which systems.

Quick wins. Move resident and guest Wi-Fi to isolated networks. This is usually the safest and most valuable first step.

Isolate high-risk devices. Cameras, printers and building systems follow, since they often have weaker security.

Protect servers and critical systems. Restrict access to only authorized workstations and administrators.

Refine rules. Start with monitoring mode where available, then tighten rules as you learn what traffic is legitimate.

Document and test. Record the design, verify each zone and confirm that critical workflows still work.

Watch for pitfalls

Breaking something critical. Nurse call, door access and EMR integrations may rely on traffic you did not anticipate. Test in off-hours and keep rollback plans.

Unmanaged switches. Basic switches cannot create VLANs. You may need equipment upgrades.

Vendor demands. Some vendors insist on open access. Push back, and work out the minimal rules needed.

Rule sprawl. Over time, exceptions pile up. Review firewall rules at least twice a year.

Prepare your team

Segmentation adds complexity, so label ports, keep diagrams current and make sure more than one person understands the design. Include the diagram in your disaster recovery documentation.

Measure progress

Track which zones exist, which devices are in each and which rules remain broader than you would like. Even a simple spreadsheet shows progress over time.

UnityCare IT designs and implements segmentation for senior living and long-term care facilities, including safe cutovers that protect clinical operations. If your network is flat today, we can help you plan a first phase that fits your budget.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172