Many small and mid-sized care facilities run what network engineers call a flat network: everything sits on one big network where any device can talk to any other. Computers, printers, cameras, residents' tablets, the nurse call system and the server holding clinical data all share the same space. It is simple to set up, and it is exactly what ransomware operators hope to find. One infected computer can then probe everything else.
Network segmentation divides the network into smaller zones, with controls on what can pass between them. This guide explains the concept in plain terms and offers a phased approach.
Think of a building with locked doors between wings, rather than one open floor. If a fire starts in one wing, it does not automatically reach the others. Segmentation:
Limits how far malware or an intruder can move
Reduces exposure of sensitive systems to less trusted devices
Makes it easier to monitor traffic, because each zone has expected behavior
Supports HIPAA's requirement to implement technical safeguards and limit access to ePHI
A starting design might include:
Clinical and administrative workstations: staff computers that use the EMR and business applications
Servers and critical systems: hosted or on-site servers, with strict rules about who can reach them
Medical and clinical devices: connected equipment that often cannot be updated easily
Building systems: door access, cameras, HVAC, nurse call, fire panels
Printers and copiers: frequently overlooked and often poorly secured
Resident Wi-Fi: completely separate from internal systems, with internet access only
Guest Wi-Fi: also internet only, and isolated from residents
Vendor access: a controlled zone for third-party remote connections
Management: a restricted zone for network equipment administration
A VLAN, or virtual local area network, is a way to create separate logical networks on shared switches and cabling. Each VLAN is a zone. Traffic between VLANs must pass through a router or firewall, where you set rules about what is allowed. A rule might say, for example, that staff workstations can reach the EMR server on specific ports, while resident Wi-Fi cannot reach it at all.
The principle is default deny: block traffic between zones unless a business need is documented, then allow only that.
Consider a hypothetical: a visitor's infected phone joins guest Wi-Fi. On a flat network, that device might find file shares and printers throughout the building. With segmentation, the guest zone only reaches the internet. Or a camera with a known vulnerability is compromised. In a segmented network, the camera zone cannot reach the server holding resident records.
You do not need to do everything at once, and trying to can disrupt care. A reasonable sequence:
Document the current state. Map devices, switches, cabling and traffic flows. Identify which devices talk to which systems.
Quick wins. Move resident and guest Wi-Fi to isolated networks. This is usually the safest and most valuable first step.
Isolate high-risk devices. Cameras, printers and building systems follow, since they often have weaker security.
Protect servers and critical systems. Restrict access to only authorized workstations and administrators.
Refine rules. Start with monitoring mode where available, then tighten rules as you learn what traffic is legitimate.
Document and test. Record the design, verify each zone and confirm that critical workflows still work.
Breaking something critical. Nurse call, door access and EMR integrations may rely on traffic you did not anticipate. Test in off-hours and keep rollback plans.
Unmanaged switches. Basic switches cannot create VLANs. You may need equipment upgrades.
Vendor demands. Some vendors insist on open access. Push back, and work out the minimal rules needed.
Rule sprawl. Over time, exceptions pile up. Review firewall rules at least twice a year.
Segmentation adds complexity, so label ports, keep diagrams current and make sure more than one person understands the design. Include the diagram in your disaster recovery documentation.
Track which zones exist, which devices are in each and which rules remain broader than you would like. Even a simple spreadsheet shows progress over time.
UnityCare IT designs and implements segmentation for senior living and long-term care facilities, including safe cutovers that protect clinical operations. If your network is flat today, we can help you plan a first phase that fits your budget.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172