Network Segmentation for Medical Devices and Guest Wi-Fi

On a flat network, every device can talk to every other device. The nurse station computer, the resident's tablet, the security camera, the infusion pump interface and the file server all share the same space. That is convenient, but it also means that if one device is compromised, the attacker can often reach the rest.

Network segmentation breaks that single space into smaller zones with controlled paths between them. It is one of the most valuable improvements a care facility can make, and it does not require replacing everything.

The idea in simple terms

Think of a facility with locked doors between departments. The kitchen does not need access to medical records, and the activities room does not need access to payroll. Segmentation applies the same logic to your network. Devices are placed in groups called virtual local area networks, or VLANs, and a firewall decides what traffic may pass between them.

Common zones for care facilities

A practical design might include:

Clinical and business staff network. Workstations, laptops and servers that handle ePHI.

Medical and clinical devices. Equipment that connects to the network, often older and harder to update.

Building systems. Cameras, door access, nurse call, thermostats and similar equipment.

Resident and guest Wi-Fi. Internet access only.

Management network. Switches, access points and firewalls, with access limited to IT.

Voice network. Phones, if you use internet-based telephone systems.

Why it matters

Contains ransomware. If a resident's laptop is infected, it cannot scan and attack your records system.

Protects fragile devices. Many medical and building devices cannot run security software or be patched often. Isolating them lowers the risk that they will be exploited.

Improves performance. Streaming video on guest Wi-Fi no longer competes with clinical traffic.

Supports HIPAA safeguards. Limiting access to systems with ePHI is consistent with the Security Rule's access control expectations, and it is easy to explain in a risk analysis.

How to approach it

Start with an inventory

You cannot segment what you cannot see. List every device type on the network, what it needs to talk to, and who manages it. Include vendor-managed equipment, which often has remote access arrangements you should know about.

Define the rules

For each pair of zones, decide what is allowed. Guest Wi-Fi might reach only the internet. Building systems might reach their vendor's cloud service and nothing else. Staff computers might reach servers but not the management network.

The default should be deny, with specific exceptions allowed where needed.

Check your equipment

Segmentation needs switches and a firewall that support VLANs and inter-zone rules. Most business-grade equipment does. Consumer-grade routers often do not.

Phase the change

Move one group at a time, starting with guest Wi-Fi, which is the easiest and least risky. Then proceed to building systems and medical devices. Schedule changes outside peak care hours and have a rollback plan.

Test thoroughly

After each change, confirm that devices still work, that nurse call and door access function, and that blocked paths are indeed blocked.

Pitfalls to avoid

Moving a device into a new zone without checking with the vendor. Some medical devices depend on specific network settings.

Creating too many exceptions, which defeats the purpose.

Forgetting to document the design. Diagrams help future troubleshooting and audits.

Neglecting monitoring. Logging blocked traffic can reveal misconfigured devices or suspicious behavior.

Vendor remote access

Many device and building system vendors connect remotely for support. Control this by requiring a secure method, limiting access to the specific device, enabling it only when needed and keeping logs. Uncontrolled vendor access has been a recurring path into healthcare networks.

A starting example

For example, a 60-bed assisted living community might begin by creating a separate guest and resident network, then moving cameras and nurse call to their own zone, and finally restricting which workstations may reach the server that holds resident records. Even these first steps substantially reduce exposure.

How UnityCare IT can help

UnityCare IT designs and implements segmented networks for healthcare and senior living facilities, with attention to vendor requirements and clinical workflow. We can start with an assessment of your current layout and propose a phased plan.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172